The Federal Bureau of Investigation (FBI) has issued a warning about recently identified phishing campaigns targeting customers of “brand companies” in attacks known as “brand phishing”.

See also: Phishing email threatens influencers with deletion of their TikTok accounts
This warning was issued as a public service announcement through the office's Internet Crime Complaint Center platform, in coordination with DHS's Cybersecurity and Infrastructure Security Agency (CISA).
Targets are sent to phishing landing pages through various means, including spam emails, text messages, or web and mobile applications that may spoof a company's identity or official website address.
Attackers embed login forms or malware into their phishing pages with the ultimate goal of stealing their victims' user credentials, payment details, or various other types of personally identifiable information (PII).
In addition to these ongoing phishing attacks, threat actors are likely developing tools to trick potential targets into revealing information to bypass two-factor authentication (2FA).
See also: Phishing campaign used Proofpoint to scam users
“ When cybercriminals gain access to a consumer’s email accounts, they may be able to intercept emails with 2FA codes that are used to make important changes to online accounts, update passwords, verify user access, or change security rules and settings before the account holder is aware and informed ,” the federal law enforcement agency said
According to Check Point's Q2 2021 Brand Phishing Report, the top five brands featured in brand phishing attempts are Microsoft (45% of all brand phishing attempts worldwide), DHL (26%), Amazon (11%), Bestbuy (4%), and Google (3%).
The FBI encouraged private sector partners to remain vigilant and evaluate their internal security policies and provide their consumers with information about account security protocols.
If you are a victim of a brand phishing attack, you should contact your local law enforcement agency or FBI office and report the incident immediately.

See also: Phishing emails infect victims with MirCop ransomware
Consumers are advised to follow these recommendations to defend against phishing attempts:
- Be wary of unsolicited contact via email or social media from anyone you do not know personally and/or that contains messages that entice you to open a link or attached file.
- When you receive account notifications, instead of clicking a link within an email or text, choose to navigate to the website using the secure URL to check any logs, messages, or notifications.
- Carefully verify the spelling of web addresses, websites, and email addresses that appear trustworthy but may be imitations of legitimate websites.
- Use strong, unique passwords and don't reuse the same password across multiple accounts.
- Do not store important documents or information in your email account (e.g., private digital currency keys, documents with your social security number, or photocopies of your driver's license).
- Enable 2FA and/or multi-factor authentication (MFA) options to help secure online accounts, such as a phone number, software-based authenticator programs/apps, a USB security key, or a separate email account (with a unique password that is not associated with other accounts) to receive authentication codes for account logins, password resets, or updates to sensitive account information.
- When possible, do not use your primary email address for logins to Websites. Create a unique username that is not associated with your primary email address.
