WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Security Awareness – DHL and Microsoft Among Top Brands Impersonated in Phishing Attacks During Third Quarter of 2022
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – DHL and Microsoft Among Top Brands Impersonated in Phishing Attacks During Third Quarter of 2022

Author: Alec Davison

Created: Thursday, November 3, 2022 - 18:34

Categories: Cybersecurity

Brand impersonation attacks, when adversaries attempt to mimic the website or domain of a well-known brand by using a similar domain name and webpage designed like the actual site, remain one of the most deceptive forms of phishing. A recent report from the IT company Check Point identifies the top brands criminals impersonated in brand phishing attacks in the third quarter of 2022.

In the third quarter of this year, DHL was the top brand impersonated by cyber threat actors, accounting for 22 percent of all phishing attempts worldwide. According to Check Point, DHL’s increase “could be due in part to a major global scam and phishing attack that the logistics giant warned about itself just days before the quarter started.” The second most impersonated brand was Microsoft, compromising 16 percent of attacks, and LinkedIn has fallen into third place, accounting for just 11 percent of scams, compared to 52 percent in Q1 and 45 percent in Q2. Other top impersonated brands include Google, Netflix, Walmart, WhatsApp, and Instagram.

Additionally, the report features an example of a brand phishing attack where DHL users are contacted via an official-looking email in an attempt to lure them to click on a malicious link to “update their delivery.” After clicking on the link, users are taken to a malicious website and prompted to log-in to the site via a fake portal where their credentials are harvested. To defend against this activity, members are reminded to always be wary of messages that require urgent actions and ones that ask a user to click on a link or open an attachment. Users should reach out to the purported sender via another means of communication to confirm its authenticity. Read more at Check Point.

Related Resources

(TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026 – Executive Summary

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar