sözaltı news Finance
Finance
EN AZ
Reαd carefully: how to spot – and avoid – a homoglyph attack

Reαd carefully: how to spot – and avoid – a homoglyph attack

theguardian.com 20.09.2026 08:00 1 views
Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miсrosoft.comYou’ve read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual

The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. You feel safe to proceed. But if you had looked slightly closer you may have noticed something slightly wrong with one of the characters.

Just as in the headline of this piece where instead of “a” we used the Cyrillic “α”. Fraudsters can use letters from different alphabets to create URLs and email addresses that look almost identical to the real thing, but in reality send anyone who clicks on them to a spoof website or inbox. From there they can harvest personal details to use in their scams.

There are other letters and symbols that are easily switched. Last year tech experts spotted fraudsters using the Japanese hiragana character ん to look like a / in an address designed to look as though it was on Booking.com’s website. Jake Moore, global security adviser at cybersecurity company ESET, says the fraudsters “love Microsoft” as a company identity to spoof.

Moore says this type of fraud – known as a homoglyph attack – is becoming increasingly popular. A homoglyph is a character that looks very similar, or even identical, to another one. Attachments can easily be scanned and caught by security software if malicious,” he says.

They’re betting that when we’re in a rush, our brains see what we expect to see,” Briedis says. It just goes to show that the split-second decision you make when clicking a link is often the most vulnerable part of the whole security chain.” You will receive an email or text message suggesting you need to click on a URL or email to sort something out. Some fonts make substitutions almost impossible to detect.

In an email address given in comic sans gill, for example, the Cyrillic a does not look at all out of place. If it’s a URL, Moore says typically it will lead to a site that encourages you to enter your credentials for the real site, including your username, password and even a one-time passcode. If you are sent a link, take a moment to think rather than reacting immediately.

Extract — continue reading at the source.

Read full story