Check Point Research (CPR), the Threat Intelligence arm of Check Point Software Technologies Ltd., has released its Brand Phishing Ranking for a Q2 2025, revealing the brands most exploited by cybercriminals in phishing attacks.
According to the report, Microsoft remained the most impersonated brand globally, appearing in 25% of phishing attempts. Google followed at 11%, with Apple at 9%. In a notable shift, Spotify reentered the top 10 for the first time since Q4 2019, ranking fourth at 6%.
The Technology sector remained the most targeted industry, followed by Social Networks and Retail platforms.
“Cybercriminals continue to exploit the trust users place in well-known brands. The resurgence of Spotify and the surge in travel-related scams, especially in light of summer and school holiday travel in the Northern Hemisphere, show how phishing attacks are adapting to user behavior and seasonal trends. Awareness, education, and security controls remain critical to reducing the risk of compromise,” said Omer Dembinsky, data research manager at Check Point Software.
Top 10 Targeted Brands in Q2 2025
Below are the brands most frequently targeted by phishing attacks during Q2 2025:
- Microsoft – 25%
- Google – 11%
- Apple – 9%
- Spotify – 6%
- Adobe – 4%
- LinkedIn – 3%
- Amazon – 2%
- Booking – 2%
- WhatsApp – 2%
- Facebook – 2%
Top 10 Personalities Driving Cybersecurity Revolution in 2025
Phishing Campaign Impersonating Spotify
One of the most prominent phishing attacks this quarter targeted Spotify users. Cybercriminals created a malicious login page, which replicated the official Spotify login experience, complete with authentic branding and design. Victims were asked to enter their usernames and passwords, which were then funneled to a fake payment page that attempted to steal credit card details as well.
This campaign marks Spotify’s first reappearance in phishing top charts since Q4 2019—and underscores how entertainment services are now being exploited just as aggressively as tech platforms.
Booking.com Confirmation Scam Surge
Another major trend in Q2 was the sharp increase in Booking.com-themed phishing domains, with over 700 new domains registered using the confirmation-id****.com format. This represents a 1000% increase compared to earlier in the year.
Sample phishing domain:
Many of these domains embedded real user data, such as names and contact details, to enhance credibility and urgency. Although these sites were short-lived, they illustrate the increasing personalisation and targeting capabilities of phishing campaigns.
Industry Trends: Technology and Digital Platforms Under Siege
The Technology sector continued to dominate as the most impersonated industry in phishing attacks during Q2 2025. Tech giants like Microsoft, Google, and Apple remain prime targets due to their widespread use in authentication and productivity workflows.
Social media platforms like LinkedIn, WhatsApp, and Facebook also remained high-risk targets. The Retail and Travel sectors—including Amazon and Booking.com—were exploited by attackers seeking to capitalise on seasonal shopping and travel activity.
The Check Point Brand Phishing Ranking is published quarterly and is based on data drawn from Check Point’s ThreatCloud AI platform—the world’s largest collaborative cyber threat intelligence network. The report analyses phishing emails, fake websites, and impersonation attempts across multiple vectors.