New Omegatech Bulletproof Host Captures 3% of US Financial Phishing in Just 6 Months as Threat Actors Turn to Agent AI and Free Hosting for Developers.
- US financial services faced nearly 40,000 phishing URLs during the first half of 2026
- Attackers used 645 hosting providers to distribute financial phishing campaigns
- Free hosting accounted for 12.6% of phishing URLs targeting financial services
Phishing campaigns targeting US financial institutions are spreading across a fragmented network of hosting services, making fraudulent infrastructure difficult to contain.
New research from Netcraft has found that nearly 40,000 unique phishing URLs connected to US financial services were discovered in the first half of 2026.
Behind those URLs were 645 hosting providers and 576 registrars, while newer services and automated AI tools helped attackers move quickly between platforms.
Latest videos ofTechnologyRadar
Cheap infrastructure is helping campaigns multiply
The scale of the activity becomes clearer when you examine the services carrying out these attacks and not just the fraudulent websites.
Free developer and app hosting accounted for 12.6% of phishing URLs reported in US financial services during the first half of 2026.
That means that approximately one in eight observed attacks relied on infrastructure that attackers could access without paying conventional hosting fees.
Netcraft observed significant changes in infrastructure usage between the first and second quarters, suggesting that criminals were switching services as infrastructure became unavailable or less useful.
AI is facilitating that move by helping users create websites, render legitimate pages, and deploy malicious infrastructure with less technical effort.
Netcraft said generative AI Website builders and cloning tools are increasingly including free web hosting options, further reducing the work needed to set up campaigns.
The spoofed financial brands also show where attackers focused their efforts across the industry during the reporting period.
Payment service providers accounted for 37.2% of the phishing activity observed, and PayPal accounted for 80.6% of attacks within that subsector.
American Express accounted for 72.8% of the activity seen across card networks, demonstrating the extent to which campaigns can focus on recognizable financial brands.
Omegatech emerges as another source of attack infrastructure
The infrastructure landscape changed further with the emergence of Omegatech, a paid hosting provider based in Seychelles, which started operations in January 2026.
In June, Netcraft attributed approximately 3% of phishing attacks seen against US financial services to infrastructure hosted through Omegatech.
One cluster contained 16 .es domains that generated 585 unique attack URLs between March 25 and April 21, 2026.
Those domains were used to impersonate 41 financial brands through subdomains, allowing one group to support campaigns against numerous institutions.
Registration data for many of those domains was not available, limiting the visibility of the companies responsible for registering the infrastructure.
Omegatech’s emergence came as another major campaign was coming to an end after attacking Fidelity Investments via the Darcula phishing platform.
That operation grew sevenfold between the first and second quarters, after previously accounting for more than half of the phishing infrastructure impersonating Fidelity.
Meanwhile, financially motivated North Korean groups and organized criminal operators continued to pursue compromised banks, cryptocurrency services, and accounts.
The changing mix suggests that attackers are not relying on a single platform, campaign or technique to reach financial customers.
Financial companies are advised to closely monitor newly registered domains, restrict suspicious links, and strengthen employee verification procedures against phishing attempts.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment