There has been a big rise in phishing attacks designed to target smartphones as cybercriminals try to exploit our increased reliance on these tiny screens.
See also: eBike phishing websites promote scams through Google Ads

Previously, many phishing sites were device-agnostic, designed to steal usernames and passwords regardless of whether the user clicked the link on a computer or mobile device. However, cybersecurity researchers at Zimperium have analyzed hundreds of thousands of phishing sites and found that there has been a significant increase in sites designed specifically for smartphone phishing attacks, now accounting for three-quarters of all phishing sites.
The small screens of smartphones and other mobile devices make it more difficult for users to recognize phishing messages and malicious websites.
For example, the sender address is more prominent on a desktop browser than on mobile, meaning that if a user doesn't examine the email, they may not notice that it's being sent from a fake address.
See also: Phishing attacks target countries helping Ukrainian refugees
It's also harder to see the address of links on mobile devices. When using a laptop or desktop, a user can hover over the hyperlink, which can reveal the URL – potentially alerting them that it's malicious, especially if it's misspelled.
Smartphone users are not very likely to check, especially if the lure is convincing.
Phishing targeting mobile devices also offers cybercriminals an extensive variety of attack vectors, such as SMS messages, messaging apps, in-app chat links, and more, which can be used to direct victims to malicious websites.

Many of these mobile phishing sites are designed to be indistinguishable from the brand they are impersonating. Some of the top brands most commonly impersonated by phishing sites include Microsoft, Amazon, Facebook, and PayPal, as well as a number of delivery companies related to the region targeted by each campaign.
Users can help themselves by being extra cautious. If an email notification or text message claims to be from a particular brand, rather than clicking the link in the email, it's often wiser to go to the brand's actual website in your browser and log in to your account from there.
See also: Phishing: Chinese hackers target European diplomats
Anyone who suspects that one of their accounts has been the victim of a phishing attack should change their password immediately.
Information source: zdnet.com
