Phishing Attacks in August 2026: Monthly Report
What August’s phishing kits stole, and how little time they needed to do it.
• 231 phishing kits we monitor captured 10,926 credentials in August 2026, from 6,300 email addresses across 2,331 domains. We see each credential where the kit delivers it, at the same time the operator does.
• No single campaign dominated August. On a typical day we saw about 400 stolen credentials. The busiest day brought 928 and the quietest 111.
• Kits don’t last. Of the 173 phishing kits that stole at least five credentials each, 50 shut down within 24 hours.
• Where the kit recorded which brand it was impersonating, 89% were Microsoft logins. Nothing else came close.
By the time a phishing page gets reported, the kit behind it has usually gone quiet. Blocking it achieves little. Resetting the accounts whose credentials it already collected is the part that still helps.
Every phishing kit has to deliver what it steals somewhere. We monitor some of those destinations, so we see the credentials arrive at the same time the operator does. Plenty of phishing kits deliver somewhere we can’t see, for example straight to a private inbox or a log file on their own server. This report doesn’t cover those.
This is the first month of the series, so there’s no month-over-month comparison yet. The methodology note at the end sets out what we counted and what we left out.
Here’s what the August 2026 numbers show.
August 2026 phishing numbers at a glance
August is the first month we indexed phishing kit data, so these numbers are the baseline the rest of the series gets measured against.
A phishing kit is the packaged fake login page an attacker deploys on a web host. When a victim types their password, the kit sends it straight to whoever’s running it. Kits get bought and resold. The same kit code ends up deployed many times over, each copy run by a different attacker.
- 10,926 stolen credentials captured in August
- 6,300 unique email addresses across 2,331 domains
- 231 separate kit hosts running 234 campaigns
- 400 credentials on a typical day, ranging from 111 to 928
- 56 hours is how long the typical kit lasted
- 46% of credentials came from kits on free hosting, 44% from a registered domain
These numbers cover the phishing kits we can see, not every kit in operation.
No single campaign dominated August
The daily count stayed in a narrow band all month. No single kit or campaign produced a burst big enough to carry the total by itself.
There’s no one large operation here to disrupt. It’s 231 separate kits, most of them small, most of them gone within days of showing up.
Most phishing kits go quiet within two days
173 kits collected at least five credentials each. For half of them, the first and last credential collected were 56 hours apart. 50 went quiet inside a day.
That span isn’t 56 hours of steady collecting. The typical kit was active for about six hours in total, split across three separate bursts with long quiet gaps between them. That could be a mailing campaign landing in waves, or the page being taken down and put back up at the same address. Our data can’t tell the two apart.
Other researchers have measured phishing page lifespans a completely different way. Research presented at the 2025 ACM Web Conference followed 286,237 phishing pages. They found the median page stayed online for 5.46 hours before it was taken down.
They measured how long the page survived. We measured how long it was collecting credentials. Both come out at roughly six hours.
Either way, a takedown filed on day three arrives after the credentials are already gone. When Troy Hunt was phished in March 2025, the attacker exported his 16,000-subscriber mailing list within minutes of him entering his password. He described it as highly automated, built to take the data before the victim could react.
What’s still useful on day three is knowing which of your employees’ accounts had their credentials stolen.
Where the phishing kits ran
| Hosting | Credentials | Share | Kit hosts |
|---|---|---|---|
| Domain the operator registered | 4,809 | 44.0% | 117 |
| Free deployment subdomains | 5,027 | 46.0% | 107 |
| Bare IP address | 1,090 | 10.0% | 7 |
Free hosting and registered domains were an almost even split. Other reporting names Cloudflare and Vercel as the platforms attackers abuse most. In our data the largest single free platform was edgeone.dev at 18.3%, across 34 subdomains.
Free hosting gives an operator a valid certificate and a trusted-looking domain name in seconds, at no cost. When one subdomain gets taken down, they register another for free.
The kits on a bare IP skip domains altogether, so any filter based on domain reputation never sees them. They were 10% of what we captured.
Microsoft logins are the primary target
In 3,941 cases the kit recorded which brand it was impersonating. That’s 36% of the credentials we collected this month.
| Brand | Share of branded credentials |
|---|---|
| Microsoft | 77.6% |
| Outlook | 11.2% |
| Gmail | 5.2% |
| 1.5% | |
| 1.0% | |
| Apple | 1.0% |
When you add Outlook and Office 365 to Microsoft itself, you get 89% of all impersonations. Google accounted for about 7%, and everything else split the remainder. Banking brands barely appeared.
2,265 companies had at least one employee credential stolen in August, from the kits we monitor alone. 951 of them lost more than one account. Nine lost more than twenty employee credentials.
The rest of the leaked credentials were mostly consumer webmail accounts, many of them Hotmail and Outlook. Those are Microsoft accounts too. So the 89% above covers employees and consumers typing into the same fake login pages.
Where the kit recorded a location, most of the stolen credentials came from the United States, with 1,786. The United Kingdom followed with 586 and Canada with 462.
These phishing kits weren’t collecting MFA codes
Out of the entire dataset for the month, only four credentials included an MFA code. Two included a credit card number.
These kits took a username and a password, and nothing else. So if the account has MFA enabled, that stolen password alone won’t give the attacker access to the account.
Some kits do act as a proxy and relay the MFA prompt in real time. We just didn’t see any of those in August. The bigger gap is infostealer malware, which lifts session tokens straight off an infected machine.
A session token is what your browser holds after you log in, so the site stops asking who you are on every page. Anyone who steals the token inherits that logged-in session. They never see the login page, which is why a second factor doesn’t stop them.
What security teams should do
Assume the credentials are already in use. By the time a takedown happens, the credentials have been leaked for days. Reset the password first, only investigate afterwards.
Don’t rely on domain reputation alone. 10% of what we captured came from kits on a bare IP address, and another 46% from free subdomains that rotate on demand.
Blocking the campaign doesn’t mean nobody fell for it. Your mail gateway may have caught the second wave of the attack. It can’t help the employee who typed their password into the first one.
Dark web monitoring alerts you when your employees’ credentials turn up, whether the source was a phishing kit, a third-party breach, or an infostealer log. You can also read up on how phishing domains impersonate brands to steal credentials.
Methodology
We drop entries that aren’t real victim data. Some kit panels generate test and demo rows. The passwords normally follow a template and the usernames come from a name library. The “victim” domains are lifted from a list of popular websites.
Every figure is dated by when the credential was stolen, not by when the credential was recaptured. Anything that took more than 48 hours to reach us is excluded.
Every credential here was recaptured directly from a threat actor’s phishing kit infrastructure as the attacker received it. This isn’t a count of all phishing attacks. Kits that deliver their payloads to a private inbox, or write to a log file on their own server, never reach us. They outnumber the ones that do.
Breachsense monitors the dark web and criminal forums for your company’s exposed data, from leaked credentials to files stolen in ransomware attacks, and alerts your team by webhook or email.
