Skip to content

Watering Hole Attacks

A watering hole attack compromises or manipulates a legitimate website, portal, platform, or other online resource routinely used by a defined group, allowing normal access patterns to create the initial opportunity.

Trust is inherited from routine use. A familiar supplier portal, industry resource, or shared platform already fits the target audience’s workflow and may receive less scrutiny during repeated visits. The destination can therefore provide contextual legitimacy before an unusual request or change in behaviour is assessed.

Attackers may alter an existing resource, insert malicious content, profile visitors, redirect selected users, or use the compromised resource to deliver malware or capture credentials. Familiarity with the legitimate location can cause changes in its behaviour to receive less scrutiny.

Watering hole attacks appear through compromised websites, altered supplier portals, community platforms, file repositories, software download pages, and other legitimate resources that deliver malicious content or redirect visitors elsewhere.

A standalone lookalike site is better treated as phishing or website impersonation rather than a watering hole. It can, however, form part of a watering hole attack when a compromised legitimate resource redirects selected visitors to it.

Common scenarios include:

  • a compromised site used by a target industry or professional group
  • a supplier or partner portal presenting an unfamiliar authentication flow
  • an established resource page offering an unexpected file or update
  • a community platform directing users to altered or external content
  • a software page serving a modified installer
  • a familiar website redirecting to another domain or login page
  • a legitimate industry, supplier, event, or professional resource that has been compromised and continues to circulate through trusted networks
  • a resource requesting credentials or sensitive information outside its normal workflow

These attacks turn on a small set of elements:

ElementWhat it meansExamples
Trusted locationThe website, portal, or online resource the target audience already expects to use.Supplier portal, industry site, association page, community forum, file repository, software page.
Target audienceThe group the attacker expects to reach through that location.Employees, suppliers, sector members, developers, researchers, customers, event attendees.
Trust basisThe familiarity or relationship that makes the location appear legitimate.Known domain, established brand, industry relevance, previous use, trusted community, supplier relationship.
Unexpected behaviourThe change in the site, page, or workflow that may indicate compromise or malicious manipulation.New login prompt, redirect, download, warning, certificate issue, altered page, unusual form.
Requested actionThe action sought through the altered or deceptive experience.Enter credentials, approve MFA, download a file, install software, submit data, open a document.

Behavioural change in an established destination carries the indicators: a new action, altered content, or movement outside the workflow previously associated with the resource.

IndicatorWhat to look for
Unexpected login promptA familiar website, portal, or resource suddenly requests credentials, MFA codes, recovery details, or account verification outside the established workflow.
Changed site behaviourA known resource presents unfamiliar content, prompts, wording, navigation, or page behaviour.
Unexpected downloadThe site offers a file, installer, plugin, browser extension, document viewer, update, or security tool without an established reason.
Unexplained redirectThe resource moves to another domain, login page, file-sharing service, payment page, form, or support portal without a clear workflow basis.
Domain or certificate inconsistencyThe URL, certificate, browser warning, domain spelling, or subdomain differs from the expected destination.
Unusual information requestPersonal information, business information, payment details, credentials, MFA codes, or other sensitive data is requested where the resource does not normally require it.
Security control warningBrowser, endpoint, DNS, email, or download controls warn about the site, redirect, certificate, file, or page behaviour.
Shared reports of abnormal behaviourMultiple users report the same unusual prompt, redirect, download, error, or account issue associated with the resource.
Redirect to a lookalike resourceA legitimate resource unexpectedly redirects to a page that reproduces a known industry, supplier, community, software, or portal site while using a different address or inconsistent branding.
Workflow mismatchThe requested action does not align with the established purpose or normal operation of the site, portal, or resource.