
Reñd carefully: how to spot â and avoid â a homoglyph attack
Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miÃÂrosoft.com
YouâÂÂve read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. You feel safe to proceed.
But if you had looked slightly closer you may have noticed something slightly wrong with one of the characters. Just as in the headline of this piece where instead of âÂÂaâ we used the Cyrillic âÂÂñâÂÂ.
Fraudsters can use letters from different alphabets to create URLs and email addresses that look almost identical to the real thing, but in reality send anyone who clicks on them to a spoof website or inbox. From there they can harvest personal details to use in their scams.
There are other letters and symbols that are easily switched. Last year tech experts spotted fraudsters using the Japanese hiragana character ã to look like a / in an address designed to look as though it was on Booking.comâÂÂs website.
Jake Moore, global security adviser at cybersecurity company ESET, says the fraudsters âÂÂlove Microsoftâ as a company identity to spoof. âÂÂA fake site might use the Cyrillic âÂÂÃÂâ instead of the Latin âÂÂcâ (miÃÂrosoft v microsoft),â he says.

Moore says this type of fraud â known as a homoglyph attack â is becoming increasingly popular. A homoglyph is a character that looks very similar, or even identical, to another one.
âÂÂMost phishing attacks are designed to point people to links these days instead of downloading attachments. Attachments can easily be scanned and caught by security software if malicious,â he says.
âÂÂTherefore, criminals need to design their websites where the links look genuine and casually request people to click on them without thinking.âÂÂ
Marijus Briedis, chief technology officer at NordVPN, says homoglyph attacks âÂÂare really more of a psychological trick than a technical oneâÂÂ, because the fraudsters are typically trying to panic you into responding quickly, rather than taking time to check things out.
âÂÂThe goal is to create a sense of panic so you donâÂÂt look too closely at the URL. TheyâÂÂre betting that when weâÂÂre in a rush, our brains see what we expect to see,â Briedis says.
It just goes to show that the split-second decision you make when clicking a link is often the most vulnerable part of the whole security chain.âÂÂ
What it looks like
The real thing. Until you look closely.
You will receive an email or text message suggesting you need to click on a URL or email to sort something out.

Some fonts make substitutions almost impossible to detect. In an email address given in comic sans , for example, the Cyrillic a does not look at all out of place.
âÂÂWeâÂÂve spent years telling people to check the website before trusting it but the problem with this technique is that you can do exactly that and still be fooled as it can look as it should,â says Moore.
If itâÂÂs a URL, Moore says typically it will lead to a site that encourages you to enter your credentials for the real site, including your username, password and even a one-time passcode.
What to do
If you are sent a link, take a moment to think rather than reacting immediately.
âÂÂIf any text, WhatsApp or email is asking you to log in anywhere, it is vital that you independently visit the genuine website rather than trusting the link in front of you to save a few seconds,â says Moore.
And apply the same thinking to email addresses. Type in the address you know to be correct, rather than clicking on a link.
Keep your browser updated. It will flag up suspicious websites, and by keeping it updated it will catch the criminalsâ latest workarounds.
Put in place two-factor authentication, or multifactor authentication (2FA or MFA), which means you have two steps to log into a site.
If you find that your details have been compromised, change your passwords immediately. Contact your bank and report the phishing attack to Report Fraud.
