09/07/2026
09:36

The most widespread Phishing attempts in JULY 2026.


Find out the most common phishing attempts you might encounter and avoid

PHISHING INDEX

Below are the most common email phishing attempts detected by the TG Soft Anti-Malware Research Center in JULY 2026:

30/07/2026 => Aruba - Unknown Device
29/07/2026 => Banca MEDIOLANUM
18/07/2026 => Credit Agricole
17/07/2026 => Aruba - Service suspension
16/07/2026 => Webmail
15/07/2026 => Bank
13/07/2026 => Emai Account
08/07/2026 => OpenAI
08/07/2026 => Emai Account
02/07/2026 => Microsoft

These emails aim to deceive unsuspecting victims into providing sensitive information, such as bank account details, credit card codes, or personal login credentials, with all the easily imaginable consequences.

30 July 2026 ==> Phishing Aruba -  Unknown device

SUBJECT: <An unknown device has accessed your email.>

Here is yet another phishing attempt posing as a message from the Aruba brand.

Clicca per ingrandire l'immagine della falsa e-mail di Aruba che induce l'utente ad effettuare l'accesso per controllare gli accessi, ma in realtà è una TRUFFA!
The message informs the recipient that a login attempt from a new device has been detected on their email account hosted by Aruba. It therefore asks them to check whether the login was authorised via the following link:

ACCESS VERIFICATION

Let's always exercise caution when asked to enter personal credentials via suspicious links sent by email.
The well-known web hosting, email and domain registration company, Aruba, is clearly not involved in the mass sending of these emails, which are outright scams whose aim, as always, is to steal sensitive data from unsuspecting recipients.

We can see straight away that the email address in the message appears to be that of the unsuspecting user. This technique, which conceals the true sender, is often used in these scams.   

Clicca per ingrandire l'immagine del falso sito di Aruba dove viene richiesto di effettuare l'accesso per recuperare i messaggi in sospeso...in realtà si tratta di una TRUFFA!
Anyone who unfortunately clicks on the link will be redirected to a web page unrelated to the Aruba website, with an unusual address/domain:

https[:]//[FakeDomainName/amazonaws[.]com/Arubs[.]html#***]

On this page, users are asked to log in to their customer area by entering their email password in order to check their login history and report any unusual activity.

We always urge you to pay attention to every detail, however trivial, not to rush, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to the cybercriminals behind the scam, who will use them for criminal purposes.


29 July 2026 ==> Phishing Banca Mediolanum

SUBJECT: < Regular updating of the customer database >
 
Below, we examine the following phishing attempt, which comes as a fake message from  Banca MEDIOLANUM, the well-known bank.

Clicca per ingrandire l'immagine della falsa e-mail di Banca MEDIOLANUM che cerca di rubare i dati sensibili del destinatario...
The message reads: “In accordance with the regulatory provisions on anti-money laundering and financial transparency (Legislative Decree 231/2007, as amended), Banca Mediolanum S.p.A. is required to keep its customers’ personal, identification and contact details up to date at all times.
The purpose of this communication is to invite you to check that the information currently held by us is correct and, where necessary, to update it via the dedicated digital platform
.”
The user is then asked to update or confirm their details via the following link:

  ACCESS THE UPDATE FORM

If we examine the message, we immediately notice that it contains an email address <noreply[at]mediolanum[dot]com> which, although misleading, does not originate from the official Banca MEDIOLANUM domain. We should always exercise the utmost caution before clicking on suspicious links.

The aim is to trick the victim into logging in to their online banking account.

Clicca per ingrandire l'immagine del falso sito contraffatto di Banca MEDIOLANUM che ha l'obiettivo di rubare le credenziali di accesson del noto istituto bancario...
Anyone who unfortunately clicks on the ACCESS THE UPDATE FORM
link will be redirected to a fraudulent web page, which is completely unrelated to the official  Banca MEDIOLANUM website.
From the image shown on the side, we can see that the web page is well designed and mimics the official banking portal quite effectively.

 Based on these points, we urge you to pay close attention to any misleading details, bearing in mind that before entering sensitive data – in this case, your online banking credentials – make sure to check the URL where the login form is hosted.


In this case, the landing page is hosted at a URL that is completely unrelated to the official website of the well-known bank.


hrrps://[FakeDomainName*]/web/login[.]php.

This MISLEADING WEBSITE is run by cybercriminals whose aim is to gain access to your most valuable data in order to use it for illegal purposes.


