Microsoft Accounts for 40% of All Phishing Attacks in Q3 2025

Microsoft Accounts for 40% of All Phishing Attacks in Q3 2025

Check Point Research (CPR), the Threat Intelligence arm of Check Point Software, released its Brand Phishing Report for Q3 2025. The latest findings reveal a significant surge in brand impersonation attacks targeting users’ most trusted digital services, with Microsoft once again the most exploited brand, appearing in 40% of all phishing attempts worldwide – a significant rise that highlights attackers’ growing focus on widely used productivity platforms.

The dominance of familiar tech brands shows no sign of slowing. Google (9%) and Apple (6%) ranked second and third respectively, and together, these three companies accounted for more than half of all phishing activity in the last quarter. PayPal and DHL made notable re-entries into the global top 10 after a long absence, landing in 6th and 10th place, reflecting a widening attacker focus across digital payments and logistics services – critical vectors for both consumers and enterprises.

Omer Dembinsky, Data Research Manager at Check Point Software, commented, “Phishing is no longer just about misspelled emails or poorly designed login pages — it’s now AI-generated, hyper-personalized, and deeply deceptive. The fact that 40% of phishing attempts now impersonate Microsoft, and that familiar brands like PayPal and DHL are making a comeback, shows how attackers are doubling down on the services and everyday tools that users trust most. Combating this next wave of phishing requires a prevention-first approach, combining AI-driven security tools with strong authentication and continuous user education.”

Top 10 Most Imitated Brands in Q3 2025

  1. Microsoft – 40%
  2. Google – 9%
  3. Apple – 6%
  4. Spotify – 4%
  5. Amazon – 3%
  6. PayPal – 3%
  7. Adobe – 3%
  8. com – 2%
  9. LinkedIn – 2%
  10. DHL – 2%

PayPal and DHL Make a Comeback as Cybercriminals Broaden Their Targets
After several quarters off the list, PayPal and DHL have re-entered the global top 10, ranking 6th and 10th, respectively.

Their return reflects cybercriminals’ growing focus on financial services and logistics platforms—domains where trust and urgency can be easily manipulated to maximize the success of phishing attempts.

Check Point researchers uncovered a fraudulent DHL website (dhl-login-check[.]org) that mirrored the courier’s official login page and tricked users into entering login and email credentials, phone numbers, and home addresses. For victims, the experience would appear routine, just another package-tracking sign-in, until their personal data was quietly harvested behind the scenes.

In a similar case, Check Point Research identified another masquerading PayPal phishing site (paypal-me[.]icu) which promised fake rewards using social engineering tactics, luring users into revealing sensitive information including passwords, login credentials, and credit card details.

By blending the familiar look and feel of trusted brands with emotional triggers like urgency or reward, attackers continue to blur the line between legitimate and fraudulent online experiences. 

Continued Focus of Sector Attacks on Technology Organisations
The Technology sector maintained its position as the most targeted industry in Q3 2025, followed by social networks and retail, underscoring how attackers continue to exploit the digital services people depend on every day, including heavily-used e-commerce and professional sites. As we enter the big shopping season, it is expected to see an increase in such phishing scams across the travel and logistics services, with hackers exploiting users’ trust during the coming holiday season.

 

Humanoids are the future of workforce

Humanoids are the future of workforce

Zeeshan Mehdi, Engineering Director for the Middle East at SoftServe,…
Hidden risks of browser extensions

Hidden risks of browser extensions

Phil Muncaster, guest writer at ESET, explains that not all browser…
Pillars of modern digital transformation

Pillars of modern digital transformation

Prithika Sharone Rosaline, Enterprise Analyst at ManageEngine, explains that…
Pentera Acquires DevOcean to Automate Cyber Risk Remediation

Pentera Acquires DevOcean to Automate Cyber Risk Remediation

Pentera announced the acquisition of DevOcean, an AI-Remediation…
Calo raises $39 million in Series B extension

Calo raises $39 million in Series B extension

Calo, the Middle East’s largest foodtech startup revolutionizing personalized meal subscriptions, has…
Push Security secures $30 million Series B funding

Push Security secures $30 million Series B funding

Push Security, a pioneer in detecting and responding to modern identity attacks…