Security1 distinct publisher3 min readUpdated
Allure Security traced one copied sentence to about 2,200 invented bank domains. Almost none imitate a real brand, which is why brand-led takedown programmes will not find them.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Allure Security says a single copied sentence in page source led it to roughly 2,200 domains hosting invented banks, and that 810 of the live ones were built on the same $25 front-end template [2][3][7]. None of that is brand impersonation, which the researchers ruled out early [5]: the fraud does not need a victim to mistake a fake bank for a real one, so the detection and takedown machinery aimed at logos and lookalike domains has nothing to grab.
The find was accidental. According to the research, Molly DeQuattro, the company's VP of Operations, was reviewing a domain that resembled a financial services client's brand but carried none of that client's branding and presented an unrelated bank instead [1]. One phrase, "one of the largest digital banking providers," searched across public website source code, returned about 2,200 matching domains [2]. Of those, 1,095 returned a working page and 838 still contained the phrase [3][4] - so just under half the inventory was live at the time of testing, and about 77% of the live pages were still running the original copy [15][16].
The stack underneath is thin and consistent. Allure Security reports that 810 of the 838 sites, 97%, retained parts of Cuex, a commercial front-end template sold for currency exchange and digital banking sites for $25 at the time [7]. Laravel, a PHP framework handling logins, sessions, registration and account access, appeared on 94% [8]. A misspelled heading carried over from the template, "Curreny Charts," survived on 90% [9]. On a per-site basis, that is roughly three cents of template cost per phantom bank [17].
What the researchers call legitimacy stacking is the operational point: banking interfaces, dashboards, investment products, corporate details and support contacts layered until an institution that does not exist looks like one that does [10]. Among the 838 sites, 770 presented login pages, 767 set session cookies and 729 contained anti-forgery tokens [11] - about 92% of the set built to accept and hold user data [18]. The researchers describe the familiar model: a broker, romantic contact, loan agent, recovery service or supposed delivery representative introduces a victim to an unfamiliar institution, and the portal gives that story a persistent interface for balances, gains, transfers, holds and withdrawal problems [12].
The one thread that led outward was a copying error. A site branded Classtands Crest still had "Create an Account- Remedy bank" in the title of its account-creation page, and the registration form posted to a separate domain, remedycodes[.]site, which had already appeared as a contact point on two other sites flagged elsewhere for suspected fraud [13]. The researchers say they did not submit the form [13].
For anyone running a brand-protection or fraud programme, the consequence is a change of index. Allure Security's recommendation is to combine artefacts rather than trademarks: the "Curreny Charts" typo, shared paths and code, matching cookies and contact details, and forms that send data to the same destination, plus independent verification of the institution's claims and preserved evidence such as pages, timestamps, hashes and sources [14]. Note also what the source does not allege: Cuex is a legitimate commercial product [7], so the supply chain here is ordinary web development, not a criminal toolkit.
Watch whether the 1,105 non-responding domains come back [19], and whether registrars and hosts will act on template-and-artefact clustering when no trademark has been infringed [5][14].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Researchers noted the features fit a familiar fraud model: "A broker, romantic contact, loan agent, recovery service, or supposed delivery representative can introduce a victim to an unfamiliar financial institution. The portal gives that story a persistent interface for accounts, balances, investment gains, transfers, holds, and withdrawal problems."
Molly DeQuattro, VP of Operations at Allure Security, was reviewing a domain that resembled the brand of one of the company's financial services clients; the page carried none of that client's branding and presented an unrelated bank instead.
She searched public website source code for the exact phrase "one of the largest digital banking providers" and found about 2,200 matching domains.
The team tried to connect to all 2,200 domains; 1,095 returned a working page.
Of the 1,095 working pages, 838 still contained the search phrase.
The researchers wrote: "Why would someone place an invented bank on a domain associated with another brand? A victim would not confuse it with their existing bank." That question ruled out brand impersonation and sent the team digging into the applications.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific measurements, one vendor source, no independent check
The counts are precise and the collection path is described end to end (phrase search, connection attempts, phrase retention, stack fingerprints, artefact prevalence), which is stronger than a bare vendor assertion. But the cluster contains a single trade-press relay of one vendor's research: no domain list, no collection window or tooling detail, no third-party corroboration, and the fraud interpretation is inference from application features with only one site traced to a previously fraud-flagged address.
Malicious infrastructure measurably live; defender uptake unmeasured
Adoption of the pattern by operators of the phantom sites is directly measured: 1,095 domains resolved live, 838 retained the copied phrase, 810 reused the $25 template and 770 served login pages. What is not measured is any adoption on the defensive side -- no takedowns, registrar or host actions, customer deployments of the detection guidance, or third parties reproducing the fingerprints -- and no victim or transaction volume is reported.
Counts solid, fraud scale and takedown-gap framing run ahead of proof
The measured artefacts support the headline arithmetic ($25 template, 810 sites), so the technical claims are not inflated. The overstatement sits in the interpretive layer: 'phantom banks built to support scams' and the implication that brand-led takedown programmes systematically miss them are asserted from application features and one off-domain form target, with no victim losses, enforcement outcomes, or counter-check against legitimate reuse of a commercial template and its boilerplate marketing sentence.
Vendor research promoting the detection capability it sells
Every figure and the coining of 'legitimacy stacking' come from Allure Security, a commercial brand-protection and scam-site detection vendor, and the story's core message is that conventional brand-led monitoring cannot find this class of site -- a gap the vendor's offering addresses. The trade-press relay reproduces the vendor framing, quotes and screenshot without independent verification or any disclosure of that commercial interest.
Moderate: coherent single-source measurement, no corroboration
Confidence is limited by cluster breadth rather than internal coherence. One publisher, one underlying vendor study, no independent replication and no dataset make the technical fingerprints credible but the scale-of-harm and takedown-gap conclusions provisional; the arithmetic-derived claims inherit whatever error exists in the source counts.
build
Once the question needs a cube, you own the parser1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
security
The customer is genuine and the payment is authorized: 55% of banks say scams dominate fraud1 distinct publisher
build
Laravel's session cookie is why your HTML never gets cached at the edge1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026