Phishing sites we found in certificate logs

Between September 14, 2026 and October 6, 2026, we flagged 33,059 suspicious names in public Certificate Transparency logs, reviewed 19,291 of them and added 5,725 phishing sites to the EZOBLOCKER security list. No user data, DNS queries or IP addresses were used for this work.

Snapshot: October 6, 2026Scanned: September 14, 2026 to October 6, 2026

Status

Our own security list currently holds 5,964 domains. On phones with the Security category on, these names are stopped on our servers; the list is open on GitHub under CC0.

See the security list on GitHub

From 33,059 names to 5,725 sites

Not every flagged name is phishing. This is how the filtering went, step by step:

  • 33,059names flaggednew certificates with a brand and a phishing word in the name
  • 19,291sites reviewedafter names of the same site were merged
  • 3,981already on other listsalready in the external lists we use, not added again
  • 5,725phishing sites confirmedadded to our own list as 5,964 rules

How did we know they were fake?

Every confirmed site has one recorded piece of evidence. Breakdown by type of evidence:

  • Flagged by the host as phishing4,829

    The site's host has flagged it as phishing; visitors see a warning instead of the page.

  • Fake login page27

    We opened the page: it imitates a brand's sign-in screen and has a password field.

  • Scam page101

    We opened the page: it asks for no password, but uses fake rewards, support lines or payment offers to get money, personal details or a file download.

  • Cloaked page21

    The page looks empty or harmless to checkers, but carries traces of a ready-made phishing kit.

  • Parked brand imitation747

    The name imitates a brand and is waiting on a parking page for now; it was listed before it went into use.

Which traps are set most often?

The most common types among confirmed sites. Dots in the example names are written as [.] so they cannot be opened by accident; they are not links.

  • Fake crypto wallets and exchanges

    3,330 sites

    Looks like a hardware wallet or exchange sign-in page and asks for your recovery phrase (seed) or login details.

    Example names

    • itrustcapital-sign-us-app-in[.]pages[.]devfake login page
    • wallet-io-ledgre[.]pages[.]devscam page
    • auths-netcoins[.]pages[.]devscam page
    • support-blockfii-logix[.]pages[.]devscam page
    • robinhood-logiin-web[.]pages[.]devscam page
    • login-ndaxx-us[.]pages[.]devscam page

    A real wallet does not ask you to type your recovery phrase into a web page.

  • Social media account recovery and "verification" traps

    932 sites

    Says "your account will be disabled", offers a "verified badge" or an "ad account appeal", then asks for your password and verification code.

    Example names

    • youtubepremium[.]sbsfake login page
    • insta-claim[.]comfake login page
    • nid-naver-mail-nidlogin-login1-rweopxqbpznjzhmuffoiraef[.]pages[.]devscam page
    • kakao-online[.]sitescam page
    • appeal-youtube[.]comscam page
    • instagram-support-policy[.]pages[.]devflagged by host

    Check the warning in the app's own notifications, not through the link in the message.

  • Fake banks and payment services

    213 sites

    Copies the sign-in screen of a bank or payment app and asks for card details and one-time codes.

    Example names

    • usbankverify[.]comfake login page
    • hdfcbanknetbanking[.]comscam page
    • onlinesbi-yono-login[.]xinscam page
    • al-meezan-invest[.]proscam page
    • aktivasi-kuponundian-brimo[.]pages[.]devflagged by host
    • usbank-online[.]workers[.]devflagged by host

    Open your bank through its own app or by typing the address yourself.

  • Fake email and cloud accounts

    104 sites

    Imitates the sign-in screen of an email, cloud storage or e-signature service and asks for your password to "view a shared document".

    Example names

    • roadrunner-email-login-gmail[.]pages[.]devfake login page
    • statement-viewonce-givesusquotes-sharepoint[.]pages[.]devscam page
    • cuentahotmail[.]orgscam page
    • wsignin-msonline-verify-docusign[.]workers[.]devflagged by host
    • apple-icloud-lawsuit-claim[.]pages[.]devflagged by host
    • api-cobrandid-docusign-msonline[.]workers[.]devflagged by host

    Open a document shared with you in the service's own app, not through the link in the message.

