Full Breakdown
New Phishing Attacks Target Microsoft and Marriott Users
1/26/2026, 5:42:46 AM
Overview of the Threat
Recent reports from Cybersecurity News have highlighted a new phishing attack that exploits a typographical trick involving the letters 'r' and 'n' to impersonate legitimate websites, specifically targeting Microsoft and Marriott. This tactic, known as a homoglyph attack, allows hackers to create fake URLs that closely resemble the real ones, making it difficult for users to detect the threat, especially on mobile devices like iPhones.
Mechanism of the Attack
The phishing scheme involves replacing the letter 'm' in a URL with the combination 'rn', resulting in domains such as rnicrosoft.com. This deceptive practice is particularly dangerous because the fake websites can appear nearly identical to their legitimate counterparts. Cybersecurity experts have noted that these types of attacks are often successful due to their visual similarity, which can easily mislead users into providing sensitive information.
Key Incidents
Two notable incidents have been reported involving this phishing technique. The first targets Microsoft users, where phishing emails sent from the domain rnicrosoft.com deliver fake security alerts or invoice notifications. The second incident involves Marriott, although details on the specific tactics used against them remain less clear. The Microsoft attack is considered more severe due to the potential for widespread credential theft.
Official Statements & Responses
Cybersecurity experts recommend that users remain vigilant and verify URLs before entering any personal information. They advise enabling security measures such as passkeys and two-factor authentication on all critical accounts, particularly those associated with Microsoft. The emphasis is on caution, especially with URLs that contain the letter 'm', as these are prime targets for the homoglyph attack.
Criticism & Opposition
While the report underscores the risks associated with these phishing attacks, some cybersecurity professionals argue that users should also be educated on recognizing phishing attempts beyond just URL scrutiny. They suggest that awareness of common phishing tactics and ongoing training could further mitigate risks.
Conflicting Reports & Gaps
There is currently a lack of detailed information regarding the extent of the Marriott phishing attack compared to the Microsoft incident. While the Microsoft attack has been clearly documented, further investigation is needed to understand the full scope of the threats posed to Marriott users.
Verbatim Quotes
- “Hackers are using the ‘rn’ typo trick to impersonate Microsoft and Marriott in a new phishing attack.” — Cybersecurity News
As phishing tactics evolve, users must remain informed and cautious to protect their personal data from these sophisticated attacks.
