Cybercriminals are refining their phishing tactics to exploit consumer trust in major digital brands and align with seasonal behaviour, according to new research from Check Point Research (CPR), the threat intelligence arm of Check Point Software Technologies.
In its Brand Phishing Report for Q2 2025, CPR found that Microsoft remained the most impersonated brand globally, appearing in 25% of phishing attempts. Google followed with 11%, while Apple held third place at 9%. Notably, Spotify re-entered the top 10 for the first time since 2019, accounting for 6% of phishing activity—coinciding with a wave of travel-themed scams targeting holidaymakers.
“Cybercriminals continue to exploit the trust users place in well-known brands,” said Omer Dembinsky, Data Research Manager at Check Point Software. “The resurgence of Spotify and rise in travel scams show how attackers are adapting to real-world trends. Awareness and robust security controls are critical.”
Top 10 most impersonated brands in Q2 2025:
- Microsoft – 25%
- Google – 11%
- Apple – 9%
- Spotify – 6%
- Adobe – 4%
- LinkedIn – 3%
- Amazon – 2%
- Booking – 2%
- WhatsApp – 2%
- Facebook – 2%
One of the most prominent campaigns this quarter involved a spoofed Spotify login page hosted on a lookalike domain. Victims were tricked into entering their credentials, which were then redirected to a fake payment page designed to steal credit card details. The page was visually identical to Spotify’s official interface, demonstrating the increasing sophistication of phishing design.
Meanwhile, attacks impersonating Booking.com surged, with more than 700 phishing domains created using fake booking confirmation formats, marking a 1,000% increase. Many embedded real user data, such as names and phone numbers, to boost credibility, showing how social engineering tactics are becoming more personalised and targeted.
The tech sector continues to bear the brunt of phishing attacks, with brands like Microsoft, Google, and Apple consistently exploited due to their role in authentication and productivity platforms. Social media platforms such as LinkedIn, WhatsApp and Facebook also remain high-risk targets, while e-commerce and travel brands like Amazon and Booking.com are being leveraged to capitalise on seasonal demand.
The findings are based on data from Check Point’s ThreatCloud AI platform, which analyses phishing emails, malicious domains and impersonation attempts across channels. CPR’s quarterly report offers a snapshot of the shifting strategies used by threat actors- and the brands they most often exploit.

