From Hotspots to Lookalike Domains: 3 Phishing Tactics to Watch

phishing post 4 email phishing domain spoofing
emma-stevens-bio-portrait
Written by Emma Stevens
Senior Threat Intelligence Advisor

In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.

Each attack uses a different method, but they all rely on the same idea: create something familiar and convincing enough to get someone to connect, click, or log in.

Evil twin phishing

What is Evil twin phishing?

Evil Twin Phishing involves attackers creating a rogue Wi-Fi network that mimics a legitimate one. These fake networks are often set up in public places such as airports, hotels, coffee shops, and conference centers, where people expect free Wi-Fi to be available. Once someone connects, they are often redirected to a fake login page requesting their email, social media, or other account credentials. Depending on how the attack is set up, the attacker may also be able to intercept network traffic or collect other sensitive information.

Real-world example

In Australia, a man used a portable wireless device known as a Wi-Fi Pineapple to create fake networks at airports in Perth, Melbourne, and Adelaide, as well as on domestic flights. The device listened for Wi-Fi networks that nearby phones and laptops had previously connected to. It then created a network with the same name, causing some devices to connect automatically because they believed it was already trusted. Once connected, users were directed to a fake portal and asked to sign in using an email or social media account. The credentials they entered were saved to the attacker’s device and later used to access victims’ online accounts. The man was 42 when he was charged in 2024 and was sentenced in November 2025, at age 44, to seven years and four months in prison.

Evil twin attacks can also pose a risk to government and enterprise networks. In 2020, the U.S. Department of the Interior’s Office of Inspector General reported that a security assessment had successfully used evil twin, eavesdropping, and password-cracking techniques against departmental wireless networks. Using portable test devices that cost less than $200, the assessment team intercepted and decrypted wireless traffic across multiple bureaus. The attacks went undetected, and weak network segmentation allowed the team to identify systems containing sensitive data and supporting mission-critical operations.

Impact

Successful evil twin attacks can lead to:

  • Credential theft
  • Account takeover
  • Exposure of sensitive corporate or personal information
  • Unauthorized access to online services
  • Interception of network traffic
  • Follow-on phishing or fraud

Strategic recommendations

  • Verify the name of a public Wi-Fi network with staff before connecting.
  • Avoid entering email, social media, or corporate credentials into unexpected Wi-Fi login pages.
  • Avoid accessing sensitive accounts over public Wi-Fi. If public Wi-Fi is necessary, use a trusted VPN, but remember that a VPN will not protect you from entering credentials into a fake login portal.
  • Disable automatic Wi-Fi connections on laptops and mobile devices.
  • Use a personal hotspot instead of public Wi-Fi when possible.
  • Require phishing-resistant MFA for sensitive corporate applications.
  • Ask employees to forget public networks after they have finished using them.
  • A familiar network name does not mean the network itself is legitimate.

Lookalike domains and domain spoofing 

What are lookalike domains? 

Lookalike domain attacks involve attackers registering or using a domain that closely resembles one belonging to a legitimate organization. A single changed letter, number, word, or top-level domain can make a malicious website appear real at first glance. 

What is domain spoofing? 

Domain spoofing is a broader term that can also include making an email appear to come from a legitimate domain.

Real-world example

In April 2025, the FBI warned that cybercriminals were creating fraudulent websites designed to mimic legitimate employee self-service portals, including payroll, unemployment, retirement, and health savings account platforms. Attackers promoted the fake websites through search engine advertisements. The malicious URLs appeared near the top of search results and contained only small differences from the legitimate domains, such as a minor misspelling.

When victims entered their credentials, the attackers captured them and used the access to redirect payroll payments, transfer funds, or steal personal information. Some phishing pages also requested MFA codes, while attackers called victims pretending to be bank representatives or technical support staff to collect one-time passcodes. The attackers did not need to compromise the real website. They only needed to create a copy that looked convincing enough for users not to notice the difference.

