PHISHING INDEX
Below are the most common email phishing attempts detected by the TG Soft Anti-Malware Research Center in
JULY 2026:
30/07/2026 =>
Aruba - Unknown Device
29/07/2026 =>
Banca MEDIOLANUM
18/07/2026 =>
Credit Agricole
17/07/2026 =>
Aruba - Service suspension
16/07/2026 =>
Webmail
15/07/2026 =>
Bank
13/07/2026 =>
Emai Account
08/07/2026 =>
OpenAI
08/07/2026 =>
Emai Account
02/07/2026 =>
Microsoft
These emails aim to deceive unsuspecting victims into providing sensitive information, such as bank account details, credit card codes, or personal login credentials, with all the easily imaginable consequences.
30 July 2026 ==> Phishing Aruba - Unknown device
SUBJECT: <
An unknown device has accessed your email.>
Here is yet another phishing attempt posing as a message from the
Aruba brand.
The message informs the recipient that a login attempt from a new device has been detected on their email account hosted by
Aruba. It therefore asks them to check whether the login was authorised via the following link:
ACCESS VERIFICATION
Let's always exercise caution when asked to enter personal credentials via suspicious links sent by email.
The well-known web hosting, email and domain registration company,
Aruba, is clearly not involved in the mass sending of these emails, which are outright scams whose aim, as always, is to steal sensitive data from unsuspecting recipients.
We can see straight away that the email address in the message appears to be that of the unsuspecting user. This technique, which conceals the true sender, is often used in these scams.
Anyone who unfortunately clicks on the link will be redirected to a web page unrelated to the
Aruba website, with an unusual address/domain:
https[:]//[FakeDomainName/amazonaws[.]com/Arubs[.]html#***]
On this page, users are asked to log in to their customer area by entering their email password in order to check their login history and report any unusual activity.
We always urge you to pay attention to every detail, however trivial, not to rush, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to the cybercriminals behind the scam, who will use them for criminal purposes.
29 July 2026 ==> Phishing Banca Mediolanum
SUBJECT: <
Regular updating of the customer database >
Below, we examine the following phishing attempt, which comes as a fake message from
Banca MEDIOLANUM, the well-known bank.
The message reads: “
In accordance with the regulatory provisions on anti-money laundering and financial transparency (Legislative Decree 231/2007, as amended), Banca Mediolanum S.p.A. is required to keep its customers’ personal, identification and contact details up to date at all times.
The purpose of this communication is to invite you to check that the information currently held by us is correct and, where necessary, to update it via the dedicated digital platform.”
The user is then asked to update or confirm their details via the following link:
ACCESS THE UPDATE FORM
If we examine the message, we immediately notice that it contains an email address <
noreply[at]mediolanum[dot]com> which, although misleading, does not originate from the official
Banca MEDIOLANUM domain. We should always exercise the utmost caution before clicking on suspicious links.
The aim is to trick the victim into logging in to their online banking account.
Anyone who unfortunately clicks on the
ACCESS THE UPDATE FORM
link will be redirected to a fraudulent web page, which is completely unrelated to the official
Banca MEDIOLANUM website.
From the image shown on the side, we can see that the web page is well designed and mimics the official banking portal quite effectively.
Based on these points, we urge you to pay close attention to any misleading details, bearing in mind that before entering sensitive data – in this case, your online banking credentials – make sure to check the URL where the login form is hosted.
In this case, the landing page is hosted at a URL that is completely unrelated to the official website of the well-known bank.
hrrps://[FakeDomainName*]/web/login[.]php.
This MISLEADING WEBSITE is run by cybercriminals whose aim is to gain access to your most valuable data in order to use it for illegal purposes.
18 July 2026 ==> Phishing Crédit Agricole
SUBJECT: <
Restriction message 18/07/2026 00:47:11 >
Below, we examine the following phishing attempt, contained in a fake message purporting to be from
Crédit Agricole, the well-known French bank.
The message reads: "
Your CreditAgricole account password will expire in 48 hours. To ensure uninterrupted access to your account and maintain the highest level of security, we ask you to update your password before the expiry date." It then invites the user to update their password via the following link:
Change password
On closer inspection of the message, we immediately notice that it contains an email address <
myagricole[at]lcn613[dot]com>, which clearly does not belong to the official
Crédit Agricole domain. We should always exercise the utmost caution before clicking on suspicious links.
The aim is to trick the victim into logging in to their online banking account.
Anyone who, unfortunately, clicks on the
Change password
link, will be redirected to a fake web page, which is designed to look like the official
Crédit Agricole website.