  • Fake shopping and subscription pages

    54 sites

    Looks like a store, music or payment service and asks for card details to "confirm your order" or "activate premium".

    Example names

    • tiket-tokopedia[.]comfake login page
    • sspotifypremium[.]com[.]infake login page
    • spotifypremiumapk[.]camfake login page
    • oresundbron[.]comscam page
    • spotify-podcast-login[.]pages[.]devscam page
    • aktivasi-akun-shopee[.]pages[.]devflagged by host

    Check your orders and subscriptions in the store's own app or in your phone's settings.

  • Robux and gift card pages aimed at children

    20 sites

    Promises game currency or gift cards and steers the child into entering account details, fake "verification" steps or downloading a file.

    Example names

    • roblox-reward-hub[.]pages[.]devfake login page
    • free-robux-with-no-verification-at-all[.]pages[.]devscam page
    • free-robux-no-verification-real[.]pages[.]devscam page
    • gift-card-in-roblox-free[.]pages[.]devscam page
    • mediafire-zip-fortnite[.]pages[.]devflagged by host
    • roblox-toy-codes-generator-no-human-verification[.]pages[.]devflagged by host

    Talk with your child about typing a game password only into the game's own screen.

  • Fake tax, fine and government portals

    19 sites

    Poses as a tax refund, an unpaid fine or an official notice to collect identity and card details.

    Example names

    • mieru-incometax-mobile[.]pages[.]devfake login page
    • elster-online-finanzamt[.]sbsscam page
    • www-8-receita-simples-fazenda[.]digitalflagged by host
    • www8-receita-fazendagerador[.]siteflagged by host

    Check official notices by opening the agency's address you already know yourself.

  • Fake parcel and delivery notices

    11 sites

    Collects card details with a "your parcel is waiting, pay a small fee" message.

    Example names

    • royalmail-redelivery[.]comflagged by host
    • concoursdelaposte[.]pages[.]devflagged by host

    Check the tracking number by typing it into the carrier's own site or app.

The remaining 1,042 sites fall into less common types.

Most imitated brands

Brand names that appear most often in confirmed site names, with the number of sites. These brands have no connection to this page or to EZOBLOCKER; they are named only because they were imitated.

  1. Trezor811
  2. Meta419
  3. Ledger417
  4. Coinbase357
  5. MetaMask264
  6. Uphold260
  7. Facebook248
  8. Robinhood186
  9. Instagram160
  10. Ledger Live157
  11. Netcoins143
  12. iTrustCapital130
  13. Exodus121
  14. KuCoin119
  15. NDAX107
  16. Naver74
  17. BlockFi61
  18. Kraken57
  19. Apple45
  20. Gemini42

Where are they hosted?

Most fake sites do not register their own domain; they open on subdomains of page services that can be set up in minutes.

  • pages.dev4,764
  • workers.dev25
  • wasmer.app5

Most common endings among sites with their own domain

  • .dev 4,789
  • .ph 735
  • .com 61
  • .info 25
  • .shop 12
  • .cc 9
  • .app 8
  • .cfd 7
  • .org 7
  • .icu 6
  • .de 6
  • .help 5

Method

  1. The only source is public Certificate Transparency logs. When a site gets an HTTPS certificate, its name is written to these logs, so newly opened fake sites can be caught while their links are spreading.
  2. New names that combine a brand name with phishing words such as login, verify or support are flagged.
  3. Each flagged site is opened and checked, a language model gives a second opinion, and a site passes the rule-based approval only with one of the pieces of evidence above.
  4. Names already on external lists are not added; only what we found ourselves goes into our own list.

Numbers are a snapshot from October 6, 2026 and are refreshed regularly.