Technology
Trending

Check Point Research Unveils Q2 2025 Brand Phishing Trends: Microsoft Maintains Lead, Spotify Reenters Top Rankings

Technology and Digital Services Continue to Dominate Phishing Landscape, Highlighting Growing Threat to Consumer Trust

Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies Ltd. (NASDAQ: CHKP) and  a pioneer and global leader of cyber security solutions, has released its latest Brand Phishing Ranking for Q2 2025. The report outlines the brands most frequently impersonated by cybercriminals to steal sensitive personal and financial information, underscoring the persistent evolution of phishing tactics.

In Q2 2025, Microsoft retained its position as the most targeted brand, appearing in 25% of all phishing attempts. Google followed in second place with 11%, and Apple held third at 9%. In a notable development, Spotify reentered the top 10 list for the first time since Q4 2019, ranking fourth with 6% of phishing activity. The Technology sector remained the most impersonated industry, followed by Social Networks and Retail.

Omer Dembinsky, Data Research Manager at Check Point Software, commented: “Cybercriminals continue to exploit the trust users place in well-known brands. The resurgence of Spotify and the surge in travel-related scams especially in light of the upcoming summer and school holiday travel, show how phishing attacks are adapting to user behavior and seasonal trends. Awareness, education, and security controls remain critical to reducing the risk of compromise.”

Top 10 Targeted Brands in Q2 2025

Below are the brands most frequently targeted by phishing attacks during Q2 2025:

  1. Microsoft – 25%
  2. Google – 11%
  3. Apple – 9%
  4. Spotify – 6%
  5. Adobe – 4%
  6. LinkedIn – 3%
  7. Amazon – 2%
  8. Booking – 2%
  9. WhatsApp – 2%
  10. Facebook – 2%

Phishing Campaign Impersonating Spotify

One of the most prominent phishing attacks this quarter targeted Spotify users. Cybercriminals created a malicious login page hosted at:

premiumspotify[.]abdullatifmoustafa0[.]workers.dev, which redirects users to activegate[.]online/id1357/DUVzTTavlOw/CgJiMcgc0fMOJY29SAg5JRoH?.

The malicious page replicated the official Spotify login experience, complete with authentic branding and design. Victims were asked to enter their usernames and passwords, which were then funneled to a fake payment page that attempted to steal credit card details as well.

This campaign marks Spotify’s first reappearance in phishing top charts since Q4 2019—and underscores how entertainment services are now being exploited just as aggressively as tech platforms.

Fradulent Spotify Login Page
Fraudulent Spotify Payment Page

Booking.com Confirmation Scam Surge

Another major trend in Q2 was the sharp increase in Booking.com-themed phishing domains, with over 700 new domains registered using the confirmation-id****.com format. This represents a 1000% increase compared to earlier in the year.

Sample phishing domain:

Many of these domains embedded real user data, such as names and contact details, to enhance credibility and urgency. Although these sites were short-lived, they illustrate the increasing personalization and targeting capabilities of phishing campaigns.

Industry Trends: Technology and Digital Platforms Under Siege

The Technology sector continued to dominate as the most impersonated industry in phishing attacks during Q2 2025. Tech giants like Microsoft, Google, and Apple remain prime targets due to their widespread use in authentication and productivity workflows.

Social media platforms like LinkedIn, WhatsApp, and Facebook also remained high-risk targets. The Retail and Travel sectors—including Amazon and Booking.com—were exploited by attackers seeking to capitalize on seasonal shopping and travel activity.

The Check Point Brand Phishing Ranking is published quarterly and is based on data drawn from Check Point’s ThreatCloud AI platform—the world’s largest collaborative cyber threat intelligence network. The report analyzes phishing emails, fake websites, and impersonation attempts across multiple vectors.

Related Articles

Back to top button

Adblock Detected

Please Turnoff the adblocker!