From the image shown here, we can see that the web page is well designed and bears a close resemblance to the official banking portal.
Based on these considerations, we urge you to pay close attention to any misleading details and to remember that before entering sensitive information—in this case, your online banking credentials—it is crucial to check the URL where the authentication form is hosted.
In this case, the landing page is hosted at a URL unrelated to the official website of the well-known bank.
hrrps://agricolesrecured[FakeDomainName*]...
This scam site is run by cybercriminals whose goal is to steal your most valuable data in order to use it for criminal purposes.
17 July 2026 ==> Phishing Aruba - Service suspension
SUBJECT: <
Important: Outstanding payment for your Aruba account>
Phishing attempts posing as communications from the
Aruba brand continue.
The message informs the recipeint that
Aruba’s billing system has detected that the hosting service associate with their domain has expired
.Iy then says: "To date, the service has not been renewed despite previous reminders being sent.
Therefore, your domain has been temporarily suspended, resulting in the interruption of all associated services” To avoid the service suspension and to ensure that the domain and all associated services remain active, it is necessary to make the payment promptly and in any case within
3 days; otherwise, the hosting service will be permanently cancelled.
The user is therefore asked to make the payment via the following link:
Renew now
The well-known web hosting, email and domain registration company,
Aruba, is clearly not involved in the mass sending of these emails, which are outright scams whose aim, as always, is to steal sensitive data from unsuspecting recipients.
When we examine the text of the message, we immediately notice that the sender’s email address <
noreply[at]i-d-leistung[dot]de> does not originate from the official
Aruba domain.
The user is given three days to renew their email account. The aim is to encourage the user, fearing that their email account might be deactivated, to act immediately without giving it too much thought.
Anyone who, unfortunately, clicks on the
Renew now link, will be redirected to the page shown.
As we can see, first of all, contrary to expectations, the landing page does not link to the login form for
Aruba’s RESTRICTED AREA but hosts an online payment form that appears to be powered by the
BancaSella payment gateway. Here, you are asked directly to enter your credit card details to complete the payment of the modest sum of €5.99.
Although the rush and the fear of having their email account suspended may prompt users to complete the transaction quickly, a quick glance at the URL displayed in the browser bar is enough to realise that the payment form is not hosted on the official
Aruba domain, nor on
BancaSella’s.
We therefore urge you not to rush and to remember that, when faced with these attempts at cyber fraud, you must pay close attention to every detail, however trivial it may seem.
If you enter the requested details – specifically your credit card details – these will be sent to the cybercriminals behind the scam, who will use them for illegal purposes.
16 July 2026 ==> Phishing Webmail
SUBJECT: <
**** New Notification: 5 Undelivered Message Reports>
Below, we examine another phishing attempt, very similar to the previous one, which aims to steal the victim’s email account credentials.
The message, in English, informs the recipient that there are 5 messages waiting and that they can check their pending messages via the following link:
Review Messages
On closer inspection of the message, we can see that it originates from the recipient’s email domain. This is highly unusual and should certainly raise our suspicions.
Anyone who unfortunately clicks on the link provided will be redirected to a fraudulent web page that mimics the email account login page.
On this page, users are asked to log in to their account by entering, specifically, the password for their email account in order to view any pending messages
Actually, the page to which the user is redirected to enter their email account credentials is hosted on a suspicious address/domain, which is listed below:
https[:]//[FakeDomainName*]
We urge you always to pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to a remote server and used by cybercriminals, with all the associated and easily imaginable risks.
15 July 2026 ==> Phishing Bank
SUBJECT: <
Official Communication: Mandatory Online Banking Verification >
The message, using graphics stolen from or similar to those of a well-known bank, attempts to pass itself off as an official communication in order to induce the recipient to comply with the request and fall into this trap based on social engineering technique.
The message warns the unsuspecting recipient: “
Your current account has been suspended due to failure to comply with the online banking profile verification requirements, in accordance with the banking regulations currently in force.
You are required to complete the verification process within 24 hours of receiving this notification. In the event of further non-compliance, your account will be permanently and irrevocably closed, without further notice and with no possibility of reactivation.” The user is then asked to complete the procedure via the following link:
PROCEED WITH THE VERIFICATION
We can see straight away that the alert message comes from a highly suspicious email address, <
service3(at)lamiagioia(dot)it>, and contains very generic text, despite the inclusion of the bank’s logo in an attempt to mislead the user. The aim is to trick the victim into logging into their banking app so that their details can be stolen.
