Microsoft the top of the list of companies that malicious users choose to impersonate when they want to "fish" their victims.
According to Vade Secure – a company that tracks phishing URLs and publishes a quarterly list of 25 companies that are favorite bait for hackers – in the third quarter of 2018, Microsoft was in first place, while in the second quarter we find Pay Pal. Netflix, Bank of America and Wells Fargo complete the top five
Vade Secure highlighted that more than half of phishing URLs belong to both cloud- based services and services whose main activity is money transfer and payments .
If you're wondering why Microsoft is the favorite choice of phishers, the answer is very simple: The main goal of phishing attacks on Microsoft accounts is to collect Office 365. credentials

“With a single set of credentials, hackers can gain access to a treasure trove of confidential files, data, and contacts stored in Office 365 applications,” Vade Secure said in its report. It went on to say that malicious users can use compromised Office 365 accounts to carry out new attacks (phishing, malware).
On the other hand, PayPal and Netflix accounts are quite tempting for phishers as they offer immediate financial repayment (PayPal) and valuable personal credit card information (Netflix) which they can sell on the dark web.
If we want to take a look at the ranking of the list beyond the main five, in 6th place we find Facebook, in 7th Chase , in 8th Orange , in 9th DHL and in 10th Dropbox . Amazon , ING, RBC and BT are in much lower positions than the main 25, while Comcast, NBC, AmEx and CIBC make their first appearance in it.

Good to know that:
- Microsoft phishing emails are sent during the week.
- Bank of America phishing emails are sent during the weekend when branches and customer service lines are closed.
- On Sundays, a higher rate of phishing is observed on Netflix as during the weekend—especially Sunday—most of us relax watching a movie/series.
In conclusion, it is worth noting that phishing is on the rise! The total number of phishing URLs increased by 20.4% for the third quarter of 2018.
Don’t be a fish, be safe!
