Reαd carefully: how to spot – and avoid – a homoglyph attack
Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miсrosoft.com You’ve read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. You feel safe to proceed. But if you had looked slightly closer you may have noticed something slightly wrong…
Scam emails are becoming more sophisticated, utilizing subtle visual tricks to mimic legitimate websites. One common tactic involves using near-identical URLs, such as mićrosoft.com, which appear harmless at first glance. Fraudsters often switch out characters from different alphabets, like using the Cyrillic "α" instead of the Latin "a".
This deceptive practice, known as a homoglyph attack, aims to trick victims into clicking malicious links and revealing personal information. Tech experts have observed fraudsters exploiting characters like the Japanese hiragana character ん to resemble a forward slash (/) in URLs, leading unsuspecting users to fraudulent sites designed to steal sensitive data.
Jake Moore, a cybersecurity expert, notes that cybercriminals frequently target well-known companies like Microsoft for spoofing, as it increases the credibility of their fake websites. To avoid falling victim to homoglyph attacks, it's crucial to scrutinize URLs and email addresses carefully, looking for any subtle character discrepancies.
Many phishing attempts now focus on directing users to fraudulent websites rather than requiring them to download malicious attachments, making it essential to verify the legitimacy of links before proceeding. Taking a moment to independently visit known, trusted websites instead of clicking on suspicious links can prevent inadvertent disclosures of personal information.
Regularly updating web browsers and enabling two-factor authentication (2FA) or multifactor authentication (MFA) adds an additional layer of security, helping to mitigate the risk of unauthorized access. If you suspect a phishing attack, promptly change your passwords and report the incident to the relevant authorities.
Written by urgent.news from Guardian Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.