A new cybersecurity warning is prompting renewed concern among Chrome and Safari users, particularly those accessing accounts on mobile devices. As cybercriminal tactics become more sophisticated, even experienced users may struggle to distinguish legitimate websites from expertly crafted fakes. The latest threat underscores a sobering reality: a single glance at the wrong URL can be enough to compromise credentials, personal data, and entire digital identities.
According to recent reporting by Cybersecurity News, threat actors are actively deploying a deceptive phishing technique that exploits a subtle visual weakness in web addresses. By replacing the letter “m” with a combination of “r” and “n,” attackers are creating fraudulent domains that appear nearly identical to trusted brands such as Microsoft and Marriott—especially on small mobile screens where visual inspection is limited.
At first glance, the difference is almost imperceptible. However, the consequences of falling victim to such deception can be severe. Once users unknowingly enter login credentials on these fake sites, attackers can seize control of accounts, extract sensitive information, and, in some cases, gain access to broader networks connected to those credentials.
The Rise of Homoglyph Attacks
This campaign is part of a broader category of cyber threats known as homoglyph attacks. These attacks exploit characters that look alike to the human eye but are technically different, allowing malicious actors to convincingly impersonate legitimate domains. Homoglyph techniques have increasingly been used in phishing operations, domain spoofing, and even software supply chain attacks, often with alarmingly high success rates.
What makes these attacks particularly dangerous is their authenticity. The fraudulent websites are frequently indistinguishable from the real ones, down to branding, layout, and messaging. As a result, even cautious users can be misled, especially when accessing email notifications or security alerts on mobile devices.

Microsoft and Marriott Among Primary Targets
Cybersecurity analysts report that two recent phishing campaigns leveraging the “r+n” substitution technique have specifically targeted Microsoft and Marriott users. While both incidents are serious, the Microsoft-related attack presents heightened risk due to the breadth of access tied to Microsoft accounts, including email, cloud storage, enterprise tools, and financial data.
Security firm Anagram has identified a coordinated phishing effort in which attackers used domains such as “rnicrosoft.com” to distribute fake security alerts and invoice notifications. These messages are designed to create urgency, prompting users to click links and “verify” their accounts—an action that immediately exposes credentials to malicious actors.
Why Mobile Users Are Especially Vulnerable
Although hovering over a link to inspect its URL can reveal inconsistencies, this safeguard is largely ineffective on smartphones and tablets. Moreover, many users simply do not take the extra step to verify links, particularly when messages appear credible or urgent. This behavioral gap is precisely what attackers exploit.
Consequently, cybersecurity experts emphasize a critical rule: never log into any account—whether Microsoft, Marriott, or otherwise—through a link embedded in an email, text message, or notification. Instead, users should access accounts directly through official apps or by manually typing the known, trusted website into their browser.
Strengthening Digital Defenses
In light of this emerging threat, proactive security measures are no longer optional—they are essential. Enabling passkeys, implementing strong and unique passwords, and activating two-factor authentication across all key accounts can significantly reduce risk. For platforms such as Microsoft, which often serve as gateways to other services, these protections are especially critical.
Additionally, users are advised to exercise heightened caution when reviewing URLs that contain or begin with the letter “m.” Given how convincingly the “r+n” substitution mimics legitimate domains, taking an extra moment to scrutinize web addresses can make the difference between safety and compromise.
A Call for Heightened Awareness
This latest warning serves as a reminder that cybersecurity threats continue to evolve alongside the technologies people rely on daily. As attackers refine their methods, awareness and vigilance remain the most effective defenses. By adopting safer browsing habits and reinforcing account security, users can stay one step ahead of increasingly deceptive cybercriminal campaigns.
The message is clear: digital trust must be earned, not assumed. And in an era where a single character can separate safety from exposure, attention to detail has never mattered more.