Homoglyph Attacks Use Fake Characters to Trick Email Users
Scammers are embedding near-identical foreign characters in URLs to bypass scrutiny. Here's how to spot the threat.
Cybercriminals are deploying an increasingly sophisticated phishing technique that exploits the human eye's inability to distinguish between visually similar characters — a method known as a homoglyph attack. Victims who believe they are clicking a legitimate link may in fact be directed to a malicious site, because a single character in the URL has been quietly swapped for a near-identical counterpart from a foreign alphabet.
The tactic works by substituting standard Latin letters with lookalike characters drawn from scripts such as Cyrillic. A URL that appears to read microsoft.com, for example, may contain a Cyrillic "с" in place of the standard Latin "c" — rendering the two addresses visually indistinguishable to most readers at a glance, while pointing to entirely different destinations on the internet.
Read more Tariffs, Fuel Costs and Rates Squeeze US Businesses →
The Guardian demonstrated the technique in the headline of its own report, replacing the Latin "a" with the Cyrillic "α" — a substitution that the vast majority of readers would not catch without deliberate, character-by-character scrutiny. Security experts note that the moment a user decides whether to click a link is frequently the weakest point in any organization's or individual's security posture.
The broader concern is psychological as much as technical. Phishing campaigns have long relied on urgency and superficial legitimacy to override caution. Homoglyph attacks add a further layer of deception by defeating even careful visual inspection, removing one of the last lines of defense that security-conscious users rely upon. Analysts warn that standard advice — telling people to "read the URL carefully" — may no longer be sufficient protection against this category of threat.
Continue reading at Business | The Guardian.