18 July 2026 ==> Phishing Crédit Agricole

SUBJECT: < Restriction message 18/07/2026 00:47:11 >
 
Below, we examine the following phishing attempt, contained in a fake message purporting to be from Crédit Agricole, the well-known French bank.

Clicca per ingrandire l'immagine della falsa e-mail di Credit Agricole, la Banca online che cerca di rubare i dati sensibili del destinatario...
The message reads: "Your CreditAgricole account password will expire in 48 hours. To ensure uninterrupted access to your account and maintain the highest level of security, we ask you to update your password before the expiry date." It then invites the user to update their password via the following link:

Change password

On closer inspection of the message, we immediately notice that it contains an email address <myagricole[at]lcn613[dot]com>, which clearly does not belong to the official Crédit Agricole domain. We should always exercise the utmost caution before clicking on suspicious links.

The aim is to trick the victim into logging in to their online banking account.

Clicca per ingrandire l'immagine del falso sito contraffatto di Credit Agricole che cerca di rubare le credenziali di accesso all'Home Banking...
Anyone who, unfortunately, clicks on the Change password
link, will be redirected to a fake web page, which is designed to look like the official Crédit Agricole website.
From the image shown here, we can see that the web page is well designed and bears a close resemblance to the official banking portal.

Based on these considerations, we urge you to pay close attention to any misleading details and to remember that before entering sensitive information—in this case, your online banking credentials—it is crucial to check the URL where the authentication form is hosted.


In this case, the landing page is hosted at a URL unrelated to the official website of the well-known bank.

hrrps://agricolesrecured[FakeDomainName*]...

This scam site is run by cybercriminals whose goal is to steal your most valuable data in order to use it for criminal purposes.


17 July 2026 ==> Phishing Aruba - Service suspension

SUBJECT: <Important: Outstanding payment for your Aruba account>

Phishing attempts posing as communications from the Aruba brand continue.

Clicca per ingrandire l'immagine della falsa e-mail di Aruba che induce l'utente ad effettuare il rinnovo del dominio, ma in realtà è una TRUFFA!
The message informs the recipeint that Aruba’s billing system has detected that the hosting service associate  with their domain has expired.Iy then says: "To date, the service has not been renewed despite previous reminders being sent.
Therefore, your domain has been temporarily suspended, resulting in the interruption of all associated services
” To avoid the service suspension and to ensure that the domain and all associated services remain active, it is necessary to make the payment promptly and in any case within 3 days; otherwise, the hosting service will be permanently cancelled.
The user is therefore asked to make the payment via the following link:

Renew now

The well-known web hosting, email and domain registration company, Aruba, is clearly not involved in the mass sending of these emails, which are outright scams whose aim, as always, is to steal sensitive data from unsuspecting recipients.

When we examine the text of the message, we immediately notice that the sender’s email address <noreply[at]i-d-leistung[dot]de> does not originate from the official Aruba domain.
The user is given three days to renew their email account. The aim is to encourage the user, fearing that their email account might be deactivated, to act immediately without giving it too much thought. 

Anyone who, unfortunately, clicks on the Renew now link, will be redirected to the page shown.

Clicca per ingrandire l'immagine del falso sito di Banca Sella dove viene richiesto di effettuare il pagamento del rinnovo del dominio di Aruba...in realtà si tratta di una TRUFFA!
As we can see, first of all, contrary to expectations, the landing page does not link to the login form for Aruba’s RESTRICTED AREA but hosts an online payment form that appears to be powered by the BancaSella payment gateway. Here, you are asked directly to enter your credit card details to complete the payment of the modest sum of €5.99.
Although the rush and the fear of having their email account suspended may prompt users to complete the transaction quickly, a quick glance at the URL displayed in the browser bar is enough to realise that the payment form is not hosted on the official Aruba domain, nor on BancaSella’s.
We therefore urge you not to rush and to remember that, when faced with these attempts at cyber fraud, you must pay close attention to every detail, however trivial it may seem.
If you enter the requested details – specifically your credit card details – these will be sent to the cybercriminals behind the scam, who will use them for illegal purposes.


16 July 2026 ==> Phishing Webmail

SUBJECT: <**** New Notification: 5 Undelivered Message Reports>

Below, we examine another phishing attempt, very similar to the previous one, which aims to steal the victim’s email account credentials.

