{
  "id": 12229407,
  "title": "Nearly 40,000 phishing attacks hit US financial firms in H1 2026 — automated AI agents and a new Seychelles bulletproof host fuel aggressive new campaigns",
  "url": "https://urgent.news/2026/10/05/nearly-40-000-phishing-attacks-hit-us-financial-firms-in-h1-2026",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T21:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/nearly-40-000-phishing-attacks-hit-us-financial-firms-in-h1-2026-automated-ai-agents-and-a-new-seychelles-bulletproof-host-fuel-aggressive-new-campaigns"
  },
  "original_language": "en",
  "account": "In the first half of 2026, US financial firms were targeted by nearly 40,000 phishing URLs, according to a new report from Netcraft. This surge in attacks was fueled by the use of 645 hosting providers and 576 registrars, many of which offered free services. These factors made it difficult to contain the fraudulent infrastructure, as criminals quickly moved between platforms using new and automated AI tools.\n\nThe research revealed that free developer and application hosting accounted for 12.6% of the phishing URLs targeting US financial services. This means that approximately one in eight observed attacks relied on infrastructure that was accessible without incurring conventional hosting fees. Netcraft observed a significant shift in infrastructure use between the first and second quarters, indicating that criminals were actively switching services as alternatives became less effective.\n\nGenerative AI website builders and cloning tools played a crucial role in simplifying the creation of phishing campaigns. These tools increasingly offered free web hosting options, further reducing the technical effort required to establish fraudulent websites. The financial brands most targeted during this period included payment service providers, with PayPal accounting for 80.6% of attacks within that subsector, and American Express, which saw 72.8% of observed activity involving card networks.\n\nThe emergence of Omegatech, a paid hosting provider based in the Seychelles, added another layer of complexity to the infrastructure landscape. By June, Omegatech was responsible for approximately 3% of observed phishing attacks against US financial services. One cluster of 16 .es domains, hosted through Omegatech, generated 585 unique attack URLs between March and April 2026, impersonating 41 financial brands via subdomains.\n\nDespite the emergence of Omegatech, another major campaign against Fidelity Investments, originally carried out using the Darcula phishing platform, had significantly declined. Its influence had fallen by sevenfold from Q1 to Q2 2026. Meanwhile, financially motivated North Korean groups and organized criminal operators continued targeting banks, cryptocurrency services, and compromised accounts.\n\nThe changing mix of attack platforms, campaigns, and techniques suggests that financial companies should adopt a proactive approach to monitor newly registered domains, restrict suspicious links, and strengthen employee verification procedures against impersonation attempts.",
  "summary": "US financial services faced nearly 40,000 phishing URLs in just six months as free hosting, AI tools, and Omegatech expanded attackers' infrastructure options.",
  "key_points": [
    "Nearly 40,000 phishing attacks targeted US financial firms in H1 2026",
    "AI agents and free hosting services fueled aggressive new campaigns",
    "Omegatech, a Seychelles-based hosting provider, accounted for 3% of attacks"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}