According to researchers at CheckPoint, DHL was the number one most spoofed company for phishing campaigns in the fourth quarter of 2021, pushing Microsoft to number two. According to researchers, this jump is due to the holiday shopping that is typically done around that time. Since DHL is an international shipping company, it is likely that this is the reason threat actors began spoofing them. The lures used in campaigns range from packages that are stuck at customs to embedded tracking numbers. The top ten spoofed companies were:
- DHL (related to 23% of all phishing attacks globally)
- Microsoft (20%)
- WhatsApp (11%)
- Google (10%)
- LinkedIn (8%)
- Amazon (4%)
- FedEx (3%)
- Roblox (3%)
- PayPal (2%)
- Apple (2%)