Clicca per ingrandire l'immagine della falsa e-mail che si spaccia per il server di posta elettronica e che induce l'utente a cliccare sul link per rubare le credenziali di accesso...in realtà è una TRUFFA!
The message, in English, informs the recipient that there are 5 messages waiting and that they can check their pending messages via the following link:

Review Messages

On closer inspection of the message, we can see that it originates from the recipient’s email domain. This is highly unusual and should certainly raise our suspicions.

Anyone who unfortunately clicks on the link provided will be redirected to a fraudulent web page that mimics the email account login page.

Clicca per ingrandire l'immagine del falso sito del server di posta elettronica dove viene richiesto di effettuare l'accesso al proprio account...in realtà si tratta di una TRUFFA!
On this page, users are asked to log in to their account by entering, specifically, the password for their email account in order to view any pending messages

Actually, the page to which the user is redirected to enter their email account credentials is hosted on a suspicious address/domain, which is listed below:

 https[:]//[FakeDomainName*]

We urge you always to pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to a remote server and used by cybercriminals, with all the associated and easily imaginable risks.


15 July 2026 ==> Phishing Bank

SUBJECT: <Official Communication: Mandatory Online Banking Verification >

The message, using graphics stolen from or similar to those of a well-known bank, attempts to pass itself off as an official communication in order to induce the recipient to comply with the request and fall into this trap based on social engineering technique.

Clicca per ingrandire l'immagine della falsa e-mail che cerca di indurre il ricevente a inserire le credenziali del Home Banking.
The message warns the unsuspecting recipient: “Your current account has been suspended due to failure to comply with the online banking profile verification requirements, in accordance with the banking regulations currently in force.
You are required to complete the verification process within 24 hours of receiving this notification. In the event of further non-compliance, your account will be permanently and irrevocably closed, without further notice and with no possibility of reactivation
.” The user is then asked to complete the procedure via the following link:

PROCEED WITH THE VERIFICATION

We can see straight away that the alert message comes from a highly suspicious email address, <service3(at)lamiagioia(dot)it>, and contains very generic text, despite the inclusion of the bank’s logo in an attempt to mislead the user. The aim is to trick the victim into logging into their banking app so that their details can be stolen.
 
Anyone who, unfortunately, clicks on the  PROCEED WITH THE VERIFICATION
link, will be redirected to a suspicious web page, which has already been flagged as a SCAM PAGE/SITE. Actually it is run by cybercriminals whose aim is to gain access to your most valuable data so that they can use it for their own purposes.

To conclude, we would urge you to always be wary of any email asking you to enter confidential information, and to avoid clicking on suspicious links, which could lead you to a fake website that is difficult to distinguish from the genuine one.


13 July 2026 ==> Phishing Email Account

SUBJECT: <Action Required*** Pending Message Report On 7/13/2026>

Below, we analyse another phishing attempt aimed at stealing the victim’s email account credentials.

Clicca per ingrandire l'immagine della falsa e-mail che si spaccia per il server di posta elettronica e che induce l'utente a cliccare sul link per rubare le credenziali di accesso...in realtà è una TRUFFA!
The message, in English, informs the recipient that they have 9 pending messages and that they can free up space in their email inbox by following the procedure set out via the link in the email:

Review Messages

On closer inspection, we can see that the message comes from an email address – <info(at)telpro(dot)co(dot)it> – which is rather unusual and has no connection to the recipient’s email domain. This is decidedly unusual and should certainly raise our suspicions.

Anyone who unfortunately clicks on the link provided will be redirected to a fraudulent web page that mimics the email account login page.

Clicca per ingrandire l'immagine del falso sito del server di posta elettronica dove viene richiesto di effettuare l'accesso al proprio account...in realtà si tratta di una TRUFFA!
On this page, users are asked to log in to their account by entering, specifically, their email password in order to download any pending messages and free up space.

Actually, the page where the user is redirected to enter their email account credentials is hosted on a suspicious address/domain, which is listed below:

 https[:]//[FakeDomainName*]

We urge you always to pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to a remote server and used by cybercriminals, with all the associated and easily imaginable risks.


08 July 2026 ==> Phishing OpenAI

SUBJECT: <Your OpenAI payment has expired>

Below, we analyse the phishing attempt aimed at stealing the victim’s credit card details.

Clicca per ingrandire l'immagine della falsa e-mail che si spaccia per il server di posta elettronica e che induce l'utente a cliccare sul link per rubare le credenziali di accesso...in realtà è una TRUFFA!
The message informs the recipient that they need to update their registered credit card to regain access to their OpenAI subscription. The last payment attempt appears to have failed. To proceed, they must click on the link:

Aggiorna carta


On closer inspection, we can see that the message contains a suspect email address: <natour21(dot)otp(at)gmail[dot]com>. This should raise suspicions.

