New Registrations

Rabobank phishing domains

Newly registered lookalikes - tracked daily


Rabobank phishing domains

Newly registered lookalikes - tracked daily


About
AIDutch retail banking phishing - credential and OTP harvest, often SMS-launched.

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details

AIHow to verify a real Rabobank URL

  • Legitimate Rabobank URLs always end in rabobank.nl (e.g. www.rabobank.nl, account.rabobank.nl). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Rabobank.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Rabobank has owned rabobank.nl for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open rabobank.nl from your browser bookmark or type the domain manually.
  • Real Rabobank pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.