Suspicious
Phishings targeting Xfinity (Comcast)
Suspicious and active websites
Phishings targeting Xfinity
Suspicious and active websites
Active
6
New (7d)
3
Trend (7d)
↑200%
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-09-01 21:30 | 2026-08-29 13:04 | ![]() |
OpenPhish | Details | |
| 2026-09-01 21:30 | 2026-08-29 01:03 | ![]() |
OpenPhish | Details | |
| 2026-09-01 21:30 | 2026-08-27 05:24 | ![]() |
GSB | Details | |
| 2026-09-01 21:30 | 2026-08-23 01:03 | ![]() |
GSB OpenPhish TweetFeed | Details | |
| 2026-09-01 21:30 | 2026-08-13 17:52 | ![]() |
urlscan | Details | |
| 2026-09-01 21:30 | 2026-08-12 23:02 | ![]() |
GSB OpenPhish urlscan | Details |
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://xfinity2.vercel.app
OpenPhish |
![]() |
Details |
| https://xfinityrefunds.com/Lo…
OpenPhish |
![]() |
Details |
| https://expert-xfinity.best
GSB |
![]() |
Details |
| http://xfinity101.duckdns.org…
GSB OpenPhish TweetFeed |
![]() |
Details |
| https://xfinitywindowfilms.com
urlscan |
![]() |
Details |
| http://xfinityservices.vercel…
GSB OpenPhish urlscan |
![]() |
Details |
AIHow to verify a real Xfinity (Comcast) URL
- Legitimate Xfinity (Comcast) URLs always end in
xfinity.com(e.g.www.xfinity.com,account.xfinity.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Xfinity (Comcast). - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
xfinity.comfrom your browser bookmark or type the domain manually. - Real Xfinity (Comcast) pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.