Anyone who unfortunately clicks on the link provided will be redirected to a fraudulent web page, which is designed to look like the OpenAI website.

Clicca per ingrandire l'immagine del falso sito del server di posta elettronica dove viene richiesto di effettuare l'accesso al proprio account...in realtà si tratta di una TRUFFA!
On this page, users are asked to enter their credit card details to proceed with the payment for their subscription… or so it would seem.

Actually, the page is hosted on an unusual address/domain:

https[:]//[FakeDomainName*]


We would like to remind you to always pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake websites, as these will be sent to a remote server and used by cybercriminals, with all the associated risks easily imaginable.

08 July 2026 ==> Phishing Email Account

SUBJECT: <Statement_REF_2026_045A Detailed_account_summary_for_July_2026>

Below, we analyse the phishing attempt, which aims to steal the victim’s email account credentials.

Clicca per ingrandire l'immagine della falsa e-mail che si spaccia per il server di posta elettronica e che induce l'utente a cliccare sul link per rubare le credenziali di accesso...in realtà è una TRUFFA!
The message informs the recipient that a document has been prepared and is ready for signing. It does not contain any other information that would help us identify the type of file referred to in the email or its possible origin. Perhaps this is a summary document for an account (?) relating to the month of July, as indicated in the subject line, but only a very general part of the shared file name is shown: ‘DOC_001830787....". To continue, the user is asked to download or open the document via the following link:

DOWNLOAD FILE

Looking at the message, we can see that it has an email address <sales(at)*******[dot]co[dot]za> from a suspicious domain. This alone should raise suspicions.

Anyone who unfortunately clicks on the links provided will be redirected to a fraudulent web page that mimics the email account login page.

Clicca per ingrandire l'immagine del falso sito del server di posta elettronica dove viene richiesto di effettuare l'accesso al proprio account...in realtà si tratta di una TRUFFA!
On this page, the user is asked to log in to their account by entering, specifically, the password for their email account, and then download the document they have received.

Actually, the page where the user is redirected to enter their email account credentials is hosted on a suspicious address/domain, which is listed below:

 https[:]//[FakeDomainName*]

We urge you to always pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to a remote server and used by cybercriminals, with all the associated and easily imaginable risks.

02 July 2026 ==> Phishing Microsoft

SUBJECT: < ***** S.r.l.".>

Clicca per ingrandire l'immagine della falsa e-mail che cerca di indurre il ricevente a cliccare sui link per rubare le credenziali di accesso all'account di Microsoft.
Below, we analyse the phishing attempt aimed at stealing Microsoft account credentials.
 
The message, seemingly from a certain Maurizio at the company **** S.r.l., seems to share a tax document with the recipient. The file named ‘*****SRL-Invoice 2030072026’ seems to be an invoice that the recipient may need to download and pay. The user is therefore invited to download the document for reference and to carry out the necessary checks by clicking on the following link:

*****SRL-Invoice 2030072026

Looking at the email, we can see that the cybercriminal has taken care to use – probably via a label – an email address that appears to belong to the supplier or customer who sent the file. These measures are designed to make the message seem more credible, thereby leading the recipient – who sees the email coming directly from one of their own suppliers or customers – to trust it and click on the link.

Clicca per ingrandire l'immagine del falso sito contraffatto che chiaramente non ha nulla a che vedere con Microsoft...
 We also notice that the official contact details (website, registered office and business address, telephone number, etc.) of the company that is supposed to have issued and sent the invoice are listed at the bottom.
Anyone who unfortunately clicks on the link *****SRL-Invoice 2030072026
will be redirected to a suspicious web page – which is visually well-designed – where they are asked to log in to their Microsoft account in order to download the file mentioned in the message.
However, the page to which the user is redirected is hosted on a suspicious address/domain:

https[:]//[FakeDomainName*].com/.....

We urge you to always be careful and never enter your personal details and/or passwords into forms hosted on fake websites, as these will be sent to a remote server and used by cybercriminals, with all the associated risks easily imaginable.


A little attention and a quick glance can save you a lot of hassle and headaches...

We urge you NOT to be fooled by these types of e-mails, which, even though they use familiar and not particularly sophisticated approach techniques, if there is a resurgence, with reasonable likelihood more than a few unfortunates will be fooled.
 
