Over 20 years in brand protection, I’ve watched a pattern play out that most brands never fully appreciate: attackers don’t just choose industries – they choose specific brands within those industries. Two companies of similar size, serving similar customers, can experience wildly different attack volumes. One gets hit repeatedly; the other is barely touched.
This isn’t random. And it’s not whack-a-mole.
Attackers are running a yield calculation. They’re asking: which brand gives us the highest return with the least friction? And they’re sharing the answers with each other. Your brand has a reputation in attacker circles – built on how fast you respond, how tight your domain posture is, and whether campaigns against you convert. Most brand owners don’t know this is happening, let alone manage it.
The Attacker Economy That Drives Targeting Decisions
Phishing attacks against brands are not improvised. Research examining 8,600+ discussions across underground forums and dark web marketplaces found that 43.8% of listings reference multi-brand phishing panels – pre-built kits targeting specific companies that are actively traded, refined, and reused. Once a playbook works against a brand, it circulates. The BlackForce phishing kit, for example, has been deployed against 11 brands including Disney, Netflix, DHL, and UPS – the same infrastructure, repurposed.
Microsoft’s consistent dominance of brand phishing reports illustrates the compounding effect. Through every quarter of 2024 and into 2025, Microsoft accounted for between 25-57% of all brand phishing attempts globally. That’s not because Microsoft is uniquely vulnerable – it’s because attackers have built and refined years of working playbooks, shared tooling, and proven infrastructure around the brand. Success begets more success.
The inverse is equally true. Brands with no established track record in attacker circles – where campaigns haven’t proven profitable – are largely left alone, even when they’re a comparable size and sector.
“Once a playbook works against a brand, it circulates. Your brand has a reputation in attacker circles whether you manage it or not.”
Why Some Brands Stay on the Target List
Once you understand that targeting is reputation-driven, the specific factors that shape that reputation become clear.
Takedown speed is the single biggest lever
If your brand consistently shuts down phishing infrastructure in 2-6 hours and a competitor takes 24-72 hours, attackers notice and redirect. Traditional manual processes operate at the 24-72 hour range while attackers can deploy new infrastructure in minutes. Best-in-class automated enforcement programmes achieve takedowns in under 60 seconds through direct registry integrations. The economic logic is simple: slow enforcement is a signal to come back. Fast enforcement is a signal to go elsewhere.
Domain hygiene signals your attack surface
Only 18% of the world’s top 10 million domains publish a valid DMARC record, and just 4% enforce a reject policy. 41% of banking institutions have no DMARC protection at all. Two similar brands can look identical on the surface but have very different domain posture - unused domains, weak SPF/DMARC configuration, exposed subdomains. Attackers gravitate toward the gaps.
A concrete example: the Better Business Bureau was receiving 10-15 million phishing emails per week impersonating their brand, sent two to three times weekly. After implementing DMARC across 500+ domains, those campaigns were virtually eliminated within weeks. The infrastructure for the attack existed; tightening domain posture removed the opportunity.
Communication inconsistency makes phishing easier to run
The less consistent a brand’s legitimate communications - varying sender domains, inconsistent templates, frequent ‘urgent’ messaging - the easier it is for phishing to blend in. Attackers target brands where the gap between legitimate and fake is small.
Ecosystem exposure expands the real attack surface
Attackers don’t always go directly at the core brand. Heavy reliance on affiliates, third-party platforms, and payment providers creates entry points that look identical to a customer. Two brands that appear equivalent on paper can have very different real-world exposure depending on how their digital ecosystem is structured.
Internal friction is an attacker’s best friend
It doesn’t matter how good your detection is if the path from detection to takedown runs through three departments with no clear owner. Fragmented ownership - legal, IT, and marketing all involved, nobody accountable - creates delays that attackers benefit from directly. Where internal friction exists, attacker ROI increases.
How to Move Off the Target List
The goal isn’t to eliminate all risk. It’s to make your brand harder, slower, and less profitable to attack than the alternative. In a market where attackers make yield calculations, you need to change the maths.
- Reduce time-to-takedown. Aim for hours, not days. Automate wherever possible. Fast, consistent enforcement is the primary deterrent - and the primary signal attackers use to decide whether to come back.
- Lock down your domain surface. Monitor permutations, enforce SPF, DKIM, and DMARC properly, and remove lookalikes quickly. The BBB example demonstrates how rapidly this changes the economics for attackers.
- Detect early. Identify campaigns at domain registration or certificate issuance, not after emails are live. Earlier disruption means lower attacker ROI.
- Standardise communications. Consistent formats, domains, and messaging reduce the believability of phishing. Remove ambiguity that attackers rely on.
- Audit your ecosystem. Your weakest external dependency is your entry point. Third parties, affiliates, and platforms all extend your attack surface.
- Centralise ownership. One accountable function from detection through to enforcement. No handoffs, no delays.
The Underlying Principle
After two decades of this work, the pattern is consistent: the brands that get targeted less aren’t necessarily better resourced or more technically sophisticated. They’re the ones that have made it harder to run a profitable campaign against them than against the next brand on the list.
Visible enforcement, rapid shutdowns, and repeat disruption build a reputation – the same way poor response builds one. In attacker circles, your brand eventually becomes known as either ‘worth running’ or ‘not worth it’.
The goal is the latter.