Netcraft Finds Nearly 40,000 Phishing URLs Targeting US Financial Services in H1 2026
Netcraft found nearly 40,000 phishing URLs tied to US financial services in H1 2026, across 645 hosts and 576 registrars.
Free developer and application hosting accounted for 12.6% of the phishing URLs recorded against US financial services in H1 2026, meaning about one in eight observed attacks used infrastructure available without conventional hosting fees. Netcraft observed significant changes in infrastructure use between Q1 and Q2, suggesting criminals switched services when infrastructure became unavailable or less useful.
Netcraft said generative AI website builders and cloning tools increasingly include free web hosting options, reducing the technical work needed to create websites, reproduce legitimate pages and deploy malicious infrastructure.
The impersonated financial brands show where attacks concentrated. Payment service providers accounted for 37.2% of observed phishing activity, and PayPal represented 80.6% of attacks within that subsector. American Express accounted for 72.8% of observed activity involving card networks.
The hosting picture changed with Omegatech, a paid hosting provider based in the Seychelles that began operations in January 2026. By June, Netcraft attributed roughly 3% of observed phishing attacks against US financial services to infrastructure hosted through Omegatech. One cluster contained 16 .es domains that generated 585 unique attack URLs between March 25 and April 21, 2026. Those domains impersonated 41 financial brands through subdomains, and registration data for many was unavailable, limiting visibility into who registered the infrastructure.
Omegatech emerged as another major campaign targeting Fidelity Investments through the Darcula phishing platform was winding down. That operation fell sevenfold from Q1 to Q2 after previously accounting for more than half of phishing infrastructure impersonating Fidelity. Financially motivated North Korean groups and organized criminal operators continued to pursue banks, cryptocurrency services and compromised accounts.
Netcraft said the changing mix suggests attackers are not relying on one platform, campaign or technique to reach financial customers. The report advised financial companies to closely monitor newly registered domains, restrict suspicious links and strengthen employee verification procedures against impersonation attempts.
Editor's Summary
Netcraft research reported by TechRadar found nearly 40,000 unique phishing URLs targeting US financial services in H1 2026, spread across 645 hosting providers and 576 registrars. Free hosting and AI website builders lowered barriers, while attacks concentrated on PayPal, American Express and other brands. A Seychelles-based host, Omegatech, emerged as new infrastructure, and North Korean and criminal groups continued targeting banks and crypto services.