Skip to main content

Morning Overview

9 brands scammers impersonate, from Microsoft at 22% of phishing lures to fake Netflix logins

Scam messages succeed by borrowing the look of companies that people already trust and use daily. Check Point’s Q1 2026 ranking put Microsoft first at 22% of brand phishing, and consumer-focused warnings show the same trick on shops, streamers, couriers and payment apps. Here are nine impersonated brands, each paired with the specific bait and the clue that gives it away.

1. Fake Microsoft 365 login page: Imitation Leader

Fake Microsoft 365 login page — Image Credit: Salvatore De Lellis/Pexels
Image Credit: Salvatore De Lellis/Pexels

Microsoft was the most imitated brand in Q1 2026, accounting for 22% of brand phishing attempts in Check Point Research’s ranking. One fake page sat on a long address beginning login.microsoftonline.com.office, followed by a different domain entirely, and it asked visitors for an email address as the first step of a credential grab.

The tell is the domain’s real ending, which is read from right to left before the first slash. Anything after the genuine registered name matters more than the familiar words at the front. Typing the sign-in address directly, or using a saved bookmark, avoids the lookalike page altogether and keeps work credentials out of a harvesting kit.

2. Fake LinkedIn message: Fifth Place Lure

Fake LinkedIn message — Image Credit: LPS.1 - CC0/Wiki Commons
Image Credit: LPS.1 – CC0/Wiki Commons

LinkedIn was imitated in 6% of brand phishing attempts in Q1 2026, which placed it fifth among all brands in the Check Point brand ranking. Fake messages that borrow its look tend to promise a job lead, a connection request or a notice that needs a quick login, aimed at professionals who expect such mail.

A share that size means roughly one in seventeen brand-phishing attempts leaned on the LinkedIn name. Job seekers and recruiters are natural targets because unexpected messages from strangers are routine on the platform. Opening the app or typing the address manually, rather than following a link in a message, is the safer route to check whether any notification is real.

3. Fake PlayStation Store: Bank Transfer Red Flag

Fake PlayStation Store — Image Credit: 茅野ふたば - CC BY 4.0/Wiki Commons
Image Credit: 茅野ふたば – CC BY 4.0/Wiki Commons

A fake storefront at playstation-stores.com demanded payment by direct bank transfer, a method Check Point flags as a strong indicator of fraud. The site copied the look of Sony’s gaming shop, but a real checkout would offer ordinary card or wallet options rather than asking shoppers to wire money.

Direct transfers are hard to reverse once sent, which is why scammers favor them. A deal that looks too generous on games or consoles, paired with an unusual payment method, deserves a pause. Buyers can check that the address matches the official PlayStation domain exactly, since an added word or an extra letter is the usual sign of a copycat.

4. Fake Amazon Prime email: Payment Update Bait

Fake Amazon Prime email — Image Credit: Tedder - CC BY-SA 4.0/Wiki Commons
Image Credit: Tedder – CC BY-SA 4.0/Wiki Commons

A fake Prime email asked recipients to update payment details, but the button pointed to reserve-pay-amazon.misecure.com rather than amazon.com, as TrendLife’s phishing roundup documented. The sender name and layout mimicked a billing notice, the kind of message that prompts a fast, worried click.

The giveaway sits in the part of the address just before the first slash, where the real registered domain lives. Here that was misecure.com, not Amazon. Hovering over a button before clicking reveals the true destination on a computer. Account problems can be checked by opening the Amazon app or typing the site address, never by using links in an unexpected email.

5. Fake Netflix unusual-login email: Fake Login Alarm

Fake Netflix unusual-login email — Image Credit: CitizenGO - CC BY 2.0/Wiki Commons
Image Credit: CitizenGO – CC BY 2.0/Wiki Commons

An email warned of an unusual login on a Netflix account, then sent recipients to a counterfeit sign-in page that records whatever is typed, according to TrendLife’s scam breakdown. The alarm is the hook: fear of losing access to a subscription pushes people to act before checking where the link actually leads.

Streaming accounts matter to scammers because stolen logins can be resold or reused on other sites where people repeat passwords. A genuine security concern can be checked by opening the Netflix app or typing the address directly. Changing the password and turning on any available protections limits the damage if a lookalike page was already filled in.

6. Fake UPS package-on-hold text: Package On Hold

Fake UPS package-on-hold text — Image Credit: Edwin Leong - CC BY-SA 2.0/Wiki Commons
Image Credit: Edwin Leong – CC BY-SA 2.0/Wiki Commons

A text claimed a package was on hold and linked to cubicsoftlab.com, a counterfeit tracking page built to gather home addresses and card numbers, according to TrendLife’s delivery-scam entry. The message borrowed UPS branding to make a small redelivery fee or address correction seem routine.

Delivery texts work because nearly everyone is waiting on something. The domain is the quick check: a courier’s notice leads to the courier’s own site, not an unrelated software-sounding name. Tracking numbers can be pasted into the carrier’s official site or app instead. A request for card details to release a parcel is a reason to stop and verify.

7. Fake PayPal suspension notice: Suspension Scare

Fake PayPal suspension notice — Image Credit: Kürschner 16:25, 27 February 2026 (UTC) - CC0/Wiki Commons
Image Credit: Kürschner 16:25, 27 February 2026 (UTC) – CC0/Wiki Commons

A notice said a PayPal account had been suspended, and the link hid the word paypal.com inside another domain, such as bitsaleshop.com, per TrendLife’s phishing examples. Placing a trusted name inside a longer address is a common trick to fool a quick glance at the link.

Account-suspension threats rely on urgency, which discourages careful reading. The real domain is whatever sits directly before the first slash, so a trusted name appearing earlier in the address means nothing. Logging in through the official app or a typed address shows whether a problem exists. PayPal accounts hold linked cards and bank details, which raises the stakes of a stolen password.

8. Fake iPhone unlock alert: Unlock Request Trap

Fake iPhone unlock alert — Image Credit: Freepik
Image Credit: Freepik

A message claimed that a request to unlock an iPhone 13 was currently being processed, then linked to a counterfeit iCloud login page, as TrendLife’s phishing list recorded. The wording suggests a lost or stolen device, prompting a worried reaction and a rushed sign-in.

Apple ID credentials can open backups, photos and device-location tools, which makes them valuable to thieves. The message targets people who may have just misplaced a phone or who fear someone else is attempting access. A genuine concern is better checked in the device’s own settings or on Apple’s official site, typed by hand, than through a link delivered by text or email.

9. Fake USPS delivery text: Address Not Detailed

Fake USPS delivery text — Image Credit: Tim1965 - CC BY-SA 3.0/Wiki Commons
Image Credit: Tim1965 – CC BY-SA 3.0/Wiki Commons

A text said a delivery address was not detailed, showed the sender as [us post], and linked to domains that were not USPS ones, per TrendLife’s roundup. The awkward phrasing and the bracketed sender name were both clues that the message did not come from the Postal Service.

Odd grammar, a made-up sender label and an unfamiliar link together mark this as a smishing attempt. Recipients who are expecting a parcel can check its status by entering the tracking number on the official USPS website. Texts demanding quick action about a missing address deserve deletion, and reporting them helps carriers and regulators spot active campaigns.


More from Morning Overview

Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.