The most popular brand for phishing attacks might surprise you

>

Global logistics and shipping powerhouse DHL is the most represented brand in phishing attacks, with most criminals using its name and logo when trying to steal people’s login credentials, payment details and even money, experts warn.

A new report from Check Point examining the threat landscape between July and September 2022 found that nearly a quarter (22%) of all phishing attempts were masquerading as DHL.

In phishing attacks, cyber criminals prepare an email (or a text message or any other form of communication) to look and feel like it comes from a legitimate brand in order to get people to actually open the content. In the email itself, the scammers claim that the victim needs to resolve an urgent issue (for example, a pending package) by providing sensitive data, either directly via email or through a specially designed landing page.

Microsoft and LinkedIn also suffer from

The data would then end up in the hands of the criminals to use in various other forms of cybercrime such as identity theft (opens in new tab)wire transfer fraud or something like that.

As reported by The registerIn late June, DHL warned customers against being used in a “major global scam and phishing attack”, adding that it was “working hard to block the fraudulent websites and emails”.

Since the Covid-19 pandemic and the lockdowns, people are shopping much more online, giving DHL extra exposure – something that cybercriminals are now looking to take advantage of.

However, the shipping giant isn’t the only brand mimicked in these attacks. At 16%, Microsoft is the second most imitated brand, followed by third place LinkedIn, which previously held the number one spot in both Q1 and Q2 2022.

To protect against phishing attacks, companies are advised to educate: (opens in new tab) their employees about cybersecurity best practices. Employees, as the first line of attack, should be extra careful when receiving emails with links or attachments and to check the email’s sender address, as well as its content, for typos or inconsistencies.

Through: The register (opens in new tab)

Related Post