You're gonna need some help recognizing this phishing scam

How do you spot a phishing scam when the URL looks perfectly legit?
 By 
Colin Daileda
 on 
You're gonna need some help recognizing this phishing scam
Credit: boris Reossler/Epa/REX/Shutterstock

How do you spot a phishing scam when the URL looks perfectly legit?

An old phishing technique has recently popped back up in the news, and it has the potential to fool some folks no matter how many times they inspect a URL for typos.

Phishing works like this: Some fool sends people an email that asks readers to please click on this link or download this thing. The person sends the link from a URL with a (theoretically) clever typo (think yhaoo.com instead of yahoo.com). But this other kind of phishing scheme -- called a homograph attack -- sends an email from a URL that looks nearly identical to the real thing, replacing some the letters with similar ones from other alphabets.

Look at this example of the real apple.com and an imposter created by web developer Xudong Zheng, who brought renewed attention to homograph attacks by writing about them on April 14.

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

A homograph attack replaces all the letters in a URL with similar or identical letters from non-English alphabets such as Cyrillic.

Here's how it works: Zheng's fake "apple.com" is actually a translation. Its true URL looks like this: "xn--80ak6aa92e.com."

That keyboard vomit means nothing to me, but this arrangement of letters and dashes and numbers corresponds to Cyrillic letters. It's written in unicode, a coding standard that pulls from a wide range of letters and numbers and whatever else. But, with the help of a separate tool called punycode, that illegible URL is translated into something called American Standard Code for Information Interchange, which renders URLs in English. Thus, that unreadable mess becomes a fake apple.com.

This is an issue for anyone using Firefox, Chrome and several less popular browsers, though not for folks using Safari or Internet Explorer. But while the regular URLs are seemingly impossible to distinguish from the bad ones, the fix is still relatively simple (if kind of annoying).

If you get an email you're not sure about, and it asks you to click on a link, don't. Instead, Zheng suggests, type it out into a browser or a search engine. This will take you to the legitimate link, if there is such a thing. A few seconds of extra key-tapping could save you a whole lot of malware issues.

Another bit of good news: Zheng says homograph attacks aren't all that common because once a Cyrillic-based URL is blacklisted, it's pretty much useless. Homograph attacks only work if each letter of the real URL is replaced with a letter from a different alphabet. If a Cyrillic-based site gets blacklisted, the phisher can't just come back with a different fake arrangement of letters and try again.

In less good news, Zheng says homograph attacks often aren't necessary. Phishers trick plenty of people with schemes that aren't so complex.

Mashable Image
Colin Daileda

Colin is Mashable's US & World Reporter. He previously interned at Foreign Policy magazine and The American Prospect. Colin is a graduate from Columbia University Graduate School of Journalism. When he's not at Mashable, you can most likely find him eating or playing some kind of sport.

Mashable Potato

Recommended For You
Meta rolls out Facebook scam warnings
Meta rolls out scam protection warnings to Facebook, Instagram


This AI-powered app listens as you play to help you learn piano
Skoove Premium Piano Lessons: Lifetime Subscription

Get instant AI help exactly where you need it with this discounted tool
BrowserCopilot AI: Lifetime Subscription (Unlimited Plan - Unli Queries per Month)

Shop cordless tool deals now for some home DIY ahead of the Amazon Big Spring Sale
Cordless tools on pink and lavender abstract background

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!