NiCKEL phishing page detected

Threat Analysis: Nickel Phishing – Fake “Sponsorship” Offer Stealing Card Details This phishing campaign impersonates Nickel, a French neobank (a subsidiary of BNP Paribas). The scam uses a fake “parrainage” (referral/sponsorship) offer to lure victims into providing their personal information and full card details under the guise of participating in a rewards program. How it …

Naranja X phishing page detected

Threat Analysis: Naranja X Phishing – Fake Login Page Stealing Email and Password This phishing campaign impersonates Naranja X, a popular digital financial platform in Argentina that offers credit cards, loans, and digital accounts. The page mimics the platform’s login interface to steal customers’ email address and password. How it works:The victim receives a phishing …

Daviplata phishing page detected

Threat Analysis: Daviplata Phishing – Credential & SMS Code Harvesting This phishing campaign impersonates Daviplata, a widely used digital wallet and mobile payment platform in Colombia, operated by Davivienda Bank. The scam uses a multi-page flow to capture the victim’s document number, Daviplata password, and the SMS verification code—the three elements needed to access the …

AOL phishing page detected

Threat Analysis: AOL Phishing – Fake Login Page Stealing Email Credentials This phishing campaign impersonates AOL (America Online) , an email and online service provider. The page is designed to steal victims’ username, email address, or mobile number and password used to access AOL accounts. How it works:The victim receives a phishing email, SMS, or …

Bancolombia phishing page revealed

Threat Analysis: Generic Banking Phishing – Credential & SMS Code Harvesting This phishing campaign impersonates a financial institution (likely a bank or digital wallet in Latin America, based on the Spanish language and the “reactivar” – reactivate – pretext). The scam uses a multi-page flow to capture the victim’s username, password, and SMS verification code …

Citizens Bank phishing page detected

Then visitor will be redirected to the official website of Citizens Bank. Threat Analysis: Citizens Bank Phishing – Full Identity & Financial Data Harvesting This phishing campaign impersonates Citizens Bank, a prominent bank in the United States. The scam uses a multi-page flow to capture: This combination of data enables attackers to commit identity theft, …

Bank of America pishing pages in Spanish detected

Threat Analysis: Bank of America Phishing – Email Credential & Card Data Harvesting This phishing campaign impersonates Bank of America, targeting Spanish-speaking customers. The scam uses a multi-page flow to capture: By compromising both the email account and the payment card, attackers can gain persistent access to sensitive communications and conduct unauthorized transactions. How it …

Massachusetts Unemployment Insurance phishing page detected

Threat Analysis: Massachusetts Unemployment Insurance Phishing – SSN & Account Takeover Scam This phishing campaign impersonates the Massachusetts Unemployment Insurance (UI) Online Application portal, used by the state’s Department of Unemployment Assistance (DUA). The scam targets unemployment claimants, aiming to steal their Social Security Number (SSN), password, and email verification code—the credentials needed to access …

Credit Agricole Bank phishing page detected

Threat Analysis: CrĂ©dit Agricole Phishing – Multi‑Stage SĂ©curiPass & Credential Theft This phishing campaign impersonates CrĂ©dit Agricole. The scam uses a long, multi‑page flow to capture: By harvesting both the SMS and email codes, attackers can bypass multiple security layers and gain full account access. How it works:The victim receives a phishing email claiming they …

BAC Credomatic phishing page detected

Threat Analysis: BAC Credomatic Phishing – Fake “Banca en LĂ­nea” Login Page This phishing campaign impersonates BAC Credomatic, one of the largest banks in Central America. The page mimics the bank’s “Banca en LĂ­nea” (Online Banking) login interface to steal customers’ username and password. It also includes a “Usar Token” option, suggesting the attacker may …