OSINT Phishing Intelligence

OSINT phishing intelligence explains the campaigns behind the emails, texts and fake login pages your people keep reporting. We identify the kit, map the infrastructure, follow where stolen credentials go and tell you which operator is behind it, so your SOC can block the whole campaign rather than one URL at a time.

  • Lures and targeting
  • Kit and phishing-as-a-service analysis
  • Infrastructure clusters
  • Detections and awareness material
Short answer

OSINT phishing intelligence is the open-source study of phishing campaigns aimed at your organization: the lures used, the phishing kit or subscription service behind them, the domains and hosting, where captured credentials are sent and who sells or runs the kit. You receive a campaign report, indicators your tools can block, detection advice for email and identity systems, and real lures for staff training.

What OSINT Phishing Intelligence Tracks

Six layers of a campaign, from the message your staff see to the operator who sells the kit. Each layer produces a different defensive action.

LayerQuestions we answerWhat you do with it
LuresWhich pretexts, brands and senders are used: invoices, shared documents, payroll, delivery notices, QR codesEmail filtering rules and training that shows the real messages
TargetingWho receives them: finance, executives, new joiners, customers of one productExtra protection for the groups being hit
KitWhich kit or subscription service builds the pages, whether it relays sign-in sessions to defeat MFA, which other brands it imitatesIdentity controls matched to the kit's method
InfrastructureDomains, hosting, redirectors and URL patterns shared across the campaignBlocks on the cluster, not on single links
Credential flowWhere captured data goes and whether your accounts later appear for saleResets and session revocation for the right users
OperatorWho advertises, sells or supports the kit, and how active they areReports to platforms and law enforcement

Phishing in 2026: Record Volumes and Kits for Rent

Phishing volume is still rising, and much of it is built with rented kits that copy many brands at once.

  • The Anti-Phishing Working Group observed 1,069,681 phishing attacks in the second quarter of 2026, up 10.1% on the first quarter, with June the busiest month since April 2023, against 941 unique brands. SaaS and webmail services were the most targeted sector, at 29.1% of attacks (APWG Phishing Activity Trends Report, Q2 2026).
  • In September 2025, Microsoft obtained a court order to seize 338 websites tied to RaccoonO365, a subscription service selling kits that imitate Microsoft 365. Microsoft says it was used to steal at least 5,000 credentials from users in 94 countries and that its kits were built to get around multi-factor authentication (Microsoft).

The practical point: the page your staff saw is rarely unique. The same kit is usually aimed at hundreds of organizations, so the fastest way to understand your campaign is to identify the kit and the people renting it.

Phishing Intelligence or Phishing Domain Takedown?

Takedown removes a domain or page; intelligence explains the campaign so you can block what comes next. Most serious cases need both.

Phishing intelligencePhishing domain takedown
QuestionWho is phishing us, with what, and what will they try next?How do we get this domain or page removed?
Main outputCampaign report, indicators, detection advice, training luresEvidence packs for registrars, hosts, URS or UDRP
Owner at your endSOC, identity team, awareness teamBrand protection, legal, fraud
Time horizonThe campaign and the operator over weeksOne domain or cluster, often the same day

When a live domain needs to come down, we hand the cluster to phishing domain takedown, which handles routes and registrar evidence. If a campaign has already led to a changed bank account or a paid invoice, the case continues as a business email compromise investigation.

How an OSINT Phishing Investigation Runs

Collect samples, analyze the kit, cluster the infrastructure, follow the credentials, then hand over actions and keep watching.

  1. Collect reported samplesYour reported emails, texts and URLs, with full headers, become the seed set. We agree what may be shared and remove recipients' personal details not needed for analysis.
  2. Analyze the page and kitPages are viewed from an isolated environment as an ordinary visitor would see them, and the kit family, its MFA handling and its other target brands are identified.
  3. Cluster the infrastructureDomains, hosts, redirectors and page fingerprints are grouped so you can see the full campaign, not one link.
  4. Follow the credentialsWe check where captured data is sent and watch criminal markets and channels for your accounts or access being offered.
  5. Hand over actionsIndicators to block, detection ideas for your email gateway and identity provider, and a short brief for leadership.
  6. Watch for the next waveNew domains and pages matching the operator's patterns are flagged through our analyst-reviewed monitoring platform, which updates hourly.

