Walmart Jumps to Top of the List of the Worlds Most Impersonated Brands Used in Phishing Attacks

Stu Sjouwerman | May 4, 2023

Walmart Most Impersonated Brand Walmart’s rise to become the brand most likely to be impersonated in Q1 of this year is a real problem.

If you’ve been paying attention to brand impersonation in phishing attacks, you know the premise is to use a brand that a large number of potential victims do business with as a means of both establishing credibility . For many quarters, we continually saw Microsoft and/or Microsoft 365 as the brand of choice due to its wide use. Phishing scams ranged from attempting to take over your computer for “tech support” to spoofing login pages to obtain legitimate Microsoft 365 credentials.

But, according to Check Point’s latest Brand Phishing Report for Q1 of this year, Walmart has risen to the top of the list, representing 16% of all impersonated phishing attacks in Q1. This jump, up from 13th place, demonstrates that attackers are looking for new ways to trick victims into performing the desired malicious action – whether that be clicking a link, opening an attachment, or making a phone call.

We found a recent example of a Walmart-themed email at pcrisk.com where the scam appears to be similar to ones we’ve encountered that were Amazon-themed.

walmart-order-email-scam-main

Source: Check Point

The scam makes the recipient think they ordered something rather expensive (that they didn’t actually order), and get them to call the customer service number to trick them into giving up their credit card details.

All it takes to trick someone is the fabricated legitimacy. Seeing that Walmart has not been a large focus for phishing scams to date, it’s newfound popularity could be all that’s needed to trick email recipients into becoming victims.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.