Cybercriminals are increasingly leveraging a complex and fragmented network of hosting services to target the United States financial sector. According to recent findings from Netcraft, nearly 40,000 unique phishing URLs aimed at US financial institutions were identified during the first half of 2026.
The Challenge of Fragmented Infrastructure
The scale of these operations is highlighted by the sheer volume of infrastructure involved. Attackers utilized 645 distinct hosting providers and 576 registrars to execute their campaigns. A significant portion of these attacks—approximately 12.6%—relied on free developer and application hosting services, allowing malicious actors to bypass traditional costs.
Netcraft observed that threat actors frequently migrated their infrastructure between the first and second quarters of 2026, likely in response to platforms becoming unavailable or less effective for their purposes. This agility is being significantly bolstered by artificial intelligence.
AI's Role in Escalating Threats
Generative AI and automated tools are lowering the barrier to entry for cybercriminals. These technologies assist in:
- Rapidly building websites.
- Creating precise reproductions of legitimate financial web pages.
- Deploying malicious infrastructure with minimal technical expertise.
Many AI-driven website builders also integrate free hosting options, streamlining the process of launching large-scale phishing campaigns.
Primary Targets and Notable Trends
The data shows a clear concentration of attacks on specific high-profile financial brands. Payment service providers bore the brunt of the activity, accounting for 37.2% of all observed phishing, with PayPal alone targeted in 80.6% of those instances. Similarly, American Express was the focus of 72.8% of attacks directed at card networks.
A notable shift occurred with the rise of Omegatech, a Seychelles-based paid hosting provider that launched in early 2026. By June, the company was linked to approximately 3% of phishing attacks against US financial firms. In one instance, a single cluster of domains hosted at Omegatech managed to impersonate 41 different financial institutions simultaneously.
While some major campaigns, such as those utilizing the Darcula platform to target Fidelity Investments, saw a sharp decline in the second quarter, other threats persist. Both organized criminal syndicates and state-aligned groups, particularly those from North Korea, remain actively focused on banks and cryptocurrency services.
Recommendations for Financial Institutions
To mitigate these evolving risks, industry experts advise financial organizations to adopt a proactive security posture, which includes:
«Financial companies should closely monitor newly registered domains, restrict access to suspicious links, and reinforce employee verification procedures to combat sophisticated impersonation attempts.»