Impact

Domain spoofing can result in:

  • Credential theft
  • Account takeover
  • Payroll or financial fraud
  • Business Email Compromise
  • Customer and employee impersonation
  • Malware delivery
  • Brand and reputational damage

Strategic recommendations

  • Continuously monitor for newly registered domains that resemble your organization’s name or brands.
  • Train users to check the full URL before entering credentials or sensitive information.
  • Encourage employees to type important website addresses directly into the browser or use saved bookmarks.
  • Avoid relying on search engine advertisements to access payroll, banking, or employee portals.
  • Implement SPF, DKIM, and DMARC to reduce unauthorized use of company domains in email.
  • Monitor for impersonation of your organization, executives, and suppliers.
  • Create a clear process for investigating and taking down malicious domains.

Organizations should assume that attackers can copy the design of a legitimate website. The URL may be one of the only visible signs that something is wrong.

Email phishing

What is email phishing?

Email Phishing remains one of the most common forms of phishing. Attackers impersonate trusted organizations, executives, coworkers, or service providers to convince recipients to click a link, open an attachment, send money, or share sensitive information. These attacks do not always require malware or a technical vulnerability. A believable request sent to the right person at the right time can be enough.

Real-world example

In February 2016, an employee in Snapchat’s payroll department received a phishing email that appeared to come from CEO Evan Spiegel. The message requested payroll information for current and former employees. Believing the request was legitimate, the employee sent the information to the attacker.

Snapchat said its servers had not been breached and its users were not affected, but employee payroll information was exposed. The incident showed how executive impersonation and a convincing request can lead to a serious data breach without an attacker needing to compromise the company’s systems.

Business email compromise remains one of the most financially damaging forms of online fraud. The FBI’s Internet Crime Complaint Center recorded 24,768 BEC complaints and more than $3.04 billion in reported losses in 2025, making it the second-highest crime category by reported losses that year.

Impact

Successful email phishing attacks can lead to:

  • Credential theft
  • Malware or ransomware infections
  • Business Email Compromise
  • Financial fraud
  • Exposure of sensitive information
  • Cloud account compromise
  • Additional phishing sent from trusted accounts

Strategic recommendations

  • Train employees to verify unexpected, sensitive, or urgent requests.
  • Require phishing-resistant MFA wherever possible.
  • Use email security controls that analyze links, attachments, and sender behavior.
  • Clearly identify messages that originate outside the organization.
  • Give employees a simple way to report suspicious emails.
  • Confirm payment requests, payroll changes, and credential resets through a separate communication channel.
  • Monitor for unusual login activity, mailbox rules, forwarding settings, and other signs of account compromise.

Email phishing succeeds because attackers understand how people communicate and make decisions. Security controls matter, but so does creating a culture where employees feel comfortable slowing down and verifying a request.

Conclusion

Whether it’s a rogue Wi-Fi hotspot, a convincing lookalike website, or a carefully written email, phishing attacks continue to exploit something that technology alone cannot remove: trust. Attackers do not need sophisticated malware or a zero-day vulnerability to gain access. Sometimes, all they need is a familiar network name, a realistic login page, or an email that arrives at the right moment. Reducing phishing risk requires more than annual security awareness training. Organizations need a combination of employee education, strong identity controls, external monitoring, layered security, and clear processes for reporting and responding to suspicious activity.

Bitsight Threat Intelligence helps organizations detect and investigate phishing sites, malicious and typosquatted domains, brand and executive impersonation, fake mobile applications, social media spoofing, and exposed credentials. Bitsight Brand Intelligence provides real-time monitoring across DNS, social media, app stores, and underground sources, with built-in workflows to investigate, prioritize, and pursue the takedown of confirmed threats. Bitsight Identity Intelligence helps teams identify and manage compromised credentials from infostealer logs, third-party breaches, and dark web marketplaces, while supporting automated remediation through identity provider integrations. These findings can be connected to an organization’s attack surface and integrated into existing security and identity workflows to support faster investigation and remediation.

Phishing risk can also extend through vendors and suppliers. Bitsight Beacon gives SOC and third-party risk teams validated, evidence-backed visibility into supply chain exposures, malicious activity, and confirmed breaches across critical vendors. This includes exploitable CVEs, exposed infrastructure, command-and-control activity, botnet infections, leaked credentials, ransomware activity, and initial access broker listings. This helps organizations identify potential downstream risk earlier and, through optional managed services, engage affected vendors and track remediation through closure.

Bitsight cta background color
2026 gartner magic quadrant cover

Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies

Get the report and see why Bitsight was named a Visionary.

 

Download

Bitsight cta background color