5 min read

H1 Phishing Landscape Report: U.S. Financial Sector

Facebook logo
Facebook logo
X (formerly Twitter) logo
X (formerly Twitter) logo
LinkedIn logo
LinkedIn logo
Reddit logo
Reddit logo

Current phishing landscape

Netcraft identified almost 40,000 unique phishing URLs relevant to the US financial services sector in H1 2026. This field of view includes attacks using 645 distinct hosting providers and 576 distinct domain registrars. Data within this time period shows the wind down of a Darcula campaign targeting Fidelity, with a 7x drop from Q1 to Q2. Additionally, the data shows a continued trend toward abuse of cloud platforms and free hosting services for phishing infrastructure targeting this sector. 

Subsector targeting 

Among subcategories of the financial services sector, payment service providers were the most highly targeted group, accounting for 37.2% of the total phishing volume against this sector during the reporting period. This reflects the use of payment service provider logos in scams impersonating other entities to extract victim funds. For example, PayPal impersonation accounts for 80.6% of the payment service provider group activity. Similarly, American Express dominated the card network group, accounting for 72.8% of attacks within it. The other groups had a much more even split, with no single brand accounting for the majority of observed malicious URLs in their subsector. 

The investment and brokerage subsector saw the most significant change in campaign activity during the reporting period with the wind down of a Darcula-based campaign. 

Darcula denouement  

Darcula is a phishing-as-a-service (PhaaS) platform that has been used in targeting across industries. Netcraft published one of the first industry reports on Darcula as well as its adoption of generative AI in its platform. Ongoing tracking identified a phishing campaign using Darcula to impersonate Fidelity Investments. Initiated in Q2 2025, this activity wound down to near-zero phishing sites by Q2 2026. This campaign had been significant enough to make up over half of the phishing attack infrastructure targeting Fidelity at the beginning of the year.  

This was the most significant coordinated phishing campaign impersonating a single target identified in this sector during the reporting period.  

Free hosting for fast campaigns 

The phishing infrastructure ecosystem mainly uses large and legitimate hosting services. This trend is seen in phishing campaigns targeting other industries as well but is notable as the scale and speed of infrastructure deployment increases with agentic AI. These tools can be used to automate otherwise complex website development and deployment across a range of providers. The use of free services is often built into generative AI website builders and cloners, making them increase the use of these platforms even when abused. Free developer and app-hosting services accounted for 12.6% of phishing URL volume for H1 2026. 

It should be noted that the distribution shown above does not reflect average month-to-month numbers and there were significant shifts in distribution across these services from Q1 to Q2. This suggests that threat actors are shifting between free infrastructure easily and that no single provider is uniquely abusable in the long term. 

A new player: Omegatech 

Among paid hosting providers, a key change in the landscape has been the appearance of a new malicious hosting provider, Omegatech (AS202412). According to public records, its operations began only in January 2026. By June, it was responsible for hosting roughly 3% of the phishing attacks against US financial services observed by Netcraft. This company, claiming to be based in Seychelles, acts as a paper shell for transnational hosting while legally remaining in a jurisdiction historically friendly to bulletproof hosting providers. This hosting provider has quickly become one of the highest volume hosting providers for malicious activity in this sector, behind only Cloudflare, Google, and Tencent.  

Registrar and hosting provider pairings within the dataset. 

As seen in the relations graph above, Omegatech-hosted phishing URLs were not provably from the biggest registrars in this set. This is due to a large amount of these domains being within the .es namespace. Red.es, the entity responsible for WHOIS data in this space, chooses to disclose data minimally, making their registration details unknown. Threat actors may choose to register domains in this space to avoid visibility through this kind of built-in domain privacy protection. 

Example of a .es whois record which is missing many fields, including the registrar. 

This is largely influenced by a single activity cluster, comprised of 16 .es domains with similar name structure that appeared between 25 March and 21 April 2026. These accounted for 585 unique attack URLs. 41 unique financial sector brands were impersonated across subdomains of this set. The infrastructure used suggests automated rotation of domains to keep operations continuous. This campaign was aided by infrastructural opacity, with minimal information disclosed regarding the registrar and “bulletproof” hosting from Omegatech. 

An example from the Omegatech .es cluster, cbc-comerica[.]com-e2[.]es. 

Emergent threat factor update 

AI: Deepfakes and autonomous exploitation 

AI has increasingly been used by threat actors to create malicious infrastructure and execute attacks. In H1 2026, deepfake executive impersonation for wire fraud was identified by the FSSCC as a key threat to the sector. Additionally, 2026 saw the first publicly documented agentic ransomware outside of academic settings. JADEPUFFER had flaws, failing to keep and export a decryption key. However, it still proved that it is possible for an agent to adaptively execute a multi-step ransomware attack chain. It is almost certain that threat actors will continue to seek weaponisation of agentic AI. 

Regulatory trajectory cryptocurrency assets as phishing risk 

The creation of tokenized deposit networks between banks as well as ongoing clarification of the GENIUS Act has helped mature the banking sector’s adoption of cryptocurrency assets and settlement tools.  On the other hand, uncertainty over whether the CLARITY Act will pass is likely to affect the rollout of Open USD (OUSD), a stablecoin backed by 140 partners that was announced in June 2026. Uncertainty can be weaponised by attackers seeking to exploit financial institutions or the people using their services who seek to use Open USD. 

Threat actor update 

Nation-states 

One of the most notable changes in H1 2026 was the updated definition of North Korean threat actor subgroups which have been particularly active and effective in H1. 

CrowdStrike's January 2026 assessment reports that Labyrinth Chollima has fractured into three independently operating DPRK-nexus adversaries. The restructuring is estimated to have occurred between 2018 and 2020, with new threat actor definitions released just this year. There remains a core Labyrinth Chollima that continues to prioritise espionage. Two newly-defined splinter groups, Golden Chollima and Pressure Chollima, are both revenue-driven and focused on cryptocurrency and financial entities. The three still share tooling and infrastructure, indicating that the split reflects mission specialisation. The projected impact for the US financial services sector is that two dedicated, financially motivated units now exist.  

Read alongside the observed DPRK shift toward banking infrastructure over crypto exchanges, it is likely that US institutions will face increased targeting of custody, settlement and tokenized deposit systems through H2 2026.

Organized crime groups 

Scattered Spider’s activity has been relatively quiet in H1 2026 as key members were arrested or have pled guilty. However, other groups targeting the financial services sector have increasingly adopted Scattered Spider’s methods, with heavy reliance on social engineering and achieving broader permissions through Okta/Entra account compromise.  

Individuals  

This threat actor category’s activity mainly affects account holders and customers through the deployment of indiscriminate phishing campaigns. As shown above, roughly 40,000 unique identified phishing URLs were newly observed in H1 2026. The vast majority of these are almost certain to be from individuals. 

The individuals category is likely to continue expanding as the barrier to entry is lowered by AI tools. Creating convincing bank login infrastructure and deploying to free hosting services is no longer time intensive and may not require any coding or deployment experience at all.  

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.