Skip to content
US financial sector hit by 40,000 phishing URLs in H1 2026

US financial sector hit by 40,000 phishing URLs in H1 2026

Tech.Yahoo • October 6, 2026

When you buy through links on our articles, Future and its syndication partners may earn a commission.

US financial services faced nearly 40,000 phishing URLs during H1 2026

US financial services faced nearly 40,000 phishing URLs during H1 2026

Attackers used 645 hosting providers to distribute financial phishing campaigns

Attackers used 645 hosting providers to distribute financial phishing campaigns

Free hosting carried 12.6% of phishing URLs targeting financial services

Free hosting carried 12.6% of phishing URLs targeting financial services

Phishing campaigns targeting American financial institutions are spreading across a fragmented web of hosting services, making fraudulent infrastructure difficult to contain.

New research from Netcraft has uncovered almost 40,000 unique phishing URLs connected to US financial services were discovered in the first half of 2026.

Behind those URLs were 645 hosting providers and 576 registrars, while newer services and automated AI tools helped attackers move quickly between platforms.

Cheap infrastructure is helping campaigns multiply

The scale of the activity becomes clearer when the services carrying these attacks are examined rather than the fraudulent websites alone.

Free developer and application hosting accounted for 12.6% of phishing URLs recorded against US financial services during H1 2026.

That means approximately one in eight observed attacks relied upon infrastructure that attackers could access without paying conventional hosting fees.

Netcraft observed significant changes in infrastructure use between Q1 and Q2, suggesting criminals were switching services as infrastructure became unavailable or less useful.

AI is making that movement easier by helping users create websites, reproduce legitimate pages and deploy malicious infrastructure with less technical effort.

Netcraft said generative AI website builders and cloning tools increasingly include free web hosting options, further reducing the work required to establish campaigns.

The financial brands being impersonated also show where attackers are concentrating their efforts across the sector during the reporting period.

Payment service providers accounted for 37.2% of observed phishing activity, with PayPal representing 80.6% of attacks within that subsector.

American Express accounted for 72.8% of observed activity involving card networks, showing how heavily campaigns can focus on recognizable financial brands.

Omegatech emerges as another source of attack infrastructure

The infrastructure picture changed further with the emergence of Omegatech, a paid hosting provider based in the Seychelles, which started operations in January 2026.

One cluster contained 16 .es domains that generated 585 unique attack URLs between March 25 and April 21 2026.

Those domains were used to impersonate 41 financial brands through subdomains, allowing one cluster to support campaigns against numerous institutions.

Registration data for many of those domains was unavailable, limiting visibility into the companies responsible for registering the infrastructure.

Omegatech's emergence came as another major campaign was winding down after targeting Fidelity Investments through the Darcula phishing platform.

That operation fell sevenfold from Q1 to Q2, after previously accounting for more than half of phishing infrastructure impersonating Fidelity.

Meanwhile, financially motivated North Korean groups and organized criminal operators continued pursuing banks, cryptocurrency services and compromised accounts.

The changing mix suggests that attackers are not relying on one platform, campaign or technique to reach financial customers.

Financial companies are advised to closely monitor newly registered domains, restrict suspicious links and strengthen employee verification procedures against impersonation attempts.

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Industries (1)

MITRE ATT&CK (1)