Suspicious

Phishings targeting Vodafone

Suspicious and active websites


Phishings targeting Vodafone

Suspicious and active websites


Active
4
New (7d)
3
Trend (7d)
About
AIGlobal telecom operator. Fake pending-bill or account-suspended notifications harvest webmail and account credentials, mirroring the Movistar and AT&T pattern.
Countries
United StatesUnited States (3) · RomaniaRomania (1)
TLS certs
WE1 (2) · YR2 (1) · YR1 (1)

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details
2026-09-11 15:30 2026-09-07 13:03
https://vodafoneelevation.de/vodafone/
Screenshot of vodafoneelevation.de OpenPhish Details
2026-09-11 15:30 2026-09-04 13:03
https://lonato-cc-il-leone-shopping-center.vodafone-on-line.it
Screenshot of lonato-cc-il-leone-shopping-center.vodafone-on-line.it OpenPhish Details
2026-09-11 15:30 2026-09-04 13:02
https://vodafone-on-line.it/lonato-cc-il-leone-shopping-center
Screenshot of vodafone-on-line.it OpenPhish Details
2026-09-11 15:30 2026-08-26 13:02
https://vodafone-form.mhmr.ro
Screenshot of vodafone-form.mhmr.ro OpenPhish Details

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://vodafoneelevation.de/…
OpenPhish
Screenshot of vodafoneelevation.de Details
https://lonato-cc-il-leone-sh…
OpenPhish
Screenshot of lonato-cc-il-leone-shopping-center.vodafone-on-line.it Details
https://vodafone-on-line.it/l…
OpenPhish
Screenshot of vodafone-on-line.it Details
https://vodafone-form.mhmr.ro
OpenPhish
Screenshot of vodafone-form.mhmr.ro Details

AIHow to verify a real Vodafone URL

  • Legitimate Vodafone URLs always end in vodafone.com (e.g. www.vodafone.com, account.vodafone.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Vodafone.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open vodafone.com from your browser bookmark or type the domain manually.
  • Real Vodafone pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.