PhishFort

PhishFort Brand Protection Solutions to combat phishing, fake content, and IP infringements.

07/17/2026

Good Fri-yay everyone! πŸ₯³

While some are already mentally checked out for the weekend, we’ve been doing some housekeeping. 🧹
We shipped a round of dashboard improvements. From performance enhancements and speed optimizations to general cleanups that make the product feel tighter and your day a little smoother.

If you’re a PhishFort client or partner, log in and see for yourselfπŸ‘‡
https://dashboard.phishfort.com/login
And as always, feedback is welcome. Now enjoy your Friday!

Most iGaming operators we spoke to at   know phishing is a problem.Very few know the actual scale until they see the dat...
07/06/2026

Most iGaming operators we spoke to at know phishing is a problem.

Very few know the actual scale until they see the data.

Good two days in London. πŸ“Έ

Did you know someone's home router could be used to attack corporate networks, without anyone knowing?That's how IoT bot...
07/03/2026

Did you know someone's home router could be used to attack corporate networks, without anyone knowing?

That's how IoT botnets combined with residential proxy pools work: attack traffic from IPs that look completely normal.

We published the breakdown on the blog πŸ‘‡

Compromised smart home devices route attack traffic through legitimate residential IPs β€” bypassing your perimeter controls. Here's how it works and what stops it.

In the gambling industry, a fake site using your brand isn't just a fraud problem β€” it's a compliance one.We recently he...
07/02/2026

In the gambling industry, a fake site using your brand isn't just a fraud problem β€” it's a compliance one.

We recently helped a global sportsbook operator neutralise 1,400+ threats, including infrastructure designed to bypass geofencing controls.

Full case β†’

How a global sportsbook operator dismantled geofence-bypass attack infrastructure and neutralised 1,400+ threats with PhishFort.

07/01/2026

πŸ“ IGB Live London β€” today.

Monday we published the case: 4,700+ threats, 98.9% takedown rate.

Today we're at the event to talk about what's behind those numbers.

Attackers are hosting phishing on sites.google.com.Valid HTTPS. High-reputation domain. Bypasses most filters.LotL using...
06/30/2026

Attackers are hosting phishing on sites.google.com.

Valid HTTPS. High-reputation domain. Bypasses most filters.

LotL using Google's own infrastructure β†’ infostealers + crypto drainers.

Breakdown: https://phishfort.com/google-sites-phishing-lotl-attacks/

Threat actors are using sites.google.com to host fake Workspace portals that deploy infostealers and crypto drainers. Here's how the attack works.

800 threats a year, managed manually. πŸ˜΅β€πŸ’«Not to brag, but... after twelve months with PhishFort: 4,700+ detected and act...
06/29/2026

800 threats a year, managed manually. πŸ˜΅β€πŸ’«

Not to brag, but... after twelve months with PhishFort: 4,700+ detected and actioned. 98.9% takedown success rate. 38 average hours from detection to offline.

The problem wasn't the team. It was visibility.

A global iGaming operator with millions of active players had no idea what was happening out there. Fake casinos, cloned login pages, typosquatted domains active across Europe and LATAM β€” all invisible until we mapped them.

We're proud to share the full case today: https://phishfort.com/success-cases/igaming/

P.S. If you're chasing threats like these and you're at IGB Live London this week β€” we'll be there Wednesday. Come find the team.

How a global iGaming operator went from handling ~800 threats a year manually to detecting and actioning 4,700+ in twelve months with PhishFort.

06/19/2026

Friday thought before you close the laptop:
"A takedown closes one incident. It doesn't stop the campaign".

In most persistent phishing operations targeting fintech and crypto firms, a taken-down domain is replaced within 24–72 hours. Malicious apps pulled from app stores reappear under a new developer account within days.

Here's why:

πŸ” Attackers pre-register domain inventories β€” 10, 20, sometimes 50 variants across TLDs and ccTLDs. Reactive takedowns typically catch 20–30% of a campaign's total inventory.

⚑ Fast flux infrastructure means a domain can keep resolving even after the hosting provider acts. Only a registrar-level suspension stops it, and many teams are targeting the wrong layer.

🎭 Content cloaking lets fake domains sit dormant (serving benign content) until they age past automated risk scoring thresholds. Then the malicious content goes live.

πŸ“± App store removals don't stop repackaged re-submissions. A $25 developer account and a new icon is enough to get back in the store within 48–72 hours.

The common thread? Every re-emergence pattern exploits the gap between a takedown event and the next monitoring cycle.

Reactive monitoring creates windows measured in days. 24/7 continuous monitoring β€” flagging new registrations by brand pattern before content is served β€” closes that window before the replacement domain establishes itself.

A takedown without continuous monitoring is just a delay.

Already watching the World Cup? πŸ†So are the scammers. πŸ‘οΈ Last week we covered how the hashtag  was already a brand threa...
06/18/2026

Already watching the World Cup? πŸ†
So are the scammers. πŸ‘οΈ

Last week we covered how the hashtag was already a brand threat for gambling platforms. This week, our researchers went deeper, and what they found is worth flagging before the weekend.

We published the full breakdown of how the attack chain works β€” stages, data collected at each step, and what teams should be tracking now.

PhishFort researchers identified multi-stage fake FIFA ticketing sites harvesting credentials, PII, and payment data. Here's how the infrastructure works and what to monitor.

πŸ“’ 🚨 UPCOMING LIVE WEBINAR β€” June 25 Β· 11:00 AM ESTFraud has nearly tripled in a decade.It's now your CEO's  #1 cyber con...
06/16/2026

πŸ“’ 🚨 UPCOMING LIVE WEBINAR β€” June 25 Β· 11:00 AM EST

Fraud has nearly tripled in a decade.

It's now your CEO's #1 cyber concern β€” ahead of ransomware.

And most security teams still don't have a number for it.

Join Julian Drangosch for a live, data-driven briefing on the real economic impact of phishing in 2026.

β†’ Why fraud has overtaken ransomware on the board agenda

β†’ The double-edged role of AI in today's attacks

β†’ Where legacy systems and third-party risk are creating your biggest exposure

β†’ What the global skills shortage means for your supply chain

SAVE THE DATE!

πŸ“… Thursday, June 25 Β· 11:00 AM EST / 8:00 AM PT

CISOs, brand protection leads, and SOC managers β€” this one's built for you.

πŸ”— Register here!

Fraud has nearly tripled in a decade and is now the #1 CEO cyber concern. Join PhishFort for a live, data-driven briefing on what the numbers mean for your organization.

Address

166 Geary Street STE 1500 # 569
San Francisco, CA
94108

Alerts

Be the first to know and let us send you an email when PhishFort posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share