Microsoft becomes the most-spoofed brand for phishing attacks

The tech giant was imitated in almost 20% of all phishing attacks during the third quarter

Microsoft was the most-spoofed brand by hackers during the third quarter of 2020, featuring in nearly a fifth of all global brand-based phishing attacks.

That's according to Check Point, which claims that Microsoft jumped from the fifth spot in the second quarter to first place in Q3, overtaking the likes of Amazon and Google. Its research shows that, during the three-month period, around 19% of all brand phishing attacks globally spoofed the software giant, up from just 7% in the previous quarter.

Check Point attributed Microsoft's leap to the number one spot to the ongoing shift to mass remote working necessitated by the COVID-19 pandemic.

Maya Horowitz, director of Threat Intelligence & Research at Check Point said: “In this past quarter, we saw the highest increase in email phishing attacks of all platforms compared to Q2, with Microsoft being the most impersonated brand.

"This has been driven by threat actors taking advantage of the mass migration to remote working forced by the COVID-19 pandemic, to target employees with fake emails asking them to reset their Microsoft Office 365 credentials."

In mid-August, for example, Check Point researchers witnessed a malicious phishing email trying to steal credentials of Microsoft accounts. The attack attempted to encourage victims to click on a link which redirected the user to a fraudulent Microsoft login page.

Check Point says that that email was the top attack vector during the third quarter, accounting for 44% of all phishing attacks, closely followed by web phishing (43%). Mobile phishing attacks made up the remaining 12%.

Related Resource

The State of Email Security 2020

Email security insights at your email perimeter, inside your organisation, and beyond

Email security insights at your email perimeter, inside your organisation, and beyondDownload now

"As always, we encourage users to be cautious when divulging personal data and credentials to business applications, and to think twice before opening email attachments or links, especially emails that claim to from companies, such as Microsoft or Google, who are most likely to be impersonated," said Horowitz.

Back in July, Microsoft announced that it had successfully seized a number of web domains used in a sophisticated phishing scheme that attempted to exploit concerns related to the coronavirus pandemic.

Featured Resources

How virtual desktop infrastructure enables digital transformation

Challenges and benefits of VDI

Free download

The Okta digital trust index

Exploring the human edge of trust

Free download

Optimising workload placement in your hybrid cloud

Deliver increased IT agility with the cloud

Free Download

Modernise endpoint protection and leave your legacy challenges behind

The risk of keeping your legacy endpoint security tools

Download now

Recommended

Russia's "politically motivated" REvil raid could be used as leverage, experts warn
ransomware

Russia's "politically motivated" REvil raid could be used as leverage, experts warn

17 Jan 2022
Meta files lawsuit to uncover hackers targeting Facebook, WhatsApp
phishing

Meta files lawsuit to uncover hackers targeting Facebook, WhatsApp

21 Dec 2021
Five things to consider before choosing an MFA solution
Security

Five things to consider before choosing an MFA solution

17 Dec 2021
Australia and US sign CLOUD Act data-sharing deal to support criminal investigations
cyber crime

Australia and US sign CLOUD Act data-sharing deal to support criminal investigations

16 Dec 2021

Most Popular

How to move Microsoft's Windows 11 from a hard drive to an SSD
Microsoft Windows

How to move Microsoft's Windows 11 from a hard drive to an SSD

4 Jan 2022
Microsoft Exchange servers break thanks to 'Y2K22' bug
email delivery

Microsoft Exchange servers break thanks to 'Y2K22' bug

4 Jan 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

6 Jan 2022