Brand Impersonation of Microsoft Increases 50% in One Quarter

Stu Sjouwerman | Aug 5, 2024

Microsoft 365 Apps Could Give Cybercriminals LeverageThe use of the Microsoft brand in phishing attacks demonstrates both its widespread credibility as well as the continued success of attacks leveraging it.

Each quarter, security vendor Check Point builds its’ Brand Phishing Ranking, identifying the top ten impersonated brands used in phishing attacks. And, while we’ve seen Microsoft at the top of this quite a few times before in their previous rankings, it’s the growth we see in their latest report covering Q2.

According to the latest ranking, Microsoft jumped from representing 38% of all impersonated brands in Q1 to 57% in Q2 – a 50% increase in just one quarter. Additionally, the remaining nine brands each represent 10% or less of the total rankings – making Microsoft’s position six times larger than any other brand on the list.

Other brands on the list were Apple, LinkedIn, Google and Facebook – of which, all but Facebook were in the top five last quarter as well.

The growth in interest in credential theft – particularly those with access to Microsoft 365 – likely has a lot to do with Microsoft’s representation on Check Point’s list.  It also indicates that organizations need to keep their users in a constant state of vigilance through continual security awareness training to ensure that even the most credible-looking impersonated phishing email is seen for its true nature.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.