New Registrations

Bizum phishing domains

Newly registered lookalikes - tracked daily


Bizum phishing domains

Newly registered lookalikes - tracked daily


Tracked (7d)
3
New (24h)
0
vs avg
Website
bizum.es
About
AISpain's bank-backed instant mobile payment system, linked directly to the user's bank account. Lures are overwhelmingly SMS-launched, mimicking a payment-received or account-blocked notice to harvest banking credentials.
TLDs
.com (2) · .site (1)
Countries
United StatesUnited States (1)

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details
2026-09-08 13:05 2026-09-08 13:05
https://bizumonline.site
Screenshot of bizumonline.site Details
2026-09-05 13:25 2026-09-05 13:25
https://casino-online-bizum.com
Screenshot of casino-online-bizum.com Details
2026-09-05 13:23 2026-09-05 13:23
https://bizumers.com
Screenshot of bizumers.com Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://bizumonline.site
Screenshot of bizumonline.site Details
https://casino-online-bizum.c…
Screenshot of casino-online-bizum.com Details
https://bizumers.com
Screenshot of bizumers.com Details

AIHow to verify a real Bizum URL

  • Legitimate Bizum URLs always end in bizum.es (e.g. www.bizum.es, account.bizum.es). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Bizum.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Bizum has owned bizum.es for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open bizum.es from your browser bookmark or type the domain manually.
  • Real Bizum pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.