Suspicious

Phishings targeting Vinted

Suspicious and active websites


Phishings targeting Vinted

Suspicious and active websites


About
AIEurope's largest second-hand clothing marketplace, live in around 30 countries. Phishing mimics the buyer/seller shipping-label or 'balance withdrawal' flow to harvest card data outside Vinted's own payment system.
Countries
United StatesUnited States (1)
TLS certs
WE1 (1)
Historical record. phishunt is not tracking any active Vinted phishing site right now; the 1 entry below is from the 365-day archive (sites taken down, cleaned up, or otherwise inactive). Use them for retrospective analysis, not as a current threat-feed signal.
First seen URL IP Cert Detail
2026-08-29 https://vinted.pl-65445.lol/playstation-5-1t-digital/53164 172.67.149.197 WE1 View →

AIHow to verify a real Vinted URL

  • Legitimate Vinted URLs always end in vinted.com (e.g. www.vinted.com, account.vinted.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Vinted.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open vinted.com from your browser bookmark or type the domain manually.
  • Real Vinted pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.