The 2022 Phishing Bracket: 56 Million Emails, 800+ Brands, One Clear Winner

March means brackets, and for the sixth year running, Area 1 Security has turned its threat intelligence toward a very specific tournament: identifying which brands attackers impersonate most in phishing campaigns. The analysis covers more than 56 million phishing emails intercepted between January 2021 and January 2022, and while attackers spoofed over 800 distinct organizations, a remarkably small set dominates the field. Just 64 brands appear in 77% of all brand phishing attempts measured.

This year's bracket reflects the shifting landscape of trust and technology. Attackers are still exploiting the same two fundamental weaknesses—which tools people use daily, and which brands they instinctively trust—but their targets of choice have evolved significantly from the early days of phishing.

Cloud Services Dominate the Attack Surface

The most striking shift is the overwhelming reliance on cloud services. Over 22% of all brand phishing attacks leveraged commonly used cloud platforms, including Amazon, Box, DocuSign, Google, Intuit, and Microsoft. This is a direct response to the hybrid and remote workforce reality: if employees live in cloud applications, attackers will follow them there.

The list also includes some newcomers that signal where the workforce is heading. Notion.so, the productivity tool that has gained viral popularity beyond its enterprise roots, appeared in the Top 64 for the first time. Meanwhile, the cryptocurrency boom has produced its own phishing ecosystem. Binance is a first-time bracket entrant this year, and while Coinbase, Metamask, Kraken, and Gemini didn't crack the Top 64, all were spoofed in thousands of phishing emails. Bitcoin itself, though not a qualifying "organization" for the bracket, was referenced in over 600,000 phishing emails during the measurement period.

The Trust Factor: Healthcare, Groceries, and the Vulnerable

Beyond technology, attackers continue to exploit institutional trust, often at society's expense. The World Health Organization, last year's "ophishal champion," and Humana both reappear in the Top 64, reflecting the lingering pandemic. Area 1 also blocked thousands of campaigns impersonating UNICEF and the Centers for Medicare & Medicaid Services—proof that the tactic of preying on the vulnerable remains effective.

Another category that has grown alongside pandemic-era habits is grocery and food retail. With over half of U.S. shoppers having started online grocery shopping after the pandemic began, the attack surface expanded accordingly. Area 1 intercepted millions of phishing emails spoofing grocers across all regions and sizes—from regional chains like Fred Meyer and Kwik Shop to national names like Costco and Amazon Fresh.

Why Brand Phishing Still Gets Through

The natural question for any organization is whether email authentication finally makes these campaigns a non-issue. The answer, according to the data, is no. SPF, DKIM, and DMARC serve legitimate security functions—validating server and tenant origins, protecting message integrity, and providing policy enforcement—but they are largely ineffective against brand phishing, particularly when the attack is a payload-less business email compromise. Attackers have found that simply asking for a reply, a wire transfer, or a gift card doesn't require breaking any cryptographic validation.

The full bracket results, including the single most-impersonated brand (responsible for a full 15% of attacks), are set to be revealed. The underlying takeaway, however, is already clear: the brands that populate an employee's inbox are precisely the ones most likely to appear in a phishing lure.