Phishing Attacks in September 2026: Monthly Report
Quick Summary
Breachsense collected 26,068 credentials stolen by phishing kits in September 2026, from 14,335 email addresses across 5,096 domains. For 98.8% of the phished addresses outside the major webmail providers, the stolen password wasn’t in any breach record or combo list we hold. Credential monitoring that doesn’t cover phishing kits would have missed them.
Why breach monitoring misses phished passwords
A tool that monitors only breach dumps and combo lists would have missed 98.8% of September’s phished passwords. Of the 6,887 phished addresses outside the major webmail providers, 1,295 were already in breach records we hold. Only 82 of the 6,887 had the phished password anywhere in our breach records or combo lists.
Our numbers are based on the phishing kit infrastructure we can access, so they don’t cover every kit in operation.
Why listen to us?
Breachsense is a dark web monitoring API that collects credentials stolen by phishing kits, along with stealer logs and breach data. We’ve indexed over 41 billion leaked credentials. Our founder, Josh Amishav, spent nearly 20 years as a penetration tester. He got into client networks with leaked credentials, then built a tool to find those credentials first. Kaspersky’s ICS CERT cites our breach records in its quarterly industrial cybersecurity reports. See who else cites our data.
What is a phishing kit’s lifespan?
A phishing kit’s lifespan, as we measure it, is the time between the first and last credential the kit stole. We only see credentials arriving, so we can’t tell when the page itself went up or came down. Research presented at the 2025 ACM Web Conference measured the page instead, and found a median of 5.46 hours from when a site is detected to when it goes offline.
September 2026 phishing numbers at a glance
- 26,068 stolen credentials from 14,335 email addresses across 5,096 domains
- 488 kit hosts, meaning separate hostnames serving a phishing kit
- 832 credentials a day at the median, ranging from 129 to 2,014
- Microsoft was the most impersonated brand, at 84% of branded credentials
Laravel Cloud and Replit hosted the phishing kits behind a third of stolen credentials
| Hosting | Credentials | Share | Kit hosts |
|---|---|---|---|
| Subdomain on an app hosting platform | 14,950 | 57.4% | 326 |
| Link on a cloud storage or CDN domain | 5,590 | 21.4% | 37 |
| Standalone domain | 5,515 | 21.2% | 123 |
| Bare IP address | 13 | <0.1% | 2 |
Laravel Cloud alone accounted for 5,505 credentials (21.1%) across 68 subdomains. Replit accounted for 3,578 credentials (13.7%) across 50 subdomains.
Each kit runs on a subdomain of laravel.cloud or replit.app, the same domains legitimate apps use, so domain reputation checks pass it.
Storage links are harder to block than Laravel Cloud or Replit subdomains. When a kit is hosted as a file in a storage bucket, the link points at a domain like storage.googleapis.com or Backblaze’s backblazeb2.com. You can block replit.app if nobody at your company uses Replit. Blocking storage.googleapis.com would break legitimate downloads.
Phishing kits steal in waves, with long gaps between them
365 kits stole at least five credentials each in September. The median time between a kit’s first and last credential was 89 hours, close to four days.
But for half of those kits, credentials arrived in nine or fewer separate clock hours. Half of the 365 kits went 33 hours or more without a new credential at some point. 286 of the 365 kits went more than 12 hours without a victim and then started stealing again. Only 78 kits stole all their credentials within a single day.
One phishing kit took credentials from 17 staff at Belarus’s foreign ministry
Six phishing kits took credentials from 30 staff at Belarus’s Ministry of Foreign Affairs between September 19 and 28, and one of those kits took 17. At Jamaica’s Ministry of Finance, a single kit took credentials from 15 staff. We found 17 organizations where one kit took credentials from ten or more staff.
Microsoft was the most impersonated brand
Microsoft accounted for 84% of the credentials where the kit recorded which brand it was impersonating. Kits recorded a brand for 8,862 credentials, 34% of everything we collected.
| Brand | Share of branded credentials |
|---|---|
| Microsoft | 78.1% |
| DocuSign | 5.8% |
| Outlook | 5.1% |
| Adobe | 3.8% |
| 2.0% | |
| DHL | 1.5% |
| Gmail | 1.4% |
Counting Outlook (5.1%) and Office 365 (0.6%) with Microsoft gives 84%.
88.7% of the Microsoft credentials were for personal Hotmail, Outlook.com, Live and MSN accounts, not Microsoft 365.
What security teams should do
Add phishing kits to what your credential monitoring covers. Monitoring that only covers breach dumps and combo lists would have missed 98.8% of September’s phished passwords outside the major webmail providers.
Keep searching your mail logs for a reported link for at least four days. Among the 365 kits that stole five or more credentials, the median time from first to last credential was 89 hours.
How we collected this data
We date every credential by when it was stolen. When we gain access to a new kit, we also get the credentials it stole earlier. We leave out any credential that reached us more than 48 hours after it was stolen, so newly accessed kits don’t add older credentials to the month.
We drop entries that aren’t real victim data. Security scanners submit made-up addresses to phishing pages, and some operators send fake entries to test their kits.
We don’t compare monthly totals, because the phishing kit infrastructure we can access changes from month to month.
We count kits by the hostname they ran on. A shared storage hostname such as storage.googleapis.com counts once, even when it serves several kits.
Find out if your staff were phished
Dark web monitoring alerts you by webhook or email when we find one of your employees’ passwords in a phishing kit.
Breachsense is a dark web monitoring API for security teams and MSSPs. It finds credentials and session tokens that have already been stolen from your staff or customers, whether by infostealer malware or a phishing page. It delivers them by webhook so teams can reset the affected accounts before attackers use them. It also indexes the files ransomware groups leak, so you can search them for your own company’s data.
To see what has already leaked for your domain, run a free dark web scan, then book a demo to set up alerts.
Our September 2026 infostealer report covers the stealer logs we indexed that month. The September 2026 ransomware report counts the companies named on leak sites. For the previous month’s phishing numbers, see the August 2026 phishing report.
