Because IDN allows websites to use full Unicode names, it also makes it much easier to create a spoofed web site that looks exactly like another, including domain name and security certificate, but in fact is controlled by someone attempting to steal private information. These spoofing attacks potentially open users up to phishing attacks.
These attacks are not due to technical deficiencies in either the Unicode or IDNA specifications, but because different characters in different languages can look the same, depending on the font used. For example, Unicode character U+0430, Cyrillic small letter a ("а"), can look identical to Unicode character U+0061, Latin small letter a, ("a") used in English. Characters that look alike in this way may be termed homonyms, homographs, or (less ambiguously) homoglyphs.