Pandemic Lockdowns Opened a New Market: Wine Phishing

When offices closed and social lives moved to video calls, wine became part of the workday in a way it rarely had before. Virtual happy hours turned a drink after work into a scheduled team event, and specialty cocktail and wine delivery services grew alongside that trend. Cybercriminals, as they tend to do, followed the attention.

Researchers at Recorded Future, working with Area 1 Security, tracked a sharp rise in wine-themed domain registrations beginning in early 2020. The increase correlated directly with the start of widespread lockdowns and the associated surge in at-home drinking and virtual socializing.

Wine Domain Registrations More Than Doubled

The research team queried newly registered domains containing one or more of a set of wine-related keywords: wine, vino, champagne, bordeaux, burgundy, chardonnay, merlot, cabernet, sauvignon, and pinot. Terms like rosé or napa were excluded to avoid false positives, and less popular grape names such as riesling did not contribute meaningfully to the totals.

Before March 2020, new wine-themed domain registrations held steady between 3,000 and 4,000 per month. That baseline shifted quickly:

  • March 2020: ~5,500 registrations
  • April 2020: ~7,200 registrations
  • May 2020: 12,400 registrations

From June 2020 through March 2021, monthly registrations fluctuated between 7,000 and 9,500 — roughly two to three times the pre-pandemic rate. In total, 96,489 wine-related domains containing the listed keywords were registered between April 2020 and March 2021.

BLOG-1441 Embedded Image - Qi05SU

Malicious registrations — defined by Recorded Future as domains scored Suspicious, Malicious, or Very Malicious — followed a similar but shifted trajectory. Activity peaked in May 2020 with 668 malicious wine-themed domains registered, down from an April spike of 278, then settled into a monthly range of 230 to 430. The 12-month total reached 4,389 malicious wine-themed domains.

Attackers Were Slow to Adapt

Cybercriminals took time to catch on to the wine trend. Malicious registrations as a share of total wine-themed domains peaked in June 2020 at 7%, then fell to a range of 3-5% for the remainder of the tracking period. That is low relative to other event-driven phishing themes, such as COVID-19-related domain abuse.

BLOG-1441 Embedded Image - Tr5aX3

Spam Did Most of the Heavy Lifting

Working with Area 1 Security, researchers examined how these newly registered wine domains were actually used in email campaigns from April 2020 through April 1, 2021. Area 1 caught more than 25,000 emails using wine domains in attacks on companies ranging from Fortune 500 firms to small and medium-sized businesses across industries including consumer products, financial services, healthcare, and aerospace.

Breakdown of the campaigns:

  • 74.71% classified as spam — potentially early-stage reconnaissance
  • ~13.5% contained suspicious or malicious links or files
  • 11.74% were Type 1 Business Email Compromise (BEC) phishing, attempting to impersonate a recognized sender
  • 0.03% were Type 3 and Type 4 BEC phishing — more sophisticated attacks tied to significant business losses
BLOG-1441 Embedded Image - S84Wny

One example observed by Area 1 involved a voicemail phishing campaign that Microsoft Office 365 failed to detect. The malicious link routed to a subdomain of lueriawinery[dot]com.

BLOG-1441 Embedded Image - OJ9KtC

Practical Defenses

Wine is just the latest in a series of topical lures. Phishers have shown they can pivot quickly, moving between COVID-19 themes, online retail interest, and food delivery apps as circumstances change. Awareness training should make clear that attackers are opportunistic and will swap lures to match public interest.

Beyond training, filtering suspicious email at the perimeter prevents the message from ever reaching an employee. Organizations running their own email servers face a near-impossible task maintaining perfect security; cloud email platforms such as Google GSuite or Microsoft Office 365 combined with a cloud email security solution offer a better baseline. Layering Recorded Future and Area 1 Security intelligence on top of those inbox providers completes a defense-in-depth approach to email protection.