USPS Surges to Take Top Spot as Most Impersonated Brand in Phishing Attacks



USPS Surges to Take Top SpotNew data shows phishing attacks are deviating from the traditional focus on technology and retail sectors and are opting for alternate brands with widespread appeal.

I’ve covered plenty of reports about brand impersonation and it’s almost always Microsoft on top of the list.

And with good reason: access to a Microsoft 365 account can give attackers a foothold and potential access to data, applications and more.

But in Guardio’s latest Q1 Phishing Impersonation report, things take a surprising turn. According to their data, the U.S. Postal service saw a massive jump of nearly 6x from its position two quarter’s ago, representing just 1.9% of all impersonation attacks to Q1’s position of 11.6%.

Guardio cites the use of text messages as a common medium for scams involving the USPS.  This could be one of the reasons for the jump; the ease of access to basically every mobile phone number in the U.S. outweighs the work it would take to obtain the equivalent number of email addresses.

Add_a_heading__Twitter_Post___1_-min

Source: Ctfassets

Microsoft’s brand was still represented in 9.3% of all impersonated emails, putting it in second place, with the focus remaining on obtaining user credentials with fake logins:

Microsoft_sign_in-min

Source: Ctfassets

You should expect the brands to continue to change positions in the lists of those security vendors tracking the brands they see in attacks; it’s merely a shifting of priorities and desired outcomes – all in the name of figuring out the best path to monetize victims.

No matter the brand, the simple rule of thumb, “If it’s not expected, it should be treated as suspicious” applies here – something employees who undergo security awareness training understand fully. Anyone receiving branded communications across an unexpected medium or with a request that is out of the norm, should treat them as hostile and scrutinize such messages with extreme prejudice until it’s proven to be legitimate.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews