Phishing Kit: What It Is and How It Steals Credentials

A phishing kit is a packaged fake login page that an attacker uploads to a web host. When a victim types a username and password into the page, the kit sends them to the attacker. Kits are bought and resold, so the same code runs on many sites, often run by different attackers.

Of the phished credentials Breachsense collected in September 2026 where the kit recorded a brand, 84% came from fake Microsoft pages.

How does a phishing kit work?

  1. The attacker uploads the kit. A kit is usually a zip file of web pages and scripts. The attacker uploads it to a free hosting platform or a hacked website.
  2. A phishing email links to it. The victim clicks the link and sees a page that looks like their usual sign-in page.
  3. The victim types a username and password. Many kits then show an error or forward the victim to the real site, so nothing seems wrong.
  4. The kit sends the credentials to the attacker.

The victim typed that password into the fake page, so a phished credential is a confirmed compromise, not possible exposure.

Where are phishing kits hosted?

Phishing kits mostly run on platforms the attacker doesn’t own. Free app hosting gives each app its own subdomain, so a kit’s address sits on the same domain as legitimate apps. In September 2026, kits on Laravel Cloud and Replit subdomains alone took over a third of the credentials Breachsense collected.

Storage links are harder to block than app subdomains. You can block replit.app if nobody at your company uses Replit. Blocking storage.googleapis.com would break legitimate downloads.

Phishing kit vs phishing domain

  • A phishing domain is a lookalike web address, such as a misspelling of your company name. Lookalike domain detection finds the fake site, sometimes before it’s used.
  • A phishing kit is the page running on that address, or on any other host. Monitoring phishing-harvested credentials finds the passwords a kit has already taken.

In September 2026, 79% of the phished credentials Breachsense collected came from kits on app hosting subdomains or cloud storage links, not lookalike domains.

What to do when a phishing kit takes an employee’s password

Reset the password and end the account’s active sessions, because some sessions survive a password reset.

Keep searching your mail logs for the phishing link for at least four days. In September 2026, half of the 365 kits we tracked went 33 hours or more without a new credential before stealing again.

Dark web monitoring alerts you by webhook or email when we find one of your employees’ passwords in a phishing kit. To see what has already leaked for your domain, run a free dark web scan.

Phishing Kit FAQ

A phishing kit is a packaged fake login page that an attacker uploads to a web host. When a victim types a username and password into the page, the kit sends them to the attacker. Kits are bought and resold, so one kit’s code can run on many sites.
Phishing kits mostly run on platforms the attacker doesn’t own. In September 2026, 57% of the phished credentials Breachsense collected came from kits on app hosting subdomains such as Laravel Cloud and Replit. Another 21% came from links on cloud storage and CDN domains, and 21% from standalone domains.
Some phishing kits can. Adversary-in-the-middle kits pass the victim’s sign-in to the real site as it happens and keep the session cookie the site sends back. That cookie lets the attacker into the account without the one-time code. Simpler kits collect only the username and password.
A phishing kit often keeps taking credentials for days, in bursts. Among 365 kits that stole at least five credentials in September 2026, the median time from first to last credential was 89 hours. Half of those kits went 33 hours or more without a new credential before stealing again.
Monitor phishing-harvested credentials for your company domains. Dark web monitoring that collects credentials from phishing kits sends an alert when an employee’s password turns up, so your team can reset that account. A lookalike domain check finds the fake site, but the check can’t show who typed a password into the site.