Anyone who, unfortunately, clicks on the
PROCEED WITH THE VERIFICATION
link, will be redirected to a suspicious web page, which has already been flagged as a SCAM PAGE/SITE. Actually it is run by cybercriminals whose aim is to gain access to your most valuable data so that they can use it for their own purposes.
To conclude, we would urge you to always be wary of any email asking you to enter confidential information, and to avoid clicking on suspicious links, which could lead you to a fake website that is difficult to distinguish from the genuine one.
13 July 2026 ==> Phishing Email Account
SUBJECT: <
Action Required*** Pending Message Report On 7/13/2026>
Below, we analyse another phishing attempt aimed at stealing the victim’s email account credentials.
The message, in English, informs the recipient that they have 9 pending messages and that they can free up space in their email inbox by following the procedure set out via the link in the email:
Review Messages
On closer inspection, we can see that the message comes from an email address – <
info(at)telpro(dot)co(dot)it> – which is rather unusual and has no connection to the recipient’s email domain. This is decidedly unusual and should certainly raise our suspicions.
Anyone who unfortunately clicks on the link provided will be redirected to a fraudulent web page that mimics the email account login page.
On this page, users are asked to log in to their account by entering, specifically, their email password in order to download any pending messages and free up space.
Actually, the page where the user is redirected to enter their email account credentials is hosted on a suspicious address/domain, which is listed below:
https[:]//[FakeDomainName*]
We urge you always to pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to a remote server and used by cybercriminals, with all the associated and easily imaginable risks.
08 July 2026 ==> Phishing OpenAI
SUBJECT: <
Your OpenAI payment has expired>
Below, we analyse the phishing attempt aimed at stealing the victim’s credit card details.
The message informs the recipient that they need to update their registered credit card to regain access to their OpenAI subscription. The last payment attempt appears to have failed. To proceed, they must click on the link:
Aggiorna carta
On closer inspection, we can see that the message contains a suspect email address: <
natour21(dot)otp(at)gmail[dot]com>. This should raise suspicions.
Anyone who unfortunately clicks on the link provided will be redirected to a fraudulent web page, which is designed to look like the
OpenAI website.
On this page, users are asked to enter their credit card details to proceed with the payment for their subscription… or so it would seem.
Actually, the page is hosted on an unusual address/domain:
https[:]//[FakeDomainName*]
We would like to remind you to always pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake websites, as these will be sent to a remote server and used by cybercriminals, with all the associated risks easily imaginable.
08 July 2026 ==> Phishing Email Account
SUBJECT: <
Statement_REF_2026_045A Detailed_account_summary_for_July_2026>
Below, we analyse the phishing attempt, which aims to steal the victim’s email account credentials.
The message informs the recipient that a document has been prepared and is ready for signing. It does not contain any other information that would help us identify the type of file referred to in the email or its possible origin. Perhaps this is a summary document for an account (?) relating to the month of July, as indicated in the subject line, but only a very general part of the shared file name is shown: ‘
DOC_001830787....". To continue, the user is asked to download or open the document via the following link:
DOWNLOAD FILE
Looking at the message, we can see that it has an email address <
sales(at)*******[dot]co[dot]za> from a suspicious domain. This alone should raise suspicions.
Anyone who unfortunately clicks on the links provided will be redirected to a fraudulent web page that mimics the email account login page.
On this page, the user is asked to log in to their account by entering, specifically, the password for their email account, and then download the document they have received.
Actually, the page where the user is redirected to enter their email account credentials is hosted on a suspicious address/domain, which is listed below:
https[:]//[FakeDomainName*]
We urge you to always pay attention to every detail, however trivial, and not to enter your personal details and/or passwords into forms hosted on fake web pages, as these will be sent to a remote server and used by cybercriminals, with all the associated and easily imaginable risks.
02 July 2026 ==> Phishing Microsoft
SUBJECT: <
***** S.r.l.".>
Below, we analyse the phishing attempt aimed at stealing
Microsoft account credentials.
The message, seemingly from a certain Maurizio at the company **** S.r.l., seems to share a tax document with the recipient. The file named ‘*****SRL-Invoice 2030072026’ seems to be an invoice that the recipient may need to download and pay. The user is therefore invited to download the document for reference and to carry out the necessary checks by clicking on the following link:
*****SRL-Invoice 2030072026
Looking at the email, we can see that the cybercriminal has taken care to use – probably via a label – an email address that appears to belong to the supplier or customer who sent the file. These measures are designed to make the message seem more credible, thereby leading the recipient – who sees the email coming directly from one of their own suppliers or customers – to trust it and click on the link.
We also notice that the official contact details (website, registered office and business address, telephone number, etc.) of the company that is supposed to have issued and sent the invoice are listed at the bottom.
