Updated
Updated · The Guardian · Sep 20
Fraudsters Deploy Homoglyph Attacks With 2FA-Baiting Fake URLs and Emails
Updated
Updated · The Guardian · Sep 20

Fraudsters Deploy Homoglyph Attacks With 2FA-Baiting Fake URLs and Emails

2 articles · Updated · The Guardian · Sep 20

Summary

  • Cybersecurity experts say homoglyph attacks are gaining traction, with fraudsters swapping near-identical characters from other alphabets to make fake URLs and email addresses look legitimate.
  • Those links usually drive victims to spoof sites that capture usernames, passwords and even one-time passcodes, as phishing shifts away from attachments that security software can more easily scan.
  • Examples include a fake Microsoft address using a Cyrillic “с” and a Booking.com-style link that replaced a slash with the Japanese hiragana character “ん”.
  • Experts say the tactic works as a psychological trick: urgent messages push users to react quickly, while some fonts make the substituted characters almost impossible to spot.
  • Recommended defenses include typing known web or email addresses manually, keeping browsers updated, enabling 2FA or MFA, and changing passwords and contacting banks immediately if details are compromised.

Insights

Could the global push for inclusive internet alphabets be the exact loophole cybercriminals use to steal your digital identity?
Why are standard two-factor authentication methods failing to protect you against these invisible lookalike domain attacks?
If identical URLs and standard security locks can no longer be trusted, how can you truly verify the website you are visiting?