Allure Security Research on Phantom Bank Ecosystem Draws Industry Press Coverage

Share Article

Security publications are covering Allure Security’s investigation into 2,200 domains tied to a mass-produced network of fake financial institutions.

SecurityBrief reports on Allure Security’s discovery of 2,200 domains linked to a network of phantom bank websites.

Allure Security research published this month in Signal & Noise, the monthly column from Director of Security Research Ryan Merritt, is drawing coverage from cybersecurity press focused on fraud and financial services.

The investigation began when Molly DeQuattro, Allure Security’s VP of Operations, noticed one awkward sentence on a suspicious website. A source-code search for that exact phrase surfaced roughly 2,200 domains, which the research team traced to a mass-produced ecosystem of phantom banks: invented financial institutions assembled from commodity parts and dressed with enough features to appear real.

Help Net Security framed the finding around its economics, reporting that a $25 commercial template supplied the visible design for 97% of the surviving sites, with a reusable application layer underneath handling logins, sessions, and registration. SecurityBrief, in a story syndicated across the TechDay network, emphasized that these were not static facades: hundreds of the sites presented working login pages, set session cookies, and referenced the internal machinery of full banking applications, from KYC review to transaction management.

Both stories highlighted the concept the research introduces, legitimacy stacking: the layering of bank-like functions, compliance claims, corporate identities, and support channels that makes a fabricated institution credible enough to support investment, loan, romance, and advance-fee fraud.

The findings have also circulated through the channels security practitioners read daily. Risky Business featured the research in its Risky Bulletin newsletter, Help Net Security included the story in its weekly review, and Thailand’s National Cyber Security Agency cited the work in an August threat intelligence bulletin.

“The interest in this research reflects something practitioners already know: fraud infrastructure is industrializing,” said Ryan Merritt, Director of Security Research at Allure Security. “When an invented bank can be assembled from commodity parts for less than the cost of dinner, the question stops being whether these sites exist and becomes how fast you can find and connect them.”

The full investigation, including methodology, indicators, and guidance for defenders, is available in When Fraud Needs a Bank: Inside an Ecosystem Built to Manufacture Trust. A technical paper with the complete indicator matrix and clustering methodology will follow.

About Allure Security

Allure Security is the AI-native platform for disinformation defense. Its platform detects and dismantles digital impersonation threats, including phishing sites, fake executive identities, rogue mobile apps, and coordinated disinformation campaigns, across the web, social media, mobile, and the dark web. Combining AI-powered detection, patented deception technology, and managed response backed by a 24×7 Security Operations Center, Allure Security helps enterprises find threats earlier and neutralize them faster. Headquartered in Boston, the company is backed by Riverside Acceleration Capital, Curql Collective, Glasswing Ventures, and Gutbrain Ventures.

Contact
Ben Rogers
press@alluresecurity.com

Disinformation Security guide covering AI-generated impersonation threats and enterprise defense strategies

DISINFORMATION GUIDE

The emerging discipline of disinformation security

Gartner predicts 50% of enterprises will invest in disinformation security by 2027. This guide explains what that means: the three pillars of protection, why AI-generated threats are accelerating the timeline, and how to build a defense strategy that protects revenue, reputation, and trust.