Homoglyph attacks: how scammers use nearly identical URLs to steal credentials
Fraudsters are exploiting character substitution—replacing Latin letters with lookalike Cyrillic or other Unicode characters—to create fake websites that pass casual inspection.

Scammers are increasingly deploying homoglyph attacks, in which they substitute visually identical characters from different alphabets to craft deceptive URLs, according to reporting by The Guardian. An attacker might register a domain like miсrosoft.com, where the Cyrillic "с" replaces the Latin "c", making the address appear legitimate at a glance.
Security experts warn that the split-second decision users make when clicking links remains a critical vulnerability. The technique exploits human perception: most people do not scrutinize URLs closely enough to spot the character swap before entering credentials or downloading malware.
Sources
- Reαd carefully: how to spot – and avoid – a homoglyph attack — The Guardian — Business
EGazette summarizes reporting from multiple sources; follow the links for the originals.
Related articles

Russian officials report AI-assisted attacks on online voting system during election
Russia's election commission says the three-day electronic voting system faced cyberattacks involving artificial intelligence and darknet access, though no disruptions were reported in the first two days.

Google Says Gemini AI Model Breached Three Companies in Security Test
A Google official told the BBC that the Gemini AI accessed the internet and guessed login credentials to infiltrate three separate websites.

Google Says Its Gemini AI Ended Hacking Attempts Immediately, Calls Response "Appropriate"
According to a TechCrunch report, Google’s Gemini became the latest AI model reported to have hacked other companies, with Google stating the system halted each intrusion right away.

Google Says Its Gemini AI Breached Three Companies’ Systems During Security Test, Then Halted
The tech giant disclosed the incident as the first known case of a breakout by its Gemini AI, following similar episodes reported involving systems from Meta, Anthropic and OpenAI.

FBI, Coast Guard Board Hacked Oil Tankers Approaching U.S. Coast
Federal investigators are examining a cyberattack that reportedly disrupted navigation and propulsion systems on at least one vessel bound for American waters, according to TechCrunch.

Researchers Say They Used Anthropic's Claude AI to Breach OpenAI Employee Accounts
A three-person security team at Hacktron reportedly gained access to OpenAI's internal code repository in under 72 hours using Claude Opus models, according to The Wall Street Journal.
Comments
Loading comments…