PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Watch Out. Scammers Are Using This URL Typo to Mimic Microsoft, Marriott

Hackers are replacing the 'm' in certain domains with 'rn' (r and n) to make communication from well-known companies look genuine.

 & Jibin Joseph Contributor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Credit: Gabby Jones/Bloomberg via Getty Images)

Hackers are using a new typo trick to mimic legitimate websites and potentially steal your information and money.

As Cyber Security News reports, malicious actors are using the letters “r” and “n” in lower case and creating fake URLs that look real. When they're next to each other, “rn” looks like the letter “m,” and cybersecurity firms have identified two major brands that hackers have been exploiting using this "rn" trick: Microsoft and Marriott.

Potential victims have been receiving emails from rnarriottinternational.com, rnicrosoft.com, and other similar addresses that claim to be alerting recipients to security alerts, password resets, or invoice notifications. The fake Marriott addresses also reference loyalty accounts or other customer relationship info.

Emails from the fake Microsoft account are a bit more difficult to distinguish, according to the report, since they replicate the company’s logo, tone, and layout rather accurately.

So how do you avoid falling for this trap? If you receive an unsolicited password reset request from Microsoft or a lucrative hotel deal from Marriott, type the website's address manually to log in to your account and verify the communication. Do not click links provided in these emails.

The hacking technique used here is called “typosquatting.” It has been around for quite some time. Last year, some hackers were using it to send fake Instagram login alerts.

About Our Expert

Jibin Joseph

Jibin Joseph

Contributor

Jibin is a tech news writer based out of Ahmedabad, India. Previously, he served as the editor of iGeeksBlog and is a self-proclaimed tech enthusiast who loves breaking down complex information for a broader audience.

Read full bio