Anyone who unfortunately clicks on the link
*****SRL-Invoice 2030072026
will be redirected to a suspicious web page – which is visually well-designed – where they are asked to log in to their
Microsoft account in order to download the file mentioned in the message.
However, the page to which the user is redirected is hosted on a suspicious address/domain:
https[:]//[FakeDomainName*].com/.....
We urge you to always be careful and never enter your personal details and/or passwords into forms hosted on fake websites, as these will be sent to a remote server and used by cybercriminals, with all the associated risks easily imaginable.
A little attention and a quick glance can save you a lot of hassle and headaches...
We urge you NOT to be fooled by these types of e-mails, which, even though they use familiar and not particularly sophisticated approach techniques, if there is a resurgence, with reasonable likelihood more than a few unfortunates will be fooled.
We invite you to check the following information on phishing techniques for more details:
12/06/2026 09:12 - Phishing: the most common credential and/or data theft attempts in June 2026...
12/05/2026 16:29 - Phishing: the most common credential and/or data theft attempts in May 2026...
02/04/2026 11:01 - Phishing: the most common credential and/or data theft attempts in April 2026.
04/03/2026 10:44 - Phishing: the most common credential and/or data theft attempts in March 2026.
04/02/2026 10:33 - Phishing: the most common credential and/or data theft attempts in February 2026.
08/01/2026 09:53 - Phishing: the most common credential and/or data theft attempts in January 2026.
04/12/2025 15:56
- Phishing: the most common credential and/or data theft attempts in December 2025.
04/11/2025 14:45
- Phishing: the most common credential and/or data theft attempts in Novembre 2025.
01/10/2025 16:40 - Phishing: the most common credential and/or data theft attempts in October 2025.
04/09/2025 09:45 - Phishing: the most common credential and/or data theft attempts in September 2025.
05/08/2025 08:58- Phishing: the most common credential and/or data theft attempts in August 2025.
01/07/2025 16:04 - Phishing: the most common credential and/or data theft attempts in July 2025.
Try Vir.IT eXplorer Lite
If you are not yet using Vir.IT eXplorer PRO, it is advisable to install Vir.IT eXplorer Lite -FREE Edition- to supplement the antivirus in use to increase the security of your computers, PCs and SERVERS.
Vir.IT eXplorer Lite has the following special features:
- freely usable in both private and corporate environments with Engine+Signature updates without time limitation;
- fully interoperable with other AntiVirus software and/or Internet Security products (both free and commercial) already installed on your computer. It doesn't need any uninstallation and it doesn't cause slowdowns, as some features have been appropriately reduced to ensure interoperability with the AntiVirus software already on your PC/Server. This, however, allows cross-checking through the scan;
- it identifies and, in many cases, even removes most of the viruses/malware actually circulating or, alternatively, allows them to be sent to the C.R.A.M. Anti-Malware Research Center for further analysis to update Vir.It eXplorer PRO;
- through Intrusion Detection technology, also made available in the Lite version of Vir.IT eXplorer, the software is able to report any new-generation viruses/malware that have set in automatically and send the reported files to TG Soft's C.R.A.M
- Download Vir.IT eXplorer Lite from the official distribution page of TG Soft's website.
Acknowledgements
TG Soft's Anti-Malware Research Center would like to thank all users, customers, reseller technicians, and all people who have transmitted/reported material attributable to Phishing activities to our Research Center, that allowed us to make this information as complete as possible.
How to submit suspicious emails for analysis as possible phishing but also virus/malware or Crypto-Malware
You can submit materials to TG Soft's Anti-Malware Research Center safely and free of charge in two ways:
- any suspect email can be sent directly by the recipient's e-mail, to the following mail lite@virit.com,choosing as sending mode "Forward as Attachment" and inserting in the subject section "Possible phishing page to verify" rather than "Possible Malware to verify";
- save the e-mail to be sent to TG Soft's C.R.A.M. for analysis as an external file to the e-mail program used. The resulting file must be sent by uploading it from the page Send Suspicious Files (http://www.tgsoft.it/italy/file_sospetti.asp). Obviously if you want a feedback on the analysis of the data submitted, you have to indicate an e-mail address and a brief description of the reason for the submission (for example: possiible / probable phishing; possible / probable malware or other).

For more details on how to safely forward suspicious e-mails, we invite you to consult the following public page:
How to send suspicious emails for analysis
We provide all this information to help you prevent credential theft, viruses/malware or, even worse, next-generation Ransomware / Crypto-Malware.
TG Soft Anti-Malware Research Centre (C.R.A.M.)