Deliverables, Timelines and Limits

A campaign report with indicators and detection advice from 10 business days, quick answers on a single sample sometimes within a business day.

You receive a campaign report with the six layers above, an indicator list in the format your tools accept, detection and hardening advice, and an anonymized lure pack your awareness team can use. Identifying the kit behind one reported page is often a small task we can sometimes return within a business day. A campaign report starts from 10 business days, and a study of all campaigns targeting a brand over a quarter takes up to about a month. Urgent delivery costs 50% more, a senior analyst reviews every report, the price is fixed after written scoping and the fee goes down if we miss the agreed date.

We do not log in to phishing panels, submit real or stolen credentials, buy kits or stolen data, or pose as a buyer in closed channels. Personal data of staff or customers found during the work is kept to what the case needs under the GDPR and similar laws. Kit operators who keep coming back can be profiled through OSINT threat actor profiling, and campaign indicators can feed curated threat intelligence feeds. Phishing work is part of the wider OSINT threat intelligence service and one of the OSINT services for security teams we run.

Find Out Who Is Phishing Your People

Send two or three reported phishing emails with full headers, or the URLs your staff clicked. We tell you what we can learn, how long it takes and a fixed price.

OSINT Phishing Intelligence FAQ

Our staff keep reporting fake Microsoft 365 login emails that look slightly different every week — can OSINT phishing intelligence tell us whether it is one group, and how to stop the whole campaign?

Often, yes. OSINT phishing intelligence compares the reported pages, domains, hosting and kit fingerprints to see whether they share an operator or a rented phishing kit. If they do, you get the full cluster to block, the kit's method, for example whether it relays sign-in sessions to defeat MFA, and identity controls matched to that method. Changing lures every week is normal for kits sold by subscription, so the kit is a better target than the message.

We already pay for an email security gateway that catches most phishing — what does phishing intelligence add that our filter vendor does not already do?

Context about your own campaigns. A gateway scores each message on its own and sees only what reaches you. Phishing intelligence looks at the campaign from outside: which kit is used, which other brands it imitates, where credentials go and whether your accounts are later offered for sale. That produces cluster blocks, identity rules and targeted resets your filter cannot infer from one email at a time.

A phishing site copying our customer portal is live right now — should we ask you for phishing intelligence or for a domain takedown first?

Takedown first if customers are being harmed today. Our phishing domain takedown service prepares the registrar and host evidence, often within a business day. Intelligence work can start in parallel on the same samples: it finds the sibling domains, the kit and the operator, so the next copy is blocked or reported faster. Most clients run both on a serious campaign.

Can you tell us whether credentials our employees typed into a phishing page are now being sold, and which accounts we need to reset?

We can follow the credential flow where it is visible in open and commercially available sources, and watch criminal markets and channels for your domain, accounts or access being offered. We do not buy data or log in with it. When accounts appear, we report them for reset and session revocation. Ongoing coverage of this kind is also available as leaked credential monitoring.

Our awareness team wants to use real phishing emails that targeted us in next quarter's training — can your report give them material they can safely use?

Yes. Each report can include a lure pack: the real messages and pages aimed at your organization, with recipients' details, live links and tracking parameters removed. Trainers can show staff exactly what reached them, which is more convincing than generic templates. If you also want controlled simulations, our social engineering assessment covers authorization, scope and staff welfare for that work.

Our lawyers asked whether it is legal for your analysts to visit phishing sites and examine phishing kits on our behalf — where exactly do you stop?

Visiting a public phishing page as an ordinary visitor and documenting it is standard practice, and we do it from an isolated environment. We stop at anything that needs credentials or a deal with the operator: we do not log in to panels, submit real or stolen credentials, buy kits or pose as a buyer. Findings about identifiable operators go to you, your counsel or law enforcement, not to the public.