Skip to content
Securelist·

🚨Phishing Scams Exploit Cloud Services to Evade Detection

Attackers are using your favorite cloud services against you

TL;DR

Threat actors are increasingly leveraging popular cloud hosting services to host phishing pages, making them harder to detect. This trend has security teams scrambling for new methods to combat these sophisticated attacks.

Attackers are exploiting legitimate cloud services to deploy scam infrastructure and evade detection. Throughout 2025-26, phishing operators migrated to platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS due to generous free-tier plans and minimal verification requirements. These platforms make it easier for attackers to create hundreds of malicious accounts, hiding behind CDNs to obscure their true origin server IPs. Security teams can't simply block parent domains without affecting legitimate users, pushing vendors towards content-based analysis methods.

Phishing Scams Exploit Cloud Services to Evade Detection — Securelist

Key Points

1

Threat actors exploited 224,984 unique third-level domains on cloud platforms for phishing in a year-long study (Aug 2025 - Jul 2026).

2

Attackers use native CDN features to hide their true origin server IP address, complicating detection by security vendors.

3

Phishing pages hosted on reputable platforms appear more trustworthy and reduce suspicion among potential victims.

4

Cloud hosting services offer generous free-tier plans with minimal verification requirements, enabling rapid account creation.

5

Security teams must develop content-based analysis methods to combat phishing tactics leveraging cloud platforms effectively.

Why It Matters

If you're using Cloudflare Workers or GitHub Pages for your projects, be aware that these same platforms are being exploited by attackers. This trend highlights the need for robust security measures and vigilant monