Phishing Attacks on U.S. Financial Sector Top 40,000 in First Half of 2026 as AI Tools Lower Barriers
Netcraft research finds malicious campaigns distributed across 645 hosts, using free developer platforms, generative site builders, and offshore infrastructure.

Nearly 40,000 unique phishing URLs targeted U.S. financial services institutions in the first half of 2026, according to research from security intelligence firm Netcraft reported by TechRadar Pro. The campaigns relied on a fractured hosting footprint spanning 645 hosting providers and 576 registrars, complicating takedown and containment efforts by defenders.
The data shows threat actors increasingly leaning on free developer and application hosting environments, which represented 12.6%—roughly one in eight—of all phishing URLs detected against U.S. financial institutions during the six-month period. Netcraft recorded marked shifts in infrastructure between the first and second quarters, indicating that operators rapidly rotated platforms as older hosting setups became unavailable or were taken down.
Automated generative artificial intelligence tools are accelerating that movement. Netcraft found that generative AI website builders and cloning tools, which often include free hosting tiers, have reduced the technical effort required to copy legitimate brand pages and launch malicious hosting setups at scale.
Payment service providers bore the brunt of the activity, accounting for 37.2% of observed financial phishing URLs during the period. Within that subsector, PayPal represented 80.6% of attacks. Among credit card networks, American Express was the primary target, accounting for 72.8% of observed card-related campaigns.
Netcraft also traced shifts toward newer bulletproof infrastructure, notably Omegatech, a paid hosting provider based in the Seychelles that launched in January 2026. By June, Omegatech hosted roughly 3% of all observed phishing attacks targeting U.S. financial firms. One tracked cluster of 16 .es domains hosted via Omegatech generated 585 unique attack URLs between March 25 and April 21, 2026, impersonating 41 financial brands through subdomains while registration records remained shielded.
The rise of Omegatech coincided with the decline of older infrastructure. A major phishing operation that impersonated Fidelity Investments using the Darcula phishing kit dropped sevenfold between the first and second quarters of 2026, after previously accounting for more than half of all phishing links targeting the firm. Netcraft noted that financially motivated organized criminal operators and North Korean groups continue to target banks, cryptocurrency platforms, and compromised user accounts across diverse digital vectors.
To counter fragmented campaigns, Netcraft recommends that financial institutions actively monitor newly registered domains, block suspicious links at the perimeter, and enforce stricter employee verification controls against impersonation tactics. Further details on the research are available via TechRadar Pro (https://www.techradar.com/pro/nearly-40-000-phishing-attacks-hit-us-financial-firms-in-h1-2026-automated-ai-agents-and-a-new-seychelles-bulletproof-host-fuel-aggressive-new-campaigns).
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



