The wild wild west (www)

First, let's acknowledge that cops and robbers have exactly the same tools at their disposal.
Frequently, cybercriminals are far better equipped.

Essentially, there are 3 main vehicles required for a website to become accessible


Putting content together is easy

It's just putting pixels together and it will look just as intended.


Getting a domain is cheap

So opportunities to spread content on the web are endless, e.g. look-alike domains.


Getting a padlock is virtually free

CA's publicly admit, legitimacy/safety of content is not in their job description.


The impersonation problem

2019 saw a 640% growth of phishing sites
2018 saw a 220% growth of phishing sites
2017 - 1.5 million new phishing sites created each month

84% are active for less than 24h, to evade blacklists
74% of phishing sites have the https:// padlock

It's all about the monetary incentive!
Among the most impersonated brands are: Paypal, Facebook, Microsoft, Bank of America, Apple, Amazon, Instagram, BNP Paribas, DHL, Orange, Google, Dropbox

Sources: Verizon, Cisco, APWG, WebRoot

