Reαd carefully: how to spot – and avoid – a homoglyph attack | Scams

You have read the email carefully and it appears legitimate. The link it asks you to click on doesn’t have any of the usual red flags: there are no strange numbers or extra parts in the URL. You feel safe to continue. But if you had looked a little closer, you might have noticed something slightly wrong with one of the characters. Just like in the headline of this article where instead of “a” we use the Cyrillic “α”. Scammers can use letters from different alphabets to create URLs and email addresses that look almost identical to the real thing, but actually send anyone who clicks on them to a fake website or inbox. From there they can collect personal data to use in their scams. There are other letters and symbols that can be easily changed. Last year, tech experts spotted scammers using the Japanese character hiragana ん to look like / in an address designed to look like it was on the Booking.com website. Jake Moore, global security advisor at cybersecurity firm ESET, says scammers “love Microsoft” as a corporate identity to spoof. “A fake site might use the Cyrillic “с” instead of the Latin “c” (miсrosoft v microsoft),” he says. Today, most phishing attacks are designed to direct people to links instead of downloading attachments. Photograph: Dominic Lipinski/PAMoore says this type of fraud, known as a homoglyph attack, is becoming increasingly popular. A homoglyph is a character that is very similar, or even identical, to another. “Today, most phishing attacks are designed to point people to links rather than download attachments. Attachments can be easily scanned and detected by security software if they are malicious,” he says. “Therefore, criminals should design their websites where the links look genuine and casually ask people to click on them without thinking.” Marijus Briedis, chief technology officer at NordVPN, says homoglyph attacks “are actually more of a psychological trick than a technical trick.” one,” because scammers usually try to scare you into responding quickly, rather than taking the time to check things out. “The goal is to create a sense of panic so you don’t look too closely at the URL. “They’re betting that when we’re in a hurry, our brains see what we expect to see,” says Briedis. “double quotes. It just goes to show that the split-second decision made when clicking on a link is often the most vulnerable part of the entire security chain.” What it looks likeThe real thing. Until you look closely. You will receive an email or text message suggesting that you need to click on a URL or email to resolve something. If they send you a link, take a moment to think instead of reacting immediately. Photograph: Sergey Tolmachev/Alamy Some sources make substitutions almost impossible to detect. In an email address provided in comic sans, for example, the Cyrillic a doesn’t look entirely out of place. “We’ve spent years telling people to check the website before trusting it, but the problem with this technique is that you can do exactly that and still be fooled because it may look the way it should,” Moore says. If it’s a URL, Moore says it will typically take you to a site that encourages you to enter your credentials for the actual site, including your username, password, and even a one-time passcode. what to doIf they send you a link, take a moment to think instead of reacting immediately. “If any text message, WhatsApp or email asks you to log in anywhere, it is vital that you independently visit the genuine website instead of relying on the link in front of you to save a few seconds,” says Moore. And apply the same thinking to email addresses. Type the address you know is correct, rather than clicking a link. Keep your browser updated. It will flag suspicious websites and, by keeping it up to date, detect the latest solutions from criminals. Implement two-factor authentication or multi-factor authentication (2FA or MFA), which means you have two steps to log in to a site. If you discover that your data has been compromised, change your passwords immediately. Contact your bank and report the phishing attack to Report Fraud.