We invite you to check the following information on phishing techniques for more details:

12/06/2026 09:12 - Phishing: the most common credential and/or data theft attempts in June 2026...
12/05/2026 16:29 - Phishing: the most common credential and/or data theft attempts in May 2026...
02/04/2026 11:01 - Phishing: the most common credential and/or data theft attempts in April 2026.
04/03/2026 10:44 - Phishing: the most common credential and/or data theft attempts in March 2026.
04/02/2026 10:33 - Phishing: the most common credential and/or data theft attempts in February 2026.
08/01/2026 09:53 - Phishing: the most common credential and/or data theft attempts in January 2026.
04/12/2025 15:56 - Phishing: the most common credential and/or data theft attempts in December 2025.
04/11/2025 14:45 Phishing: the most common credential and/or data theft attempts in Novembre 2025.
01/10/2025 16:40 - Phishing: the most common credential and/or data theft attempts in October 2025.
04/09/2025 09:45Phishing: the most common credential and/or data theft attempts in September 2025.
05/08/2025 08:58Phishing: the most common credential and/or data theft attempts in August 2025.
01/07/2025 16:04 - Phishing: the most common credential and/or data theft attempts in July 2025.

Try Vir.IT eXplorer Lite

If you are not yet using Vir.IT eXplorer PRO, it is advisable to install Vir.IT eXplorer Lite -FREE Edition- to supplement the antivirus in use to increase the security of your computers, PCs and SERVERS.

Vir.IT eXplorer Lite  has the following special features:
  • freely usable in both private and corporate environments with Engine+Signature updates without time limitation;
  • fully interoperable with other AntiVirus software and/or Internet Security products (both free and commercial) already installed on your computer. It doesn't need any uninstallation and it doesn't cause slowdowns, as some features have been appropriately reduced to ensure interoperability with the AntiVirus software already on your PC/Server. This, however, allows cross-checking through the scan;
  • it identifies and, in many cases, even removes most of the viruses/malware actually circulating or, alternatively, allows them to be sent to the C.R.A.M. Anti-Malware Research Center for further analysis to update Vir.It eXplorer PRO;
  • through Intrusion Detection technology, also made available in the Lite version of Vir.IT eXplorer, the software is able to report any new-generation viruses/malware that have set in automatically and send the reported files to TG Soft's C.R.A.M
  • Download Vir.IT eXplorer Lite from the official distribution page of TG Soft's website.
 

 

Acknowledgements

TG Soft's Anti-Malware Research Center would like to thank all users, customers, reseller technicians, and all people who have transmitted/reported material attributable to Phishing activities to our Research Center, that allowed us to make this information as complete as possible.


How to submit suspicious emails for analysis as possible phishing but also virus/malware or Crypto-Malware

You can submit materials to TG Soft's Anti-Malware Research Center safely and free of charge in two ways:
  1. any suspect email can be sent directly by the recipient's e-mail, to the following mail lite@virit.com,choosing as sending mode "Forward as Attachment" and inserting in the subject section "Possible phishing page to verify" rather than "Possible Malware to verify";
  2. save the e-mail to be sent to TG Soft's C.R.A.M. for analysis as an external file to the e-mail program used. The resulting file must be sent by uploading it from the page Send Suspicious Files (http://www.tgsoft.it/italy/file_sospetti.asp). Obviously if you want a feedback on the analysis of the data submitted, you have to indicate an e-mail address and a brief description of the reason for the submission (for example: possiible / probable phishing; possible / probable malware or other).
For more details on how to safely forward suspicious e-mails, we invite you to consult the following public page: How to send suspicious emails for analysis
We provide all this information to help you prevent credential theft, viruses/malware or, even worse, next-generation Ransomware / Crypto-Malware.



TG Soft
Anti-Malware Research Centre (C.R.A.M.)

Any information published on our site may be used and published on other websites, blogs, forums, facebook and/or in any other form both in paper and electronic form as long as the source is always and in any case cited explicitly “Source: CRAM by TG Soft www.tgsoft.it” with a clickable link to the original information and / or web page from which textual content, ideas and / or images have been extrapolated.
It will be appreciated in case of use of the information of C.R.A.M. by TG Soft www.tgsoft.it in the report of summary articles the following acknowledgment/thanks “Thanks to Anti-Malware Research Center C.R.A.M. by TG Soft of which we point out the direct link to the original information: [direct clickable link]”

Vir.IT eXplorer PRO is certified by the biggest international organisation: