Cloudflare uses the power of its global network to identify the top 50 most impersonated brands and protect Zero Trust customers

Cloudflare uses the power of its global network to identify the top 50 most impersonated brands and protect Zero Trust customers

Cloudflare, Inc., the security, performance, andreliability company helping to build a better Internet, today published a global report on the Top 50Brands Used in Phishing Attacks. Nearly 20% of all websites are protected by Cloudflare’s global network and its email security offering stopped 2.3 billion unwanted emails from hitting inboxes in 2022. As a result, Cloudflare’s machine learning and data analysis give it unique insight into the phishing domains most frequently clicked on by internet users and the ability to proactively protect its Zero Trust customers. “Phishing” refers to an attempt to steal sensitive information like usernames, passwords, credit card numbers, bank and crypto account information or other important data in order to utilize or sell the stolen information. Today, phishing is the fastest growing Internet crime, and a threat to both consumers and businesses. By masquerading as a reputable source – sometimes with an enticing request, other times with a severe consequence – an attacker lures in the victim in order to trick them, similarly to how a fisherman uses bait to catch a fish. Oftentimes, these attempts come in the form of an email, text message, or mistyped website URL that looks like it’s from a well-known brand, but is actually a malicious party.

“Phishing attacks prey on our trust in the brands we love and use everyday, and are becoming more difficult to spot for even the most digitally-savvy person. Our sanity, bank accounts, and passwords shouldn’t be compromised because we glossed over a misspelled ‘from’ field or accidentally clicked on an obscure URL,” said Matthew Prince, co-founder and CEO, Cloudflare. “We’ve extended our Zero Trust services with real-time protection against new phishing sites, so our customers won’t fall victim to attacks leveraging the brands they trust.”

Also Read: Top tactics for a Strong Cloud Security Strategy

Most Impersonated Brand of 2022: AT&T Inc.

 The top 50 brands most commonly impersonated by phishing URLs are:

 1. AT&T Inc. 

2. PayPal 

3. Microsoft 

4. DHL 

5. Facebook (Meta)

6. Internal Revenue Service 

7. Oath Holdings/Verizon 

8. Mitsubishi UFJ NICOS Co., Ltd. 

9. Adobe 

10. Amazon 

11. Apple 

12. Wells Fargo & Company 

13. eBay, Inc. 

14. Swiss Post 

15. Naver 

16. Instagram (Meta)

17. WhatsApp (Meta) 

18. Rakuten 

19. East Japan Railway Company 

20. American Express Company 

21. KDDI 

22. Office365 (Microsoft) 

23. Chase Bank 

24. AEON 

25. Singtel Optus Pty 

26. Coinbase Global, Inc.

27. Banco Bradesco S.A.

28. Caixa Econômica Federal

29. JCB Co., Ltd.

30. ING Group

31. HSBC Holdings plc

32. Netflix Inc.

33. Sumitomo Mitsui Banking Corporation

34. Nubank

35. Bank Millenium SA

36. National Police Agency Japan

37. Allegro

38. InPost

39. Correos

40. FedEx

41. LinkedIn (Microsoft)

42. United States Postal Service

43. Alphabet

44. The Bank of America Corporation

45. Deutscher Paketdienst

46. Banco Itaú Unibanco S.A.

47. Steam

48. Swisscom AG

49. LexisNexis

50. Orange S.A.

Cloudflare found that finance, technology, and telecom brands were the most commonly impersonated industries, notably for the unprecedented access and financial benefit that bank accounts, email and social media, and phone companies can give attackers. Technology and telecom companies are a unique threat because phishing attacks can intercept the emails and text messages that are used to verify a user’s identity via two-factor authentication. Therefore, these phishing attempts can lead to other accounts being compromised as well.

Also Read: Top tactics for a Strong Cloud Security Strategy

The full list can be found on Cloudflare’s blog.

New Anti-Phishing Protections with Cloudflare One. Today, Cloudflare also announced new capabilities to provide customers the most comprehensive and effective phishing protection available. Building on Cloudflare Area1’s recent launch of advanced Zero Trust email security tools, customers can now automatically and immediately identify and block “confusable” domains to better protect their corporate networks. This offering can help protect against phishing attacks similar to the one that threatened Cloudflare and 100 other companies last summer, when attackers created the misleading “cloudflare-okta.com” domain just 40 minutes before sending it to employees. Using Cloudflare Gateway, customers can create zero trust rules that prevent their employees from resolving or browsing to these “confusable” or lookalike domains.

 Report Methodology

To generate the report, Cloudflare used 1.1.1.1 DNS resolver resolution data to find the domains associated with phishing URLs that were most commonly clicked. All domains that are used for shared services (like hosting sites Google, Amazon, GoDaddy) that could not be verified as a phishing attempt were removed from the data set.

For more such updates follow us on Google News ITsecuritywire News. Please subscribe to our Newsletter for more updates.