Microsoft Remains the Most Impersonated Brand in Phishing Attacks, with Facebook Phishing Surging

Stu Sjouwerman | Sep 18, 2019
VS_Infographic_Phishers_Favorites_Q2_2019_blog_background_EN-800x450

For the fifth quarter in a row, Microsoft is the favorite domain of choice for scammers using phishing attacks to lure their victims into clicking on malicious content.

Each quarter, security vendor Vade Secure puts out their quarterly Phisher’s Favorites report, listing the top domains that are being leveraged as part of some very sophisticated phishing attacks.

As with last quarter’s coverage, the top five domains remain the same (in order from last quarter): Microsoft, Paypal, Netflix, Facebook, and Bank of America. But in this quarter’s report, we see the use of Facebook surging materially to not only put it well past Netflix to make it the third-most impersonated brand this quarter, but also see it encroaching upon Paypal’s number two spot.

Microsoft’s dominance is based on the lucrative nature of Office 365 credentials; with a single credential, attackers can potentially access a wealth of information and services, unlike any other. These attacks are also getting more sophisticated, according to Vade Secure, with phishers continuing to repurpose JavaScript, CSS, and other code from the legitimate Microsoft website to recreate an identical user experience that fools even the most savvy user.

With such well-known and well-used brands being utilized to create the illusion of legitimacy with potential victims, organizations need to train users using continual Security Awareness Training not just how to be vigilant looking for malicious email and web content, but also to have a security-centric mindset when working.

Seeing these same brands used quarter after quarter tells you one key piece of information – they’re working well for the cybercriminal. You’re going to need to step up your security awareness game to even have a chance of stopping these kinds of attacks.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.