Security1 publisher3 min readPublished
The phantom banks are not impersonating you: a $25 template built 810 of them
Allure Security traced one copied sentence to about 2,200 invented bank domains. Almost none imitate a real brand, which is why brand-led takedown programmes will not find them.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Molly DeQuattro, VP of Operations at Allure Security, was reviewing a domain that resembled the brand of one of the company's financial services clients; the page carried none of that client's branding and presented an unrelated bank instead.
- She searched public website source code for the exact phrase "one of the largest digital banking providers" and found about 2,200 matching domains.
- The team tried to connect to all 2,200 domains; 1,095 returned a working page.
- Of the 1,095 working pages, 838 still contained the search phrase.
- The researchers wrote: "Why would someone place an invented bank on a domain associated with another brand? A victim would not confuse it with their existing bank." That question ruled out brand impersonation and sent the team digging into the applications.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Allure Security says a single copied sentence in page source led it to roughly 2,200 domains hosting invented banks, and that 810 of the live ones were built on the same $25 front-end template [2][3][7]. None of that is brand impersonation, which the researchers ruled out early [5]: the fraud does not need a victim to mistake a fake bank for a real one, so the detection and takedown machinery aimed at logos and lookalike domains has nothing to grab.
The find was accidental. According to the research, Molly DeQuattro, the company's VP of Operations, was reviewing a domain that resembled a financial services client's brand but carried none of that client's branding and presented an unrelated bank instead [1]. One phrase, "one of the largest digital banking providers," searched across public website source code, returned about 2,200 matching domains [2]. Of those, 1,095 returned a working page and 838 still contained the phrase [3][4] - so just under half the inventory was live at the time of testing, and about 77% of the live pages were still running the original copy [15][16].
The stack underneath is thin and consistent. Allure Security reports that 810 of the 838 sites, 97%, retained parts of Cuex, a commercial front-end template sold for currency exchange and digital banking sites for $25 at the time [7]. Laravel, a PHP framework handling logins, sessions, registration and account access, appeared on 94% [8]. A misspelled heading carried over from the template, "Curreny Charts," survived on 90% [9]. On a per-site basis, that is roughly three cents of template cost per phantom bank [17].
What the researchers call legitimacy stacking is the operational point: banking interfaces, dashboards, investment products, corporate details and support contacts layered until an institution that does not exist looks like one that does [10]. Among the 838 sites, 770 presented login pages, 767 set session cookies and 729 contained anti-forgery tokens [11] - about 92% of the set built to accept and hold user data [18]. The researchers describe the familiar model: a broker, romantic contact, loan agent, recovery service or supposed delivery representative introduces a victim to an unfamiliar institution, and the portal gives that story a persistent interface for balances, gains, transfers, holds and withdrawal problems [12].
The one thread that led outward was a copying error. A site branded Classtands Crest still had "Create an Account- Remedy bank" in the title of its account-creation page, and the registration form posted to a separate domain, remedycodes[.]site, which had already appeared as a contact point on two other sites flagged elsewhere for suspected fraud [13]. The researchers say they did not submit the form [13].
For anyone running a brand-protection or fraud programme, the consequence is a change of index. Allure Security's recommendation is to combine artefacts rather than trademarks: the "Curreny Charts" typo, shared paths and code, matching cookies and contact details, and forms that send data to the same destination, plus independent verification of the institution's claims and preserved evidence such as pages, timestamps, hashes and sources [14]. Note also what the source does not allege: Cuex is a legitimate commercial product [7], so the supply chain here is ordinary web development, not a criminal toolkit.
Watch whether the 1,105 non-responding domains come back [19], and whether registrars and hosts will act on template-and-artefact clustering when no trademark has been infringed [5][14].