WHO Retains the Title of Most Impersonated Brand in Phishing

While the NCAA crowned its 2022 men's basketball champion, Area 1 Security has named its own winner for the year in brand phishing. For the second consecutive year, the World Health Organization (WHO) is the organization most impersonated by attackers in phishing campaigns.

Between January 2021 and January 2022, Area 1 blocked over 56 million brand phishing emails. Of those, more than 8.5 million — roughly 15% — impersonated the WHO. This period aligns with global attention on vaccine rollouts, booster shots, and the emergence of the Delta and Omicron variants. Newcomers to the list of most-targeted brands included Notion.so, Binance, and retailers from Costco to Kwik Shop, but established names still dominated the top of the rankings.

Retail and Cloud Giants Remain Prime Targets

Amazon finished as the runner-up, with attackers impersonating the company in over 3.2 million phishing emails blocked by Area 1. According to Juliette Cash, principal threat researcher at Area 1, common Amazon-themed lures include messages claiming accounts are “placed on hold,” payments have been declined, or Prime memberships have “expired.” These emails direct victims to click links that load malicious content and prompt them to enter payment details. Attackers often time these campaigns around major shopping events like Prime Day to create a sense of urgency.

Amazon has appeared in Area 1’s list of the top 64 most impersonated brands since the company began tracking the data.

The Tactics Behind Brand Impersonation

Identity deception remains straightforward for attackers, often requiring only a display name change. But more sophisticated techniques can bypass standard defenses. In one 2021 vaccine-themed phishing campaign that impersonated the CDC, attackers used a combination of tactics:

  • Display name spoofing to falsify the visible FROM header
  • An SMTP HELO command to spoof the Envelope From domain
  • Spoofing a domain that lacked email authentication protocols and no longer resolved to an IP address
  • Using a compromised host with a benign IP address to launch the attack

Microsoft also ranked in the “Final Four” of most-phished brands for the fourth straight year. Beyond impersonating Microsoft tools directly, attackers frequently use Microsoft’s own platforms — including SharePoint and Planner — to carry out credential harvesting campaigns, taking advantage of trusted infrastructure to evade legacy email defenses.

Why Brand Phishing Persists

A small number of brands account for a large share of phishing volume. According to Area 1, just 25 organizations were used in 57% of the phishing emails blocked. Three factors explain why these campaigns keep reaching inboxes:

  • Ease: Attackers can quickly register new phishing domains that exploit trusted infrastructure.
  • Speed: Setting up SPF, DKIM, and DMARC policies for new domains is fast, helping malicious emails land in inboxes.
  • Trust: Users inherently trust messages from known organizations and business partners, making it harder to spot compromised accounts without advanced email security.

Email authentication standards like SPF, DKIM, and DMARC have limits when it comes to verifying the true origin of messages. Advanced detection techniques offer a stronger line of defense. Area 1’s approach involves massive-scale web crawling to identify emerging campaign infrastructure and small-pattern analytics to spot attack formation and threats across datasets — for 800-plus brands beyond those in the annual rankings.