Suspicious

Phishings targeting Wells Fargo

Suspicious and active websites


Phishings targeting Wellsfargo

Suspicious and active websites


Active
3
New (7d)
2
Trend (7d)
↑100%
About
AIUS retail banking phishing. Standard credential, OTP, and security-question harvest, often SMS-launched.
Countries
United StatesUnited States (1) · United KingdomUnited Kingdom (1) · GermanyGermany (1)
TLS certs
ZeroSSL ECC DV SSL CA 2 (1) · YR1 (1) · YE2 (1)

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) ▾ URL Screenshot Flags Details
2026-10-11 13:03 2026-10-11 13:03
https://exodusathleticclub.com/wp-content/themes/wordpress/wordpress/…
Screenshot of exodusathleticclub.com GSB OpenPhish Details
2026-10-11 11:30 2026-10-09 17:24
https://wellsfargobank.fyi
Screenshot of wellsfargobank.fyi GSB Details
2026-10-11 11:30 2026-09-30 01:04
http://wellsfargosecurelogin.ct.ws
Screenshot of wellsfargosecurelogin.ct.ws OpenPhish Details

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://exodusathleticclub.co…
GSB OpenPhish
Screenshot of exodusathleticclub.com Details
https://wellsfargobank.fyi
GSB
Screenshot of wellsfargobank.fyi Details
http://wellsfargosecurelogin.…
OpenPhish
Screenshot of wellsfargosecurelogin.ct.ws Details

AIHow to verify a real Wells Fargo URL

  • Legitimate Wells Fargo URLs always end in wellsfargo.com (e.g. www.wellsfargo.com, account.wellsfargo.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not Wells Fargo.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open wellsfargo.com from your browser bookmark or type the domain manually.
  • Real Wells Fargo pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.