---
title: "Dismantling a 40-domain phishing cluster targeting a retail bank"
description: "A coordinated phishing kit spun up lookalike domains faster than the bank's SOC could report them. Fraudox took the entire cluster offline and cut reappearance to near zero."
date: "2026-03-18"
industry: "Banking & Finance"
category: "Phishing"
region: "Southeast Asia"
client: "Tier-1 retail bank (anonymised)"
canonical: "https://fraudox.com/case-studies/banking-phishing-cluster-takedown"
publisher: "Fraudox"
publisher_url: "https://fraudox.com"
license: "Free to quote with attribution to the canonical URL."
---

# Dismantling a 40-domain phishing cluster targeting a retail bank

> A coordinated phishing kit spun up lookalike domains faster than the bank's SOC could report them. Fraudox took the entire cluster offline and cut reappearance to near zero.

**Sector:** Banking & Finance | **Threat:** Phishing | **Region:** Southeast Asia | **Client:** Tier-1 retail bank (anonymised)

## Outcome at a glance

| Measure | Result |
| --- | --- |
| Domains removed | 41 |
| Median time to removal | 31h |
| Stayed down after 30 days | 96% |

## The challenge

The bank's fraud team was discovering new phishing domains daily: typosquats and homoglyph variants of its login portal, each harvesting credentials and OTPs. Their existing abuse-report process averaged five to seven days per domain, by which point attackers had already rotated to the next domain in the kit. The volume was outpacing the team, and customers were filing complaints faster than takedowns closed.

## How it was handled

### 1. Cluster the kit, not the symptoms

Rather than treating each domain as an isolated report, we fingerprinted the shared phishing kit (common favicon hash, TLS issuer, and hosting ASN) to enumerate the full cluster, including dormant domains not yet weaponised.

### 2. File with evidence the first time

Each abuse report shipped with packaged evidence: screenshots, the credential-harvesting endpoint, WHOIS, and DNS records. Complete reports get actioned faster and bounce back less often.

### 3. Escalate stalled cases automatically

When a registrar or host went quiet past its typical response window, cases were escalated to the upstream provider and, where applicable, the relevant CERT, without waiting for a human to notice.

## Outcome

Within the first week, 41 active and staged domains were removed. Median time-to-removal dropped from roughly six days to 31 hours. Because the takedowns hit the registrar and hosting layers rather than just the URLs, 96% of the cluster stayed down after 30 days, and the attacker's reappearance rate fell sharply.

> We went from chasing domains one at a time to watching the whole kit come down in a week. The reporting alone saved our SOC days of work.
>
> — Head of Fraud Operations

## The service behind this

[Phishing site removal](https://fraudox.com/phishing-takedown): Credential harvesting pages and cloned login flows. Filed with the host and the registrar in parallel, and submitted to browser safe-browsing lists so visitors are warned while the page is still up.

*Figures are illustrative of the Fraudox takedown workflow, and client-identifying details are anonymised unless the client has approved their use. Canonical version: https://fraudox.com/case-studies/banking-phishing-cluster-takedown.*

---

Published by Fraudox (https://fraudox.com), a brand protection takedown service that
removes phishing sites, impersonating pages, fake social accounts, counterfeit apps,
scam domains and stolen content, and bills only for confirmed removals.
