Phishing Attacks in September 2026: Monthly Report

Phishing Attacks in September 2026: Monthly Report

Quick Summary

Breachsense collected 26,068 credentials stolen by phishing kits in September 2026, from 14,335 email addresses across 5,096 domains. For 98.8% of the phished addresses outside the major webmail providers, the stolen password wasn’t in any breach record or combo list we hold. Credential monitoring that doesn’t cover phishing kits would have missed them.

Why breach monitoring misses phished passwords

A tool that monitors only breach dumps and combo lists would have missed 98.8% of September’s phished passwords. Of the 6,887 phished addresses outside the major webmail providers, 1,295 were already in breach records we hold. Only 82 of the 6,887 had the phished password anywhere in our breach records or combo lists.

Our numbers are based on the phishing kit infrastructure we can access, so they don’t cover every kit in operation.

Why listen to us?

Breachsense is a dark web monitoring API that collects credentials stolen by phishing kits, along with stealer logs and breach data. We’ve indexed over 41 billion leaked credentials. Our founder, Josh Amishav, spent nearly 20 years as a penetration tester. He got into client networks with leaked credentials, then built a tool to find those credentials first. Kaspersky’s ICS CERT cites our breach records in its quarterly industrial cybersecurity reports. See who else cites our data.

What is a phishing kit’s lifespan?

A phishing kit’s lifespan, as we measure it, is the time between the first and last credential the kit stole. We only see credentials arriving, so we can’t tell when the page itself went up or came down. Research presented at the 2025 ACM Web Conference measured the page instead, and found a median of 5.46 hours from when a site is detected to when it goes offline.

September 2026 phishing numbers at a glance

  • 26,068 stolen credentials from 14,335 email addresses across 5,096 domains
  • 488 kit hosts, meaning separate hostnames serving a phishing kit
  • 832 credentials a day at the median, ranging from 129 to 2,014
  • Microsoft was the most impersonated brand, at 84% of branded credentials

Laravel Cloud and Replit hosted the phishing kits behind a third of stolen credentials

HostingCredentialsShareKit hosts
Subdomain on an app hosting platform14,95057.4%326
Link on a cloud storage or CDN domain5,59021.4%37
Standalone domain5,51521.2%123
Bare IP address13<0.1%2

Laravel Cloud alone accounted for 5,505 credentials (21.1%) across 68 subdomains. Replit accounted for 3,578 credentials (13.7%) across 50 subdomains.

Each kit runs on a subdomain of laravel.cloud or replit.app, the same domains legitimate apps use, so domain reputation checks pass it.

Storage links are harder to block than Laravel Cloud or Replit subdomains. When a kit is hosted as a file in a storage bucket, the link points at a domain like storage.googleapis.com or Backblaze’s backblazeb2.com. You can block replit.app if nobody at your company uses Replit. Blocking storage.googleapis.com would break legitimate downloads.

Phishing kits steal in waves, with long gaps between them

365 kits stole at least five credentials each in September. The median time between a kit’s first and last credential was 89 hours, close to four days.

But for half of those kits, credentials arrived in nine or fewer separate clock hours. Half of the 365 kits went 33 hours or more without a new credential at some point. 286 of the 365 kits went more than 12 hours without a victim and then started stealing again. Only 78 kits stole all their credentials within a single day.

One phishing kit took credentials from 17 staff at Belarus’s foreign ministry

Six phishing kits took credentials from 30 staff at Belarus’s Ministry of Foreign Affairs between September 19 and 28, and one of those kits took 17. At Jamaica’s Ministry of Finance, a single kit took credentials from 15 staff. We found 17 organizations where one kit took credentials from ten or more staff.

Microsoft was the most impersonated brand

Microsoft accounted for 84% of the credentials where the kit recorded which brand it was impersonating. Kits recorded a brand for 8,862 credentials, 34% of everything we collected.

BrandShare of branded credentials
Microsoft78.1%
DocuSign5.8%
Outlook5.1%
Adobe3.8%
Google2.0%
DHL1.5%
Gmail1.4%

Counting Outlook (5.1%) and Office 365 (0.6%) with Microsoft gives 84%.

88.7% of the Microsoft credentials were for personal Hotmail, Outlook.com, Live and MSN accounts, not Microsoft 365.

What security teams should do

Add phishing kits to what your credential monitoring covers. Monitoring that only covers breach dumps and combo lists would have missed 98.8% of September’s phished passwords outside the major webmail providers.

Keep searching your mail logs for a reported link for at least four days. Among the 365 kits that stole five or more credentials, the median time from first to last credential was 89 hours.

How we collected this data

We date every credential by when it was stolen. When we gain access to a new kit, we also get the credentials it stole earlier. We leave out any credential that reached us more than 48 hours after it was stolen, so newly accessed kits don’t add older credentials to the month.

We drop entries that aren’t real victim data. Security scanners submit made-up addresses to phishing pages, and some operators send fake entries to test their kits.

We don’t compare monthly totals, because the phishing kit infrastructure we can access changes from month to month.

We count kits by the hostname they ran on. A shared storage hostname such as storage.googleapis.com counts once, even when it serves several kits.

Find out if your staff were phished

Dark web monitoring alerts you by webhook or email when we find one of your employees’ passwords in a phishing kit.

Breachsense is a dark web monitoring API for security teams and MSSPs. It finds credentials and session tokens that have already been stolen from your staff or customers, whether by infostealer malware or a phishing page. It delivers them by webhook so teams can reset the affected accounts before attackers use them. It also indexes the files ransomware groups leak, so you can search them for your own company’s data.

To see what has already leaked for your domain, run a free dark web scan, then book a demo to set up alerts.

Our September 2026 infostealer report covers the stealer logs we indexed that month. The September 2026 ransomware report counts the companies named on leak sites. For the previous month’s phishing numbers, see the August 2026 phishing report.

September 2026 Phishing FAQ

Breachsense collected 26,068 credentials from phishing kits on 488 hosts in September 2026, covering 14,335 email addresses across 5,096 domains. The count covers only the phishing kit infrastructure we can access, so the real total across all phishing is higher.
Mostly on other people’s platforms. In September 2026, 57% of the credentials we saw came from kits on app hosting subdomains, led by Laravel Cloud and Replit. Another 21% came from links on cloud storage and CDN domains such as storage.googleapis.com. 21% came from kits on standalone domains, and almost none from a bare IP address.
Among the 365 kits that stole at least five credentials in September 2026, the median time from first to last credential was 89 hours. For half of those kits, credentials arrived in nine or fewer separate clock hours. Half of those 365 kits went 33 hours or more without a new credential, then started stealing again.
Microsoft, by a wide margin. Of the September 2026 credentials where the kit recorded which brand it was impersonating, Microsoft, Outlook and Office 365 together made up 84%. DocuSign was next at 5.8%, then Adobe at 3.8%.
Rarely, in the phishing kit data we collected. Of the 26,068 credentials those kits stole in September 2026, only 45 came with a one-time passcode and 47 with a payment card number.
Monitor phishing-harvested credentials and infostealer malware logs for your company domains. Breachsense dark web monitoring sends a webhook or email alert when an employee’s password turns up in either source, and covers third-party breaches too.