Scam Campaign Report: Multi-Vector Financial and Malware Threat Cluster Consumer Protection Intelligence Report This report documents a cluster of 5,789 connected entities involved in a broad, multi-vector fraud and malware campaign targeting consumers across the United States and internationally. The cluster includes 1,271 phone numbers, 2,957 domains, 143 companies, and 281 email addresses, interconnected through 17 confirmed cross-entity relationships. The campaign appears to operate across ...
pcmag.com
First seen Feb 23, 2026
- No SSL certificate
- 1 community report from users
Campaign Intelligence
Scam Campaign Report: Privacy Email Service Impersonation and Suspicious Contact Network This report documents a cluster of 14 connected entities — including two phone numbers, ten domains, and two Zoho-hosted email addresses — that have been flagged and reported together in community threat intelligence submissions. The cluster centers on a pattern of references to privacy-focused email providers and technology review platforms, with the suspicious domain protonmaildotcom.wordpress.com serving...
Scam Campaign Report: Multi-Vector Financial Fraud and Malware Infrastructure Cluster This report documents a cluster of 4,628 connected entities identified through cross-referencing complaint databases, threat intelligence feeds, and community reporting. The cluster spans 1,295 phone numbers, 2,559 domains and IP addresses, 160 companies, and 252 email addresses. While the individual phone numbers in this cluster each carry zero FTC complaints at this time, the broader infrastructure surroundi...
Scam Campaign Intelligence Report: Multi-Vector Financial and Malware Threat Cluster This report covers a cluster of 4,263 connected entities identified through aggregated complaint data, infrastructure analysis, and community reporting. The cluster encompasses 1,055 phone numbers, 2,451 domains and IP addresses, 146 companies, and 252 email addresses, forming one of the more complex mixed-threat groupings analyzed for consumer protection purposes. The campaign appears to exploit consumer famil...
Scam Campaign Report: Multi-Vector Financial Fraud and Infrastructure Cluster This report covers a cluster of 3,157 connected entities identified through shared reporting, co-appearance in consumer complaints, and cross-domain infrastructure linkages. The campaign spans 1,314 phone numbers, 1,486 domains, 170 companies, and 187 email addresses, with 16 documented cross-entity relationships. The cluster appears to blend legitimate financial institution impersonation with fraudulent domains, susp...
Scam Campaign Report: Multi-Vector Fraud and Malware Cluster (3,955 Connected Entities) This report documents a large and technically sophisticated scam campaign comprising 3,955 connected entities, including 651 phone numbers, 2,107 flagged domains and IP addresses, and 182 associated email addresses. The campaign spans multiple fraud categories, combining impersonation-based telephone scams, malware distribution infrastructure, phishing email operations, and consumer fraud documented across c...
Scam Campaign Analysis Report: Multi-Vector Fraud and Malware Cluster (3,969 Connected Entities) Investigators have identified a sprawling cluster of 3,969 connected entities operating across phone, email, and web-based infrastructure, comprising 651 phone numbers, 2,121 domains and IP addresses, and 182 email addresses. The campaign spans multiple fraud categories including impersonation calls, malware distribution, botnet operations, and overpayment scams. The most prominently documented phon...
Scam Campaign Report: Multi-Vector Fraud Network Involving Impersonation Calls, Malware Infrastructure, and Online Vehicle Purchase Fraud This report covers a cluster of 3,426 connected entities, including 619 phone numbers, 1,630 domains, and 181 email addresses, tied to a broad and technically sophisticated fraud campaign. The campaign combines government and business impersonation robocalls, malware distribution infrastructure, and consumer-facing vehicle purchase scams. The scale and divers...
Scam Campaign Report: Multi-Vector Fraud and Malware Network (Cluster of 3,989 Connected Entities) This report documents a large-scale fraud and malware campaign identified through a cluster of 3,989 connected entities, including 651 phone numbers, 2,141 domains and IP addresses, and 182 email addresses. The campaign operates across multiple attack surfaces simultaneously, combining impersonation phone calls, malware-laced infrastructure, and deceptive email outreach to target consumers across ...
Details
Related Domains
neomailbox.com
reported togetherdomainfastmail.com
reported togetherdomainhelp.hushmail.com
reported togetherdomainprotonmaildotcom.wordpress.com
reported togetherdomainrunbox.com
reported togetherdomainblog.fastmail.com
reported togetherdomainzoho.com
reported togetherdomainblog.runbox.com
reported togetherdomainhushmail.com
reported togetherphone6626578240
reported togetherdomainwcvb.com
same infrastructuredomaindillards.com
same infrastructuredomaintdbank.com
same infrastructurephone8773824357
campaign co-memberphone8772427372
campaign co-memberphone3054749429
campaign co-memberphone9056283715
campaign co-memberphone2062221648
campaign co-memberphone8777058586
campaign co-memberphone5086371451
campaign co-memberphone2019841313
campaign co-memberphone4063591564
campaign co-memberphone2012011305
campaign co-memberphone3074282900
campaign co-memberCommunity Reports
ProtonMail, HushMail, FastMail, NeoMailbox, Runbox, and Zoho and possibly other email services have been victims of DDoS and extortion attempts in the past week Fastmail.com's statement: http://blog.fastmail.com/2015/11/11/ddos-attack-may-lead-to-potential-service-disruption-this-week/ Runbox.com's statement: https://blog.runbox.com/2015/11/ddos-attacks-on-runbox/ Zoho.com's statement: https://www.zoho.com/service-updates/blog/zoho-services-under-criminal-attack.html HushMail.com's statement: https://help.hushmail.com/entries/107539976 NeoMailBox.com's statement: https://twitter.com/neomailbox/status/662657824036556802 Comments: https://www.reddit.com/r/ProtonMail/comments/3rs34z/same_ddos_attackers_are_now_attacking_another/ ProtonMail.ch's statement: https://protonmaildotcom.wordpress.com/2015/11/05/protonmail-statement-about-the-ddos-attack/ ProtonMail actually paid the extortionists. More here: http://www.pcmag.com/article2/0,2817,2494716,00.asp Reddit comments: https://www.reddit.com/r/ProtonMail/comments/3rpb0d/a_question_to_the_protonmail_team_regarding_the/
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.