Tech.Yahoo US Financial Sector Faces Surge in Phishing Attacks Amid New Hosting Provider Emergence
Article Content
- •Nearly 40,000 phishing URLs targeted US financial services in H1 2026.
- •Omegatech, a new hosting provider, accounted for 3% of phishing activities within six months.
- •Payment service providers were the most affected, with PayPal and American Express being primary targets.
In the first half of 2026, US financial services experienced nearly 40,000 unique phishing URLs, according to Netcraft. Attackers utilized 645 hosting providers and 576 registrars, with 12.6% of phishing URLs hosted on free services. The emergence of Omegatech, a Seychelles-based hosting provider, contributed to 3% of these phishing activities within just six months. Payment service providers were the most targeted, accounting for 37.2% of phishing activity, with PayPal and American Express being heavily impersonated. The data also indicates a significant decline in a previous Darcula campaign targeting Fidelity Investments, which saw a sevenfold drop in phishing URLs from Q1 to Q2 2026. The use of automated AI tools has facilitated the rapid establishment of these phishing campaigns, making them harder to track and mitigate.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Omegatech and American Express in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What types of organizations are primarily targeted?
How has AI influenced these phishing campaigns?
What should financial institutions do to mitigate these threats?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…