LinkedIn is now the most imitated brand by cybercriminals

LinkedIn
(Image credit: 13_Phunkod / Shutterstock.com)

The job site and professional social network LinkedIn accounted for more than half of all brand phishing attacks during the first quarter of this year.

According to Check Point Research (CPR), this is the first time that LinkedIn has taken the top spot in its 2022 Q1 Brand Phishing Report. The professional social network was impersonated in 52 percent of all phishing attacks globally during Q1 which marks a dramatic, 44 percent increase from the previous quarter.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

At the same time, CPR’s new report shows that cybercriminals now prefer to leverage social networks over shipping companies and tech giants including Google, Microsoft and Apple.

As for the rest of the companies whose brands are frequently used in phishing attempts, global shipping company DHL took the second spot at 14 percent, followed by Google (7%), Microsoft (7%) and FedEx (6%). Besides these companies, Amazon, Maersk, AliExpress, Apple and WhatsApp rounded out CPR’s top 10 list with Meta-owned WhatsApp accounting for almost 1 in 20 phishing-related attacks worldwide.

Brand phishing attacks

For those unfamiliar, in a brand phishing attack, cybercriminals attempt to imitate the official website of a well-known company by using a similar domain name and webpage design. 

From here, links to fake websites are sent to targeted individuals by email or text message. These fake websites also often contain a form intended to steal user credentials, payment details or other personal information.

Data research group manager at Check Point Software, Omer Dembinsky explained in a blog post how the cybercriminals behind brand phishing attacks will also try to deploy malware on company networks in addition to stealing sensitive personal and business information, saying:

“These phishing attempts are attacks of opportunity, plain and simple. Criminal groups orchestrate these phishing attempts on a grand scale, with a view to getting as many people to part with their personal data as possible. Some attacks will attempt to gain leverage over individuals or steal their information, such as those we’re seeing with LinkedIn. Others will be attempts to deploy malware on company networks, such as the fake emails containing spoof carrier documents that we’re seeing with the likes of Maersk. If there was ever any doubt that social media would become one of the most heavily targeted sectors by criminal groups, Q1 has laid those doubts to rest.” 

In order to avoid falling victim to brand phishing attacks, CPR recommends that users remain cautious when divulging personal data and credentials to business applications or websites, think twice before opening email attachments or links, look for misspellings in emails and the domains used by websites and beware of urgent requests such as "change your password now".

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Perplexity Squid Game Ad
New ad declares Squid Game's real winner is Perplexity AI
Pedro Pascal in Apple's Someday ad promoting the AirPods 4 with Active Noise Cancellation.
Pedro Pascal cures his heartbreak thanks to AirPods 4 (and the power of dance) in this new ad
Frank Grimes confronts Homer Simpson in The Simpsons' Homer's Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Nvidia GR00T N1 humanoid robot
Nvidia is dreaming of trillion-dollar datacentres with millions of GPUs and I can't wait to live in the Omniverse
Foldable iPhone
Apple’s first foldable iPhone could beat the Samsung Galaxy Z Fold 7 in one key way