WHO Tops the 2021 Phishing Bracket

Area 1 Security’s annual March Hackness tournament has a new champion — and it’s not the kind of win any organization wants on its résumé. The World Health Organization took the top spot as the most impersonated brand of the past year, with researchers logging over 2 million phishing spoofs exploiting the WHO brand between May 2020 and February 2021, out of more than 22 million total spoof- and impersonation-based attacks analyzed.

BLOG-1440 Embedded Image - Bfv12l

The shift reflects a broader trend: attackers pivot to whatever dominates the headlines. COVID-19 and the U.S. Presidential Election heavily shaped phishing campaigns in 2020. In one example, a phishing message posed as the WHO offering safety measures against the virus, but the true sender was an unrelated domain. The attacker added the WHO logo to lend legitimacy and hosted the fraudulent site on Appspot.com, a legitimate Google cloud platform domain that is frequently whitelisted and therefore less likely to be flagged. The login page was designed to capture credentials and forward them to an attacker-controlled server.

BLOG-1440 Embedded Image - s11Mtk

Newcomers and Upsets in the Bracket

Beyond the WHO, the annual bracket included a number of first-time entrants alongside expected names like Moderna (#25) and the CDC (#48). Newcomers to the list this year included:

  • #7 — Marketo
  • #20 — Columbia Sportswear
  • #24 — UPS
  • #38 — CNN
  • #50 — Zoom
  • #51 — Adidas
  • #53 — Nike
  • #63 — Zillow

There were also notable upsets. PayPal, which topped the bracket in 2017 and 2019, failed to make the Sweet 16 this time around.

Why Authentication Isn’t Enough

The 2021 results highlight a key limitation of email authentication standards. SPF, DKIM, and DMARC were designed to help legitimate brands deliver their email properly — not to defend against sophisticated phishing. Area 1’s co-founder and CSO Blake Darché and principal security researcher Javier Castro demonstrated how easy it is for attackers to stand up a DMARC-passing phishing domain in real time.

Even when DMARC is deployed for a domain, attackers can still:

  • Spin up new phishing domains that exploit trusted infrastructure
  • Quickly configure DMARC, SPF, and DKIM for those domains to reach inboxes
  • Evade detection without additional analysis beyond email authentication

Effective phishing defense requires more than authentication checks — it demands comprehensive message analysis, computer vision, and domain registration scrutiny.

Key Takeaways from the Tournament

  • The top four seeds appeared in over 6 million phishing attacks.
  • The top 10 brands accounted for more than 56% of all spoof- and impersonation-based phishing.
  • The 64-brand bracket spanned 15 industries, with technology and financial services/banking most heavily represented.
  • Attackers ride the news cycle: COVID-19 and the election season were the dominant lures of the year.