New Registrations
Bank of America phishing domains
Newly registered lookalikes - tracked daily
Bank of America phishing domains
Newly registered lookalikes - tracked daily
Tracked (7d)
6
New (24h)
1
vs avg
—
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-05-25 01:22 | 2026-05-25 01:22 | ![]() |
Details | ||
| 2026-05-21 00:48 | 2026-05-21 00:48 | ![]() |
Details | ||
| 2026-05-21 00:37 | 2026-05-21 00:37 | ![]() |
Details | ||
| 2026-05-20 00:41 | 2026-05-20 00:41 | ![]() |
Details | ||
| 2026-05-20 00:35 | 2026-05-20 00:35 | ![]() |
Details | ||
| 2026-05-19 00:36 | 2026-05-19 00:36 | ![]() |
Details |
Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://loginauth-bankofameri…
|
![]() |
Details |
| https://enotice-bankofamerica…
|
![]() |
Details |
| https://bankofamerica-cn.com
|
![]() |
Details |
| https://bankofamerica.cyou
|
![]() |
Details |
| https://872992-bankofamerica.…
|
![]() |
Details |
| https://bankofamericas.org
|
![]() |
Details |
AIHow to verify a real Bank of America URL
- Legitimate Bank of America URLs always end in
bankofamerica.com(e.g.www.bankofamerica.com,account.bankofamerica.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Bank of America. - The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Bank of America has owned
bankofamerica.comfor years; brand-new look-alikes are almost never legitimate. - If you got the link from email, SMS, or social media, do not click it. Open
bankofamerica.comfrom your browser bookmark or type the domain manually. - Real Bank of America pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.



