Active phishing URLs tracked from PhishStats, a community threat intelligence source. Domains are shown defanged (dots replaced with [.]) and are never rendered as clickable links, this page is a monitoring reference, not a browsing tool.
Most entries above rely on a spoofed or typosquatted domain designed to look like a trusted brand at a glance, often paired with a cloned login page built to harvest credentials the moment they are typed in. Others impersonate a software vendor, a bank, or an internal IT department to trigger a fake support call or a fraudulent password reset, a technique that keeps working even against well-trained staff because it exploits urgency rather than a technical flaw.
Business email compromise takes a different route, impersonating a supplier or an executive to redirect a genuine invoice or payment, while QR-code phishing (quishing) moves the malicious link off the screen entirely and onto a scanned code, bypassing email filters altogether. Whatever the vector, the same reflex applies: verify the sender and the destination through a second, independent channel before entering any credential or approving any payment.
Contact our experts for a tailored assessment of your attack surface and cyber exposure.
Data is aggregated automatically from public sources.