Site navigation

Microsoft and LinkedIn Among Top Brands Imitated by Criminals

Ross Kelly

,

Brand Phishing
LinkedIn has been knocked off the top spot in Q3.

Microsoft, LinkedIn and Google are among the most common brands imitated by cybercriminals globally, according to Check Point’s latest Brand Phishing report.

The quarterly report highlights the brands which are most frequently imitated by criminals attempting to steal personal information or payment credentials.

Although LinkedIn was the most imitated brand across the first half of 2022, the report shows that DHL took the top spot in Q3, accounting for 22% of all phishing attempts worldwide.

Microsoft ranked in second place (16%) while LinkedIn has fallen into third, making up just 11% of scams. This marks a significant decrease compared to 52% in Q1 and 45% in Q2.

Omer Dembinsky, Data Research Group Manager at Check Point said this decrease of LinkedIn-related scams highlights the changing tactics employed by cybercriminals.

He said: “In Q3, we saw a dramatic reduction in the number of phishing attempts related to LinkedIn, which reminds us that cybercriminals will often switch their tactics to increase their chances of success.

“It is still the third most commonly impersonated brand though, so we’d urge all users to stay mindful of any emails or communications purporting to be from LinkedIn.”

According to Check Point, DHL’s increase could be due in part to a major global scam and phishing attack that the logistics giant warned about itself just days before the quarter started.

Dembinsky added: “Now that DHL is the brand most likely to be imitated, it’s crucial that anyone expecting a delivery goes straight to the official website to check progress and/or notifications.

“Do not trust any emails, particularly those asking for information to be shared.”

Top phishing brands in Q3 2022

Below are the top brands ranked by their overall appearance in brand phishing attempts:

  • DHL (related to 22% of all phishing attacks globally)
  • Microsoft (16%)
  • LinkedIn (11%)
  • Google (6%)
  • Netflix (5%)
  • WeTransfer (5%)
  • Walmart (5%)
  • WhatsApp (4%)
  • HSBC (4%)
  • Instagram (3%)

Notably, Instagram has appeared in the top ten list for the first time this quarter. The social media platform’s inclusion follows a ‘blue-badge’ related phishing campaign that was widely reported in September.

What is brand phishing?

In a brand phishing attack, criminals attempt to imitate the official website of well-known brands by using a similar domain name or URL and web-page design to the genuine site.

Links to fake websites are often sent to targeted individuals by email or text message. However, a user can also be redirected during web browsing or through a fraudulent mobile application.

These fake websites typically feature a form intended to steal users’ credentials, payment details or other sensitive personal information.


Recommended


Phishing attacks have surged in popularity over the last two years. Notably, phishing techniques have been used in number of recent high-profile attacks, including the Robinhood and Uber data breaches.

Dembinsky said: “Phishing is the most common type of social engineering, which is a general term describing attempts to manipulate or trick users. It is an increasingly common threat vector used in most security incidents.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data