Guardian explains homoglyph attacks as scams increasingly use lookalike characters
Fraudsters exploit visually identical characters from different alphabets to create convincing fake URLs and emails.
What to know
- Homoglyph attacks use visually identical characters from different alphabets (Cyrillic, Greek, Japanese) to create fake URLs and email addresses that bypass casual inspection.
- Security experts characterize these attacks as psychological manipulation rather than technical exploits, relying on users' tendency to see what they expect under time pressure.
- The technique works because phishing has shifted from attachment-based attacks (easily detected by software) to link-based attacks, making visual deception central to the fraud.
- Users are advised to independently visit genuine websites via the address bar rather than clicking suspicious links, even if the URL appears legitimate.
The dispute Whether automated technical filtering at the provider level could prevent homoglyph attacks, or if individual user vigilance is the only realistic defense. · positions read across 2 posts and comments
Email providers should implement automated filtering to block non-Latin characters in URLs.
-
“Honestly it's a bit the fault of the email provider, if there's a non-latin character in an otherwise latin character URL, it should immediately triggers a warning and block the URL. It's not a particularly difficult check to do.”
phenix_igloo · Reddit ↗
“If any text, WhatsApp or email is asking you to log in anywhere, it is vital that you independently visit the genuine website rather than trusting the link in front of you to save a few seconds”
Jake Moore, ESET, Global security adviser · The Guardian ↗
Jake Moore Global security adviser, ESETMarijus Briedis Chief technology officer, NordVPNHilary Osborne Guardian journalist
How it unfolded 2 developments, newest first · click a bar or a number to jump articlespostscomments
-
2
Bluesky user challenges Guardian's character identification
A Bluesky user points out that the character used in the Guardian headline appears to be Greek alpha, not Cyrillic as the article claims.
“I don't think that this is a Cyrillic α, it looks like a Greek α.”
— vayiam.bsky.social -
Honestly it's a bit the fault of the email provider, if there's a non-latin character in an otherwise latin character URL, it should immediately triggers a warning and block the URL. It's not a particularly difficult check to do.
1 more of the top 2 · 2 posts in this stretch
-
V
@theguardian.com I don’t think that this is a Cyrillic α, it looks like a Greek α.
-
-
1
ESET and NordVPN experts explain homoglyph attacks as psychological exploitation
Security experts explain that homoglyph attacks succeed not through technical sophistication but by inducing panic. Jake Moore notes that phishing has shifted from attachment-based attacks to link-based ones to evade security software, while Marijus Briedis of NordVPN says fraudsters deliberately create urgency to prevent careful examination.
“The goal is to create a sense of panic so you don't look too closely at the URL. They're betting that when we're in a rush, our brains see what we expect to see…”
— Marijus Briedis, NordVPN CTO -
first by Mastodon, 4d ago · also Guardian Tech
-
-
background
Guardian publishes guide on homoglyph attack scams — The Guardian's Hilary Osborne reports that scammers increasingly use near-identical URLs created with lookalike characters from different alphabets, such as Cyrillic 'с' substituted for Latin 'c' in fake Microsoft URLs. The article features expert commentary on the technique and advice on detection.