Theguardian iconTheguardianSep 20, 2026

Reαd carefully: how to spot – and avoid – a homoglyph attack

Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miсrosoft.com You've read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL.

Reαd carefully: how to spot – and avoid – a homoglyph attack

Share this story

Send the public story page.

Useful takeaways from this story.

Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miсrosoft.com You've read the email carefully and it looks legitimate.

The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL.

If you had looked slightly closer you may have noticed something slightly wrong with one of the characters.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miсrosoft.com You've read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. If you had looked slightly closer you may have noticed something slightly wrong with one of the characters.

How it works

  • It just goes to show that the split-second decision you make when clicking a link is often the most vulnerable part of the whole security chain." Continue reading...
  • Just as in the headline of this piece where instead of "a" we used the Cyrillic "α".

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app