New Registrations

Wells Fargo phishing domains

Newly registered lookalikes - tracked daily


Wells Fargo phishing domains

Newly registered lookalikes - tracked daily


Tracked (7d)
14
New (24h)
2
vs avg
—
About
AIUS retail banking phishing. Standard credential, OTP, and security-question harvest, often SMS-launched.
TLDs
.com (5) · .latino (3) · .fyi (1)
Countries
United StatesUnited States (11) · GermanyGermany (1)

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) ▾ URL Screenshot Flags Details
2026-10-09 15:55 2026-10-09 15:55
https://wellsfargobank.fyi
Screenshot of wellsfargobank.fyi GSB Details
2026-10-09 15:55 2026-10-09 15:55
https://wellsfargo-banking.com
Screenshot of wellsfargo-banking.com Details
2026-10-07 14:02 2026-10-07 14:02
https://wellsfargomobileassist.help
Screenshot of wellsfargomobileassist.help Details
2026-10-07 14:02 2026-10-07 14:02
https://wellsfargoceolive.com
Screenshot of wellsfargoceolive.com Details
2026-10-07 14:02 2026-10-07 14:02
https://wellsfargo.phone
Screenshot of wellsfargo.phone Details
2026-10-06 14:07 2026-10-06 14:07
https://wellsfargostatementmail.com
Screenshot of wellsfargostatementmail.com Details
2026-10-05 13:56 2026-10-05 13:56
https://wellsfargo-ph.com
Screenshot of wellsfargo-ph.com Details
2026-10-05 13:56 2026-10-05 13:56
https://wellsfargo-fraudalert.site
Screenshot of wellsfargo-fraudalert.site Details
2026-10-04 13:54 2026-10-04 13:54
https://wellsfargoonlinebanking.reviews
Screenshot of wellsfargoonlinebanking.reviews Details
2026-10-03 14:25 2026-10-03 14:25
https://wellsfargohomemortgage.latino
Screenshot of wellsfargohomemortgage.latino Details
2026-10-03 14:25 2026-10-03 14:25
https://wellsfargoadvisors.latino
Screenshot of wellsfargoadvisors.latino Details
2026-10-03 14:24 2026-10-03 14:24
https://wellsfargo.latino
Screenshot of wellsfargo.latino Details
2026-10-02 14:40 2026-10-02 14:40
https://wellsfargoceodesk.com
Screenshot of wellsfargoceodesk.com Details
2026-10-02 14:40 2026-10-02 14:40
https://wellsfargo.dev
Screenshot of wellsfargo.dev Details

Recently registered domains — may be used for phishing. Screenshots show parking pages while domains warm up. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://wellsfargobank.fyi
GSB
Screenshot of wellsfargobank.fyi Details
https://wellsfargo-banking.com
Screenshot of wellsfargo-banking.com Details
https://wellsfargomobileassis…
Screenshot of wellsfargomobileassist.help Details
https://wellsfargoceolive.com
Screenshot of wellsfargoceolive.com Details
https://wellsfargo.phone
Screenshot of wellsfargo.phone Details
https://wellsfargostatementma…
Screenshot of wellsfargostatementmail.com Details
https://wellsfargo-ph.com
Screenshot of wellsfargo-ph.com Details
https://wellsfargo-fraudalert…
Screenshot of wellsfargo-fraudalert.site Details
https://wellsfargoonlinebanki…
Screenshot of wellsfargoonlinebanking.reviews Details
https://wellsfargohomemortgag…
Screenshot of wellsfargohomemortgage.latino Details
https://wellsfargoadvisors.la…
Screenshot of wellsfargoadvisors.latino Details
https://wellsfargo.latino
Screenshot of wellsfargo.latino Details
https://wellsfargoceodesk.com
Screenshot of wellsfargoceodesk.com Details
https://wellsfargo.dev
Screenshot of wellsfargo.dev Details

AIHow to verify a real Wells Fargo URL

  • Legitimate Wells Fargo URLs always end in wellsfargo.com (e.g. www.wellsfargo.com, account.wellsfargo.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Wells Fargo.
  • The domains listed above were registered within the last 7 days. New-domain age is itself a signal — Wells Fargo has owned wellsfargo.com for years; brand-new look-alikes are almost never legitimate.
  • If you got the link from email, SMS, or social media, do not click it. Open wellsfargo.com from your browser bookmark or type the domain manually.
  • Real Wells Fargo pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.