• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - Booking.com phishing campaign is using the Japanese word “ん” to get by

Booking.com phishing campaign is using the Japanese word “ん” to get by

Claire by Claire
August 19, 2025 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

As high as the road is, so high is the devil. No matter how well technology companies and you take precautions, malicious people will always find ways to exploit loopholes, which is really hard to guard against. Malicious actors are using Unicode characters to make phishing links look like legitimate Booking.com links. After gaining your trust, they let your guard down and click on the link, trapping you in the trap.

Booking.com phishing campaign is using the Japanese word “ん” to get by

This attack exploits the Japanese hiragana character “ん” (Unicode U+3093) and was first used bySecurity Researcher JAMESWT It was found that when certain fonts are displayed, it may look very similar to the Latin letter “/n” or “/~”. This visual deception allows scammers to create links that look like the genuine Booking.com domain, making phishing links look real to people and directing users to malicious websites.

Below is a screenshot of the phishing email shared by a security researcher:

The text in the email, https://admin.booking.com/hotel/hoteladmin/… is itself deceptive. Although it looks like a Booking.com address, the hyperlink points to “https://account.booking.comんdetailんrestrict-access.www-account-booking.com/en/”. When rendered in a web browser’s address bar, the “ん” character can trick a user into thinking they are browsing the booking.com subdomain.

▲ How the phishing page appears in the browser. (Image source: Bleeping Computer)

This phishing tactic utilizes homographs. A homograph is a character that looks similar to another character but belongs to a different character set or alphabet. These visually similar characters may be used in phishing attacks or to create misleading content. For example, the Cyrillic letter “О” (U+041E) may look the same to the human eye as the Latin letter “O” (U+004F), but they are completely different words. Threat actors leverage homographs time and time again in homograph attacks and phishing emails due to their visual similarities. Over the past few years, defenders and software developers have also introduced security measures that allow users to easily distinguish between different homographs.

據報 Hotels.com、Booking.com 與 Expedia 有暴露百萬筆顧客個資的狀況 - 電腦王阿達

In addition, foreign media Bleeping Computer A further Intuit phishing campaign was discovered, using a similar domain name, replacing the letter I used in Intuit with the letter L. You should always start with the first / before the actual domain, which is the actual registered domain name. Granted, using visually deceptive Unicode characters like “ん” creates additional hurdles, and visual URL inspection alone isn’t foolproof.

 

 

 

Source: KOCPC Chinese

Tags: fishingInternet securitynetworkPhishingPhishing website

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology