Phishing Kit: What It Is and How It Steals Credentials
A phishing kit is a packaged fake login page that an attacker uploads to a web host. When a victim types a username and password into the page, the kit sends them to the attacker. Kits are bought and resold, so the same code runs on many sites, often run by different attackers.
Of the phished credentials Breachsense collected in September 2026 where the kit recorded a brand, 84% came from fake Microsoft pages.
How does a phishing kit work?
- The attacker uploads the kit. A kit is usually a zip file of web pages and scripts. The attacker uploads it to a free hosting platform or a hacked website.
- A phishing email links to it. The victim clicks the link and sees a page that looks like their usual sign-in page.
- The victim types a username and password. Many kits then show an error or forward the victim to the real site, so nothing seems wrong.
- The kit sends the credentials to the attacker.
The victim typed that password into the fake page, so a phished credential is a confirmed compromise, not possible exposure.
Where are phishing kits hosted?
Phishing kits mostly run on platforms the attacker doesn’t own. Free app hosting gives each app its own subdomain, so a kit’s address sits on the same domain as legitimate apps. In September 2026, kits on Laravel Cloud and Replit subdomains alone took over a third of the credentials Breachsense collected.
Storage links are harder to block than app subdomains. You can block replit.app if nobody at your company uses Replit. Blocking storage.googleapis.com would break legitimate downloads.
Phishing kit vs phishing domain
- A phishing domain is a lookalike web address, such as a misspelling of your company name. Lookalike domain detection finds the fake site, sometimes before it’s used.
- A phishing kit is the page running on that address, or on any other host. Monitoring phishing-harvested credentials finds the passwords a kit has already taken.
In September 2026, 79% of the phished credentials Breachsense collected came from kits on app hosting subdomains or cloud storage links, not lookalike domains.
What to do when a phishing kit takes an employee’s password
Reset the password and end the account’s active sessions, because some sessions survive a password reset.
Keep searching your mail logs for the phishing link for at least four days. In September 2026, half of the 365 kits we tracked went 33 hours or more without a new credential before stealing again.
Dark web monitoring alerts you by webhook or email when we find one of your employees’ passwords in a phishing kit. To see what has already leaked for your domain, run a free dark web scan.