Jpost iconJpostSep 11, 2026 ~2 min source read

BrandShield: More than 1.5 million fraudulent online domains found in past year, including fake hostage-forum listings

Israeli cybersecurity firm BrandShield mapped a surge in impersonation and fake-site fraud. High-profile targets include airlines, major brands, FIFA, and a forum for hostages’ families; AI and fast website builders are making scams easier to create and scale.

Israeli company finds over one million online fraud cases, including fake hostage forum listings

Share this story

Send the public story page.

Useful takeaways from this story.

Specific high-volume impersonations included El Al (10,395 listings), FIFA (over 10,000), Omega SA (5,878), NIKE (5,134), and Apple iPhone listings (4,041).

Scams are increasingly fast and automated: BrandShield’s test showed a fake business website can be built in about five minutes using AI and site builders.

Real-world techniques include phishing SMS that mimic government agencies (example: fake Israel Traffic Authority fines) and networks selling counterfeit medications while posing as healthcare organizations.

BrandShield, an Israeli cybersecurity company, reported finding more than 1.5 million fraudulent online domains over the last year. The dataset shows attackers overwhelmingly impersonate trusted organizations—airlines, global sports bodies, major brands, celebrities, and even family support forums—to make fraud more convincing.

  • El Al: 10,395 scam listings.
  • FIFA: more than 10,000 fake domains and sites ahead of the 2026 World Cup.
  • Omega SA: 5,878 suspicious domains linked to the luxury watch brand.
  • NIKE: 5,134 related listings.
  • Labubu: 4,987 listings.
  • Apple iPhone: 4,041 listings.
  • Elon Musk: about 4,800 listings impersonating the entrepreneur.
  • Hostages and Missing Families Forum: 1,165 listings that sold products while impersonating that community.

BrandShield's CEO Yoav Keren summarized the tactic: attackers follow public trust. The more recognizable a name, the easier it is to trick victims into believing communications or websites are legitimate.

BrandShield documented several operational tactics used by scammers:

  • Rapid site creation: Using AI tools and website builders, BrandShield demonstrated that a fully fledged fake business site—with name, logo, staff profiles, testimonials, photos, and phone numbers—can be created in about five minutes.
  • Live data capture: In one campaign impersonating the Israel Traffic Authority, SMS messages told recipients they owed 100 shekels for a fine. As victims entered information on the fake page, attackers could monitor keystrokes and actions in real time.
  • Organized networks: The firm uncovered a Hong Kong-based network running a site that sold counterfeit medications worldwide while impersonating healthcare organizations.

Keren warned that AI and automation change the scale of the problem: tasks that once required time, money, and technical know-how can now be replicated rapidly.

Notable targets and why they matter

Attackers aim at entities that carry public trust and high transaction rates: airlines and ticketing, sports organizations around major events, luxury brands where high-value goods create demand, and public-facing institutions such as government agencies. The report highlights how attackers repurpose those trusted names to harvest personal data, steal payment details, or sell nonexistent products and services.

  • Check domain details before entering sensitive information: look for subtle misspellings, unusual domain extensions, and registration age.
  • Treat unsolicited SMS links with caution, even if they claim to be fines or official notices. Verify through official channels rather than clicking embedded links.
  • Confirm seller credibility for high-value purchases (luxury watches, electronics, medications) by using official brand stores or verified resellers.
  • Report impersonation sites to the legitimate brand and to the platform or domain registrar hosting the fake site.

BrandShield's findings show a large volume of impersonation and fake-domain activity concentrated around well-known names and events. The combination of rapid site-building tools and real-time fraud management increases the number of scams that can be launched and scaled quickly. For individuals and organizations, the immediate defense is heightened verification of domains, careful handling of unsolicited messages, and preferring official channels for transactions.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app