Fraudsters Deploy Homoglyph Attacks With 2FA-Baiting Fake URLs and Emails
Updated
Updated · The Guardian · Sep 20
Fraudsters Deploy Homoglyph Attacks With 2FA-Baiting Fake URLs and Emails
2 articles · Updated · The Guardian · Sep 20
Summary
Cybersecurity experts say homoglyph attacks are gaining traction, with fraudsters swapping near-identical characters from other alphabets to make fake URLs and email addresses look legitimate.
Those links usually drive victims to spoof sites that capture usernames, passwords and even one-time passcodes, as phishing shifts away from attachments that security software can more easily scan.
Examples include a fake Microsoft address using a Cyrillic “с” and a Booking.com-style link that replaced a slash with the Japanese hiragana character “ん”.
Experts say the tactic works as a psychological trick: urgent messages push users to react quickly, while some fonts make the substituted characters almost impossible to spot.
Recommended defenses include typing known web or email addresses manually, keeping browsers updated, enabling 2FA or MFA, and changing passwords and contacting banks immediately if details are compromised.