US Financial Firms Faced 40,000 Phishing Attacks in H1

Attackers leveraged hundreds of hosting providers to impersonate major financial brands.

Updated on Oct. 5, 2026 in Financial Crime

Bold flat-color editorial illustration showing an isolated, monolithic server rack in a vast, empty space, representing cybercrime infrastructure.
Financial services in the United States faced nearly 40,000 phishing attacks in the first half of 2026, as criminals increasingly leveraged automated infrastructure to impersonate major institutions. AI Illustration. Upload story photo >

Live Poll

Do you feel confident that your financial accounts are safe from increasingly sophisticated phishing attacks?

In the first half of 2026, nearly 40,000 phishing URLs targeted US financial services. Criminals utilized 645 hosting providers and 576 registrars to execute these campaigns, with free hosting services accounting for over 12% of the malicious activity.

Why it matters

The rise of generative AI website builders and automated cloning tools allows attackers to deploy malicious infrastructure with minimal effort and cost. By frequently switching hosting services, attackers maintain campaign longevity while impersonating trusted financial institutions.

Investigations tracked 40,000 malicious URLs across 645 hosting providers during the first half of 2026. Data shows payment service providers were the primary target, experiencing 37.2% of all recorded phishing attempts.

The players

PayPal

This payment service provider accounted for 80.6% of all phishing attacks targeting the payment sector.

American Express

The card network firm saw 72.8% of phishing attacks directed at card networks during this period.

Omegatech

This Seychelles-based hosting provider hosted 3% of observed phishing attacks by June 2026.

The details

Attackers frequently employ subdomains to impersonate multiple financial brands through single domain clusters, complicating defense efforts. Notably, one cluster hosted by Omegatech generated 585 unique attack URLs between March 25 and April 21, 2026.

Timeline

  1. January 2026: Omegatech began its hosting operations.

  2. March 25 to April 21 2026: A single cluster generated 585 unique attack URLs.

  3. H1 2026: 40,000 phishing URLs targeted financial firms in the United States.

  4. June 2026: Seychelles-based Omegatech hosted 3% of observed phishing attacks.

Legal Context

The proliferation of malicious infrastructure reflects the broader, industry-wide shift toward AI-automated phishing campaigns. This report confirms a sharp increase in the use of AI-cloning tools to scale impersonation efforts across multiple financial brands.

Financial consumers should remain vigilant against suspicious emails or text messages that mimic official banking communications. Since attackers use automated tools to create highly realistic clones, verifying the legitimacy of a URL before entering payment information is essential for account security.

The takeaway

The effectiveness of these campaigns highlights the urgent need for consumers to treat all unsolicited digital requests for financial data with extreme caution. Implementing multi-factor authentication across all financial accounts remains a primary defense against these automated impersonation attempts.

Further reading

For more on evolving cyber threats, visit the Financial Crime section.

Live Poll

Do you feel confident that your financial accounts are safe from increasingly sophisticated phishing attacks?