Nearly 40,000 phishing links targeted US financial firms in the first half of 2026, and the infrastructure behind them is more scattered than ever.
Netcraft tracked the URLs across 645 hosting providers and 576 registrars, with free developer and app-hosting services carrying 12.6% of the attacks, roughly one in eight. Generative AI website builders and cloning tools, several of which bundle their own free hosting, made it faster to spin up convincing fakes. A new Seychelles-based paid host called Omegatech launched in January 2026 and by June accounted for about 3% of the phishing traffic; one cluster of 16 .es domains it hosted produced 585 attack URLs in under a month while impersonating 41 different financial brands. Payment services took the brunt of it, accounting for 37.2% of observed activity, with PayPal alone making up 80.6% of that subsector while American Express absorbed 72.8% of attacks on card networks.
The real story isn't the URL count, it's the churn. Netcraft saw attackers shift infrastructure substantially between Q1 and Q2, treating hosts as disposable the moment one gets flagged, a sign that takedown efforts are working just well enough to keep criminals moving rather than stopping them. Pair that with AI tools that automate the cloning work, and defenders are chasing a target that resets every few weeks.
A Darcula-powered campaign against Fidelity fell sevenfold between those same two quarters, which reads less like a victory than a reminder that one shuttered operation just frees up room for the next host to absorb the overflow.