New Registrations

Citigroup phishing domains

Newly registered lookalikes - tracked daily


Citigroup phishing domains

Newly registered lookalikes - tracked daily


About
AIGlobal retail and business banking phishing. Credentials, OTP capture, and second-factor-bypass pages are the recurring pattern.

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details

AIHow to verify a real Citigroup URL

  • Legitimate Citigroup URLs always end in citigroup.com (e.g. www.citigroup.com, account.citigroup.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Citigroup.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Citigroup has owned citigroup.com for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open citigroup.com from your browser bookmark or type the domain manually.
  • Real Citigroup pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.