Fraudsters are increasingly using a technique called homoglyph attacks, where characters from different writing systems are used to create URLs and email addresses that look legitimate but actually direct users to fake websites or inboxes. These attacks take advantage of the visual similarity between characters from different alphabets, such as the Cyrillic "α" which looks like the Latin "a," or the Cyrillic "с" that resembles the Latin "c." According to Jake Moore, a global security adviser at ESET, this type of fraud is growing more common. For example, a fake site might use the Cyrillic "с" instead of the Latin "c," making "miсrosoft" appear as "microsoft" at a glance. These attacks often target well-known companies, like Microsoft, to trick users into believing they are interacting with the real organization. In one case, a Japanese hiragana character ん was used to look like a slash (/) in a URL designed to mimic the Booking.com website. Marijus Briedis, chief technology officer at NordVPN, explains that these attacks are psychological. He says the goal is to create a sense of urgency, making users less likely to scrutinize the URL. "They’re betting that when we’re in a rush, our brains see what we expect to see," Briedis notes. At first glance, a fake URL or email might look exactly like the real one. You might receive an email or text message urging you to click a link to resolve an issue. Some fonts make it nearly impossible to detect the difference. For instance, in an email address written in Comic Sans, the Cyrillic "a" might blend in seamlessly. Moore points out that even if you check the website, you can still be tricked because the fake site might appear legitimate. "We’ve spent years telling people to check the website before trusting it, but the problem with this technique is that you can do exactly that and still be fooled," he says. If you are sent a link, Moore advises taking a moment to think before clicking. "If any text, WhatsApp or email is asking you to log in anywhere, it is vital that you independently visit the genuine website rather than trusting the link in front of you to save a few seconds," he says. The same applies to email addresses—type the address you know to be correct instead of clicking on a provided link. Keeping your browser updated can help it flag suspicious websites and catch the latest tricks used by fraudsters. Additionally, using two-factor authentication (2FA) adds an extra layer of security, requiring two steps to log in. If you suspect your information has been compromised, change your passwords immediately, contact your bank, and report the phishing attack to the appropriate authorities.