Phishing sites we found in certificate logs
Between September 14, 2026 and October 6, 2026, we flagged 33,059 suspicious names in public Certificate Transparency logs, reviewed 19,291 of them and added 5,725 phishing sites to the EZOBLOCKER security list. No user data, DNS queries or IP addresses were used for this work.
Status
Our own security list currently holds 5,964 domains. On phones with the Security category on, these names are stopped on our servers; the list is open on GitHub under CC0.
See the security list on GitHubFrom 33,059 names to 5,725 sites
Not every flagged name is phishing. This is how the filtering went, step by step:
- 33,059names flaggednew certificates with a brand and a phishing word in the name
- 19,291sites reviewedafter names of the same site were merged
- 3,981already on other listsalready in the external lists we use, not added again
- 5,725phishing sites confirmedadded to our own list as 5,964 rules
How did we know they were fake?
Every confirmed site has one recorded piece of evidence. Breakdown by type of evidence:
-
Flagged by the host as phishing4,829
The site's host has flagged it as phishing; visitors see a warning instead of the page.
-
Fake login page27
We opened the page: it imitates a brand's sign-in screen and has a password field.
-
Scam page101
We opened the page: it asks for no password, but uses fake rewards, support lines or payment offers to get money, personal details or a file download.
-
Cloaked page21
The page looks empty or harmless to checkers, but carries traces of a ready-made phishing kit.
-
Parked brand imitation747
The name imitates a brand and is waiting on a parking page for now; it was listed before it went into use.
Which traps are set most often?
The most common types among confirmed sites. Dots in the example names are written as [.] so they cannot be opened by accident; they are not links.
-
Fake crypto wallets and exchanges
3,330 sitesLooks like a hardware wallet or exchange sign-in page and asks for your recovery phrase (seed) or login details.
Example names
itrustcapital-sign-us-app-in[.]pages[.]devfake login pagewallet-io-ledgre[.]pages[.]devscam pageauths-netcoins[.]pages[.]devscam pagesupport-blockfii-logix[.]pages[.]devscam pagerobinhood-logiin-web[.]pages[.]devscam pagelogin-ndaxx-us[.]pages[.]devscam page
A real wallet does not ask you to type your recovery phrase into a web page.
-
Social media account recovery and "verification" traps
932 sitesSays "your account will be disabled", offers a "verified badge" or an "ad account appeal", then asks for your password and verification code.
Example names
youtubepremium[.]sbsfake login pageinsta-claim[.]comfake login pagenid-naver-mail-nidlogin-login1-rweopxqbpznjzhmuffoiraef[.]pages[.]devscam pagekakao-online[.]sitescam pageappeal-youtube[.]comscam pageinstagram-support-policy[.]pages[.]devflagged by host
Check the warning in the app's own notifications, not through the link in the message.
-
Fake banks and payment services
213 sitesCopies the sign-in screen of a bank or payment app and asks for card details and one-time codes.
Example names
usbankverify[.]comfake login pagehdfcbanknetbanking[.]comscam pageonlinesbi-yono-login[.]xinscam pageal-meezan-invest[.]proscam pageaktivasi-kuponundian-brimo[.]pages[.]devflagged by hostusbank-online[.]workers[.]devflagged by host
Open your bank through its own app or by typing the address yourself.
-
Fake email and cloud accounts
104 sitesImitates the sign-in screen of an email, cloud storage or e-signature service and asks for your password to "view a shared document".
Example names
roadrunner-email-login-gmail[.]pages[.]devfake login pagestatement-viewonce-givesusquotes-sharepoint[.]pages[.]devscam pagecuentahotmail[.]orgscam pagewsignin-msonline-verify-docusign[.]workers[.]devflagged by hostapple-icloud-lawsuit-claim[.]pages[.]devflagged by hostapi-cobrandid-docusign-msonline[.]workers[.]devflagged by host
Open a document shared with you in the service's own app, not through the link in the message.
-
Fake shopping and subscription pages
54 sitesLooks like a store, music or payment service and asks for card details to "confirm your order" or "activate premium".
Example names
tiket-tokopedia[.]comfake login pagesspotifypremium[.]com[.]infake login pagespotifypremiumapk[.]camfake login pageoresundbron[.]comscam pagespotify-podcast-login[.]pages[.]devscam pageaktivasi-akun-shopee[.]pages[.]devflagged by host
Check your orders and subscriptions in the store's own app or in your phone's settings.
-
Robux and gift card pages aimed at children
20 sitesPromises game currency or gift cards and steers the child into entering account details, fake "verification" steps or downloading a file.
Example names
roblox-reward-hub[.]pages[.]devfake login pagefree-robux-with-no-verification-at-all[.]pages[.]devscam pagefree-robux-no-verification-real[.]pages[.]devscam pagegift-card-in-roblox-free[.]pages[.]devscam pagemediafire-zip-fortnite[.]pages[.]devflagged by hostroblox-toy-codes-generator-no-human-verification[.]pages[.]devflagged by host
Talk with your child about typing a game password only into the game's own screen.
-
Fake tax, fine and government portals
19 sitesPoses as a tax refund, an unpaid fine or an official notice to collect identity and card details.
Example names
mieru-incometax-mobile[.]pages[.]devfake login pageelster-online-finanzamt[.]sbsscam pagewww-8-receita-simples-fazenda[.]digitalflagged by hostwww8-receita-fazendagerador[.]siteflagged by host
Check official notices by opening the agency's address you already know yourself.
-
Fake parcel and delivery notices
11 sitesCollects card details with a "your parcel is waiting, pay a small fee" message.
Example names
royalmail-redelivery[.]comflagged by hostconcoursdelaposte[.]pages[.]devflagged by host
Check the tracking number by typing it into the carrier's own site or app.
The remaining 1,042 sites fall into less common types.
Most imitated brands
Brand names that appear most often in confirmed site names, with the number of sites. These brands have no connection to this page or to EZOBLOCKER; they are named only because they were imitated.
- Trezor811
- Meta419
- Ledger417
- Coinbase357
- MetaMask264
- Uphold260
- Facebook248
- Robinhood186
- Instagram160
- Ledger Live157
- Netcoins143
- iTrustCapital130
- Exodus121
- KuCoin119
- NDAX107
- Naver74
- BlockFi61
- Kraken57
- Apple45
- Gemini42
Where are they hosted?
Most fake sites do not register their own domain; they open on subdomains of page services that can be set up in minutes.
Most common endings among sites with their own domain
- .dev 4,789
- .ph 735
- .com 61
- .info 25
- .shop 12
- .cc 9
- .app 8
- .cfd 7
- .org 7
- .icu 6
- .de 6
- .help 5
Method
- The only source is public Certificate Transparency logs. When a site gets an HTTPS certificate, its name is written to these logs, so newly opened fake sites can be caught while their links are spreading.
- New names that combine a brand name with phishing words such as login, verify or support are flagged.
- Each flagged site is opened and checked, a language model gives a second opinion, and a site passes the rule-based approval only with one of the pieces of evidence above.
- Names already on external lists are not added; only what we found ourselves goes into our own list.
Numbers are a snapshot from October 6, 2026 and are refreshed regularly.