Top 10 Impersonated Brands
Facebook - Google - Apple - Amazon

Top 10 Impersonated Brands

Cybercriminals know the easiest way to sneak under your radar is to pretend to be a brand you know and trust. These large companies have spent years on marketing, customer service, branding and consistency to build a trustworthy reputation, and hackers leverage this to go after you.

The most common method is to use phishing attacks. These thieves set up URLs that look scarily similar to the real company’s website. To slip by your watchful eye, here are some of the simple switches hackers make that can go unnoticed:


1. Switching out a zero for the letter “O” or a capital “i” for a lowercase “L.” If you’re quickly reading an e-mail, it might look legit.

2. Adding in a word that seems like it could be a subdomain of the real company, like “info@googleservice.com.”

3. Using a different domain extension, like “info@google.io.”

Some criminals will take it a step further and set up a web page that looks identical to that of the real website. When you click the link – via e-mail, SMS or even through social media – several dangerous results can occur.

The first is that malware can be installed on your computer. Clicking a bad link can set off an automatic malware download that contains malicious files with the ability to collect personally identifiable information from your device, like usernames, credit card or bank account numbers and more.

The second is the fake website will have a form to harvest your information. This could be login credentials, passwords and, in some cases, your credit or bank information.

The third most common issue is an open redirect. The link might look legit, but when you click on it, you’re redirected to a malicious website where the intent is to steal your information.


What brand impersonations do you need to look out for? Well, all of them, but according to Check Point’s latest Brand Phishing Report, there are 10 companies that top the chart in overall appearance in brand phishing attempts.

Here Are The Top 10 Most Frequently Impersonated Brands In Phishing Attempts In Q2 Of 2023:

1. Microsoft (29%)

2. Google (19.5%)

3. Apple (5.2%)

4. Wells Fargo (4.2%)

5. Amazon (4%)

6. Walmart (3.9%)

7. Roblox (3.8%)

8. LinkedIn (3%)

9. Home Depot (2.5%)

10. Facebook (2.1%)

Take a minute and ask yourself how many of the companies on this list send you regular e-mail communications. Even just one puts you at risk.

Cybercriminals go the full mile with these scams. They know what types of messages work best for each company to get your attention.

Here are three common phishing attacks cybercriminals have used under these brands’ good names to gain access to your private information.

1. Unusual Activity – These types of e-mails will suggest that someone gained access to your account and you need to change your password quickly. They leverage fear so people will click without thinking, hurrying to change their password before they’re a victim of the attack.

They usually have buttons that say, “Review Recent Activity” or “Click Here To Change Your Password.”

These e-mails can go as far as to show fake login information detailing the region, IP address, time of sign-in and more, like real messages from the companies do to convince you to click.

2. Fake Gift Cards – These e-mails suggest that someone sent you an e-gift card. When you open the e-mail, they either redirect you to a website to “claim your gift card” or have a button to “redeem now.”


3. Account Verification Required – These e-mails suggest that your account has been disconnected, and they need you to verify your information. As soon as you enter your login credentials, the hacker has access.

These scams are happening every single day. You’re a target, but so are the unsuspecting employees in your company. Without proper training, they might not know what to look for, panic and try to resolve these “issues” under the radar, ultimately causing the problem.

There are multiple steps to making sure your network is secure. One would be getting e-mail monitoring to help reduce the likelihood of these phishing e-mails ending up in your inbox. It’s also important to make sure employees know what to look for so that if an e-mail does get by the phishing detection system, they can still keep your company safe.

Best thing to do is to start here with your FREE Cybersecurity Risk Analysis. We’ll evaluate your network and provide a full report on areas where you are vulnerable and what to do to fix them. There’s no obligation, but you should know where you’re at risk. Click here to schedule your analysis now.

For more thought leadership, follow Kevin Fream.

To view or add a comment, sign in

More articles by Kevin Fream

  • Titans Rise

    Titans Rise

    T - Minus 352 Days It was 2007 when Transformers first hit the theaters which seems like a different world with social…

  • Rebuild Yourself

    Rebuild Yourself

    T - Minus 353 Days You wake between 4 and 5 without an alarm, make the bed, go to the bathroom to pee and brush your…

  • Courage and Fortitude

    Courage and Fortitude

    T - Minus 354 Days While the Emperor preached about his gods and allegiance to Rome, Sebastian watched near his side as…

  • Day After Tomorrow

    Day After Tomorrow

    T - Minus 355 Days Shockingly as forecast, the snow started yesterday at precisely noon. However, it can't be climate…

  • Follow Rules

    Follow Rules

    T - Minus 356 Days Growing up in Preston, Oklahoma my favorite thing was to explore - new places and new things. The…

  • Adversity Success

    Adversity Success

    T - Minus 357 Days One of my earliest memories was playing with some toy soldiers on the floor at the foot of grandpa's…

  • Playmaker

    Playmaker

    T - Minus 358 Days Say a prayer for the people in California devastated by wildfires and a little bit of music died…

  • Stronger Smarter Faster Healthier Better

    Stronger Smarter Faster Healthier Better

    T - Minus 359 Days Everyone is just trying to figure it out. For every situation I always ask, "What is the game?"…

  • Keep Pushing Your Spirit

    Keep Pushing Your Spirit

    T - Minus 360 Days The special code file called CSS that controls the formatting of your website was 50% smaller…

  • Fall Guy

    Fall Guy

    T - Minus 361 Days A previous client called up as he'd recently taken a position at a non-profit that we knew and had…

Insights from the community

Others also viewed

Explore topics