Phishing

Financial phishing campaigns exploit fragmented hosting, AI tools

(Adobe Stock)

As outlined in Tech Radar, U.S. financial services faced a significant surge in phishing attacks during the first half of 2026, with nearly 40,000 malicious URLs identified. Attackers are leveraging a fragmented landscape of over 645 hosting providers and 576 registrars to distribute these campaigns, making containment a complex challenge.

The research reveals that attackers are increasingly utilizing free hosting services, which accounted for 12.6% of phishing URLs targeting the financial sector. This reliance on no-cost infrastructure significantly lowers the barrier to entry for launching fraudulent campaigns. The agility of these operations is further amplified by advancements in AI tools, which enable faster website creation, page replication, and the deployment of malicious infrastructure with reduced technical expertise. Payment service providers were the most targeted entities, with PayPal and American Express being heavily impersonated. The emergence of new hosting providers like Omegatech in the Seychelles also contributes to the evolving threat landscape, with approximately 3% of attacks attributed to its infrastructure by June 2026. This dynamic environment, characterized by a changing mix of platforms, campaigns, and techniques, necessitates continuous monitoring of newly registered domains, restriction of suspicious links, and enhanced employee verification procedures for financial institutions.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds