News

Phishing awareness: how a Cyrillic 'o' can ruin your weekend

It's Friday afternoon. The last client meeting of the day is over and your mind is already on the weekend. Just a quick look at your email and the team chat on your phone on the way home. Then a message catches your eye, one that an IT security consultant posted that morning, almost in passing:

Phishing awareness: a Cyrillic 'o' in a link

"Good morning. I'd like to draw your attention to the mysterious Project P: resоurces.example.com (link to the internal wiki). More on this soon. Have a nice day."

The link to the internal wiki looks familiar. What nobody notices is that the domain name contains a Cyrillic 'о', so the link doesn't lead where you'd expect. Curiosity wins and you click. A familiar login page appears. Half asleep, you type in your password or copy it from your password manager. One click on Login, and there's the wiki page on Project P, or so it seems.

That's how easily a phishing attack can succeed.

Why does this work?

Browsers do have some technical safeguards. For example, they show domain names containing homographs, such as our Cyrillic 'o', in an encoded form rather than as they look. With a bit of creativity, these safeguards can be neatly sidestepped. And on mobile devices in particular, you often only see part of the URL, which makes checking it almost impossible.

A real test: about a year ago I ran a similar simulated phishing attack. Almost everyone entered their login details. Only one person noticed the manipulated URL.

Lessons learned: what helps against phishing?

Phishing attacks can't be prevented entirely, but you can reduce the risk considerably.

Don't trust links. Never click on a login link unless it comes from your own bookmarks. Check URLs yourself, especially on mobile devices.

Two-factor authentication (2FA), done properly. TOTP codes, for example from an authenticator app, are better than nothing, but they can be attacked: a phishing page can grab the code and use it straight away. FIDO2 hardware tokens such as a YubiKey, or passkeys, are safer because they are resistant to phishing.

Use your password manager properly. Install it as a browser extension so that it checks the URL for you. Avoid copying and pasting passwords: once you do it by hand, the password manager can no longer warn you that you're on the wrong site.

Watch out for warning signs.

  • The login page looks different: error messages, the wrong colours or fonts
  • Certificate errors in the browser
  • Odd-looking URLs, e.g. exarnple(dot)com instead of example(dot)com
  • Internal links sent by someone outside the company
  • Gut feeling: if something seems off, think twice.

Report phishing attempts! Let your security team know. Every report helps to spot attacks early.

In short: phishing exploits human nature, and awareness is the best protection. Stay alert, look at URLs with a critical eye and use modern authentication methods.


A German version of this article was also published on LinkedIn on 5 December 2025.