Suspicious

Phishings targeting GLS

Suspicious and active websites


Phishings targeting Gls

Suspicious and active websites


About
AIEuropean parcel-delivery lure - same 'redelivery fee' pattern as DHL / DPD, concentrated in GLS's core DE/IT/ES markets.
Countries
United StatesUnited States (3)
TLS certs
YE1 (1) · Let's Encrypt (1) · Google Trust Services (1)
Historical record. phishunt is not tracking any active GLS phishing site right now; the 3 entries below are from the 365-day archive (sites taken down, cleaned up, or otherwise inactive). Use them for retrospective analysis, not as a current threat-feed signal.
First seen URL IP Cert Detail
2026-09-09 https://glsgroup.de 172.232.6.88 Let's Encrypt View →
2026-08-29 http://gls-group-pt.qpon/pt 43.162.111.113 YE1 View →
2026-08-23 https://mercedesbenz-gls-class.pages.dev 188.114.97.3 Google Trust Services View →

AIHow to verify a real GLS URL

  • Legitimate GLS URLs always end in gls-group.com (e.g. www.gls-group.com, account.gls-group.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not GLS.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open gls-group.com from your browser bookmark or type the domain manually.
  • Real GLS pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.