The 5th Annual March Hackness: Phishing Lures After a Year Like No Other
March is back, and with it, so is our annual look at the brands cybercriminals love to impersonate. After a hiatus in 2020, we’re reviving our Phishing tournament to see how the threat landscape has shifted over a year dominated by a global pandemic.
The premise is simple: attackers exploit trust. The most effective phishing lures are the brands people interact with daily or see splashed across headlines. To build this year’s bracket, we analyzed more than 500 organizations across multiple industries that were spoofed in over 22 million phishing messages over the past year. From that data, we pulled the Top 64 companies whose brands have become the most popular baits.
While the NCAA took a year off, attackers certainly didn’t. The result is a bracket with some familiar faces and some notable newcomers.
New Players on the Court
The most significant shift in this year’s tournament is the influence of COVID-19 themes. The pandemic has introduced a new set of trusted entities into the phishing spotlight. For the first time, organizations like the World Health Organization and the Centers for Disease Control appear in our Top 64. Pharmaceutical companies, including Moderna, also make their tournament debut as cybercriminals rush to exploit vaccine-related interest.
The Usual Suspects Still Loom
Our typical heavy hitters remain well-represented. Tech and social media giants like Microsoft, Google, Facebook, and PayPal are all accounted for in this year’s field. PayPal, in particular, has a history with this tournament as our 2019 champion. The question now is whether these stalwarts can fend off the wave of new, opportunistic lures and make a deep run to the championship.
Who will cut down the nets and evade detection in this year’s tournament? We’ll be revealing the matchups soon.



