unphish
unphish unphish

Why Your Brand is Targeted for Phishing Attacks

Web Phishing Attacks

Over 20 years in brand protection, I’ve watched a pattern play out that most brands never fully appreciate: attackers don’t just choose industries – they choose specific brands within those industries. Two companies of similar size, serving similar customers, can experience wildly different attack volumes. One gets hit repeatedly; the other is barely touched.

This isn’t random. And it’s not whack-a-mole.

Attackers are running a yield calculation. They’re asking: which brand gives us the highest return with the least friction? And they’re sharing the answers with each other. Your brand has a reputation in attacker circles – built on how fast you respond, how tight your domain posture is, and whether campaigns against you convert. Most brand owners don’t know this is happening, let alone manage it.

The Attacker Economy That Drives Targeting Decisions

Phishing attacks against brands are not improvised. Research examining 8,600+ discussions across underground forums and dark web marketplaces found that 43.8% of listings reference multi-brand phishing panels – pre-built kits targeting specific companies that are actively traded, refined, and reused. Once a playbook works against a brand, it circulates. The BlackForce phishing kit, for example, has been deployed against 11 brands including Disney, Netflix, DHL, and UPS – the same infrastructure, repurposed.

Microsoft’s consistent dominance of brand phishing reports illustrates the compounding effect. Through every quarter of 2024 and into 2025, Microsoft accounted for between 25-57% of all brand phishing attempts globally. That’s not because Microsoft is uniquely vulnerable – it’s because attackers have built and refined years of working playbooks, shared tooling, and proven infrastructure around the brand. Success begets more success.

The inverse is equally true. Brands with no established track record in attacker circles – where campaigns haven’t proven profitable – are largely left alone, even when they’re a comparable size and sector.

“Once a playbook works against a brand, it circulates. Your brand has a reputation in attacker circles whether you manage it or not.”

 

Why Some Brands Stay on the Target List

Once you understand that targeting is reputation-driven, the specific factors that shape that reputation become clear.

Takedown speed is the single biggest lever

If your brand consistently shuts down phishing infrastructure in 2-6 hours and a competitor takes 24-72 hours, attackers notice and redirect. Traditional manual processes operate at the 24-72 hour range while attackers can deploy new infrastructure in minutes. Best-in-class automated enforcement programmes achieve takedowns in under 60 seconds through direct registry integrations. The economic logic is simple: slow enforcement is a signal to come back. Fast enforcement is a signal to go elsewhere.

Domain hygiene signals your attack surface

Only 18% of the world’s top 10 million domains publish a valid DMARC record, and just 4% enforce a reject policy. 41% of banking institutions have no DMARC protection at all. Two similar brands can look identical on the surface but have very different domain posture - unused domains, weak SPF/DMARC configuration, exposed subdomains. Attackers gravitate toward the gaps.

A concrete example: the Better Business Bureau was receiving 10-15 million phishing emails per week impersonating their brand, sent two to three times weekly. After implementing DMARC across 500+ domains, those campaigns were virtually eliminated within weeks. The infrastructure for the attack existed; tightening domain posture removed the opportunity.

Communication inconsistency makes phishing easier to run

The less consistent a brand’s legitimate communications - varying sender domains, inconsistent templates, frequent ‘urgent’ messaging - the easier it is for phishing to blend in. Attackers target brands where the gap between legitimate and fake is small.

Ecosystem exposure expands the real attack surface

Attackers don’t always go directly at the core brand. Heavy reliance on affiliates, third-party platforms, and payment providers creates entry points that look identical to a customer. Two brands that appear equivalent on paper can have very different real-world exposure depending on how their digital ecosystem is structured.

Internal friction is an attacker’s best friend

It doesn’t matter how good your detection is if the path from detection to takedown runs through three departments with no clear owner. Fragmented ownership - legal, IT, and marketing all involved, nobody accountable - creates delays that attackers benefit from directly. Where internal friction exists, attacker ROI increases.

How to Move Off the Target List

The goal isn’t to eliminate all risk. It’s to make your brand harder, slower, and less profitable to attack than the alternative. In a market where attackers make yield calculations, you need to change the maths.

The Underlying Principle

After two decades of this work, the pattern is consistent: the brands that get targeted less aren’t necessarily better resourced or more technically sophisticated. They’re the ones that have made it harder to run a profitable campaign against them than against the next brand on the list.

Visible enforcement, rapid shutdowns, and repeat disruption build a reputation – the same way poor response builds one. In attacker circles, your brand eventually becomes known as either ‘worth running’ or ‘not worth it’.

The goal is the latter.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account