Microsoft Continues to be the Top Impersonated Brand in Phishing Attacks

Stu Sjouwerman | Jul 20, 2021

Microsoft Top Impersonated Brand in PhishingNew data from CheckPoint identifies those brands being used by threat actors to trick victims into opening attachments, clicking links, providing credentials, and giving up personal details.

The use of a familiar brand has long been a tactic used by cybercriminals in an effort to elevate the credibility of an email, to lower the defenses of the potential victim, and to get said victim to engage with the phishing email in the desired manner.

According to the latest data from security vendor CheckPoint in their Brand Phishing Report Q2 2021 blog, Microsoft is the predominate brand used in phishing attacks by a wide margin:

  • Microsoft (45%)
  • DHL (26%)
  • Amazon (11%)
  • Best Buy (4%)
  • Google (3%)

In addition, the cybercriminals are getting pretty good at crafting realistic-looking emails that feel like they are really from the brands they claim. The email below provided by CheckPoint is one great example:

Capture

 

 

 

 

 

 

 

 

 

 

Source: Checkpoint

Note how it seems to have a look and feel that passes muster and could be misconstrued as being legitimate.

Your only real defense is to elevate your user’s sense of vigilance – the red flags should be going up first because this kind of email is unexpected and then the email’s contents should be scrutinized (e.g., the email’s subject reads “Your Subscription Has Been Expired” which obviously reads a bit odd). By placing users into continual Security Awareness Training, users can be taught to keep a watchful eye out for suspicious or unexpected emails, regardless of what brand is used.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.