New Registrations

Bank of America phishing domains

Newly registered lookalikes - tracked daily


Bank of America phishing domains

Newly registered lookalikes - tracked daily


Tracked (7d)
13
New (24h)
1
vs avg
—
About
AIUS retail banking phishing. Standard credential, OTP, and security-question harvest, often SMS-launched ('smishing').
TLDs
.com (6) · .bond (3) · .xin (1)
Countries
United StatesUnited States (4) · United KingdomUnited Kingdom (3) · Hong KongHong Kong (1)

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) ▾ URL Screenshot Flags Details
2026-10-01 13:26 2026-10-01 13:26
https://bankofamericasi.com
Screenshot of bankofamericasi.com Details
2026-09-29 13:15 2026-09-29 13:15
https://bankofamericaltd.com
Screenshot of bankofamericaltd.com Details
2026-09-29 13:14 2026-09-29 13:14
https://bankofamerica-service.com
Screenshot of bankofamerica-service.com Details
2026-09-27 13:11 2026-09-27 13:11
https://bankofamerica.xin
Screenshot of bankofamerica.xin GSB OpenPhish PhishTank Details
2026-09-26 13:09 2026-09-26 13:09
https://bankofamericasas.info
Screenshot of bankofamericasas.info Details
2026-09-25 13:22 2026-09-25 13:22
https://bankofamerica-loginuser.com
Screenshot of bankofamerica-loginuser.com Details
2026-09-25 13:21 2026-09-25 13:21
https://bankofamerica-ec.com
Screenshot of bankofamerica-ec.com GSB Details
2026-09-24 13:21 2026-09-24 13:21
https://bankofamerica.mom
Screenshot of bankofamerica.mom Details
2026-09-24 13:21 2026-09-24 13:21
https://bankofamerica-onlinebanking.cyou
Screenshot of bankofamerica-onlinebanking.cyou Details
2026-09-24 13:21 2026-09-24 13:21
https://bankofamerica-onlinebanking.bond
Screenshot of bankofamerica-onlinebanking.bond Details
2026-09-24 13:21 2026-09-24 13:21
https://bankofamerica-onlinebanking-login.bond
Screenshot of bankofamerica-onlinebanking-login.bond GSB Details
2026-09-24 13:21 2026-09-24 13:21
https://bankofamerica-login.bond
Screenshot of bankofamerica-login.bond Details
2026-09-24 13:20 2026-09-24 13:20
https://bankofamerica-diagnostic.com
Screenshot of bankofamerica-diagnostic.com Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://bankofamericasi.com
Screenshot of bankofamericasi.com Details
https://bankofamericaltd.com
Screenshot of bankofamericaltd.com Details
https://bankofamerica-service…
Screenshot of bankofamerica-service.com Details
https://bankofamerica.xin
GSB OpenPhish PhishTank
Screenshot of bankofamerica.xin Details
https://bankofamericasas.info
Screenshot of bankofamericasas.info Details
https://bankofamerica-loginus…
Screenshot of bankofamerica-loginuser.com Details
https://bankofamerica-ec.com
GSB
Screenshot of bankofamerica-ec.com Details
https://bankofamerica.mom
Screenshot of bankofamerica.mom Details
https://bankofamerica-onlineb…
Screenshot of bankofamerica-onlinebanking.cyou Details
https://bankofamerica-onlineb…
Screenshot of bankofamerica-onlinebanking.bond Details
https://bankofamerica-onlineb…
GSB
Screenshot of bankofamerica-onlinebanking-login.bond Details
https://bankofamerica-login.b…
Screenshot of bankofamerica-login.bond Details
https://bankofamerica-diagnos…
Screenshot of bankofamerica-diagnostic.com Details

AIHow to verify a real Bank of America URL

  • Legitimate Bank of America URLs always end in bankofamerica.com (e.g. www.bankofamerica.com, account.bankofamerica.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Bank of America.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Bank of America has owned bankofamerica.com for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open bankofamerica.com from your browser bookmark or type the domain manually.
  • Real Bank of America pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.