Phishing-as-a-service Kits is a tool tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed January 25, 2026; most recent activity March 10, 2026.
Phishing-as-a-service kits are tooling and infrastructure that let attackers rapidly deploy phishing campaigns by provisioning ready-made phishing pages and data-collection workflows. The recent case shows Russian hackers creating around 4,300 fake travel booking sites to harvest hotel guests' payment data, illustrating how such kits enable large-scale, automated credential and payment data theft. This underscores the growing commoditization of phishing infrastructure and the elevated risk to consumers and hospitality providers.
The ShinyHunters extortion gang has claimed responsibility for a series of voice phishing attacks targeting single sign-on (SSO) accounts at major platforms including Okta, Microsoft, and Google. In these attacks,…
In 2025, Russian hackers initiated a phishing campaign that involved creating over 4,300 fake travel websites to steal payment data from hotel guests. The campaign, which began in February, utilized sophisticated…