While most of us feel as though we are privy to phishing attempts online, sometimes, people just make mistakes. Verizon’s 2019 Data Breach Investigations Report showed that nearly one-third (32 percent) of data breaches involved phishing activity. Phishing was also present in 78 percent of cyber-espionage incidents and the installation and use of backdoors to networks.
It’s no surprise that phishing continues to be a key weapon in cyber-criminals’ arsenals, to try and trick users into giving up sensitive information by impersonating familiar brands.
Brand phishing involves the attacker creating and imitating an official website of a known brand by using a similar domain or URL, and similar web page design. The link can be sent via an email or text message, or mistakenly clicking the link while browsing, or triggered from a fraudulent mobile app. In many cases the website contains a form intended to steal credentials, personal information or payments.
Check Point Research’s latest Brand Phishing Report for Q1 2020 shows that Apple was the most imitated brand, rising from 7th place in Q4 of 2019 to the top spot. This was most probably due to the anticipated launch of the new Apple Watch, prompting criminals to exploit the online hype and launching several credential theft attempts.
Furthermore, in Q1 Mobile Phishing was the second most common attack vector compared to Q4 of 2019 where it ranked in third place. This may be due to the Coronavirus pandemic which has caused people to rely more on their mobile phones for information and work. There are also similarities in the brands being used in web and mobile phishing vectors, such as Netflix and PayPal, which have risen in popularity due to an increase in the number of people working from home as a result of the Coronavirus
Top Phishing brands per platform
During Q1 2020, similar brands were used in mobile and web phishing vectors, which included banking and streaming services such as Chase and Netflix. Web phishing was the most prominent vector at 59 percent, followed by mobile phishing as the second most common attack vector compared to Q4 of 2019, where it ranked third. This is due to people spending more time on their mobile phones during the Coronavirus pandemic, which cybercriminals are taking advantage of.
Email (18% of attacks)
- Yahoo
- Microsoft
- Outlook
- Amazon
Web (59% of attacks)
- Apple
- Netflix
- PayPal
- eBay
Mobile (23% of attacks)
- Netflix
- Apple
- Chase
Top brands industries
- Technology
- Banking
- Media
That being said, here are some tips to stay vigilant and not let your data be compromised:
- Verify you are using or ordering from an authentic website. One way to do this is NOT to click on promotional links in emails, and instead Google your desired retailer and click the link from the Google results page.
- Beware of “special” offers. An 80% discount on the new iPhone is usually not a reliable or trustworthy purchase opportunity.
- Beware of lookalike domains, spelling errors in emails or websites, and unfamiliar email senders.



