Cybersecurity experts are warning about a growing threat known as homoglyph attacks, which use nearly identical characters from different alphabets to create deceptive URLs and email addresses aimed at tricking users into divulging sensitive information. These attacks prey on the subtle visual similarities between letters to redirect victims to fraudulent websites or fake inboxes.

In a homoglyph attack, fraudsters substitute letters in URLs or email addresses with look-alike characters from other alphabets, such as replacing the Latin letter “a” with the Cyrillic “а.” This slight variation can be difficult to detect, especially when the font used masks the difference. For example, attackers have previously exploited the Japanese hiragana character レ to imitate slashes in URLs, creating misleading links that resemble legitimate sites like Booking.com.

Jake Moore, a global security adviser at cybersecurity firm ESET, noted that attackers often target trusted companies, including Microsoft, by swapping out characters that look visually similar but are different in code, such as the Cyrillic “c” for the Latin “c.” He explained that phishing attempts have evolved to rely more on convincing links rather than malicious attachments, which security software can more easily detect. As a result, attackers focus on crafting URLs that encourage users to click quickly and without suspicion.

Marijus Briedis, chief technology officer at NordVPN, described homoglyph attacks as primarily psychological tactics. Attackers aim to create urgency and panic, reducing the likelihood that people will scrutinize URLs carefully. “They’re betting that when we’re in a rush, our brains see what we expect to see,” Briedis said. This split-second decision-making moment, he added, is often the weakest link in online security.

The threat poses a challenge for users who have been advised for years to verify website addresses before entering credentials. "You can check a URL and still be fooled because it looks like it should," Moore said. Fraudulent sites constructed via homoglyph attacks often prompt users to input their usernames, passwords, and even one-time passcodes, leading to credential theft.

To mitigate the risk, experts recommend several best practices. Users should avoid clicking on unfamiliar links in emails or text messages and instead manually type the official website address. Keeping web browsers updated is essential, as modern browsers can detect suspicious sites and warn users. Implementing two-factor or multifactor authentication adds an additional layer of security by requiring multiple verification steps during login.

If users suspect their credentials have been compromised, they should immediately change their passwords, notify their bank, and report the scam to authorities. Heightened awareness of homoglyph attacks and cautious online behavior remain crucial in combating this increasingly prevalent form of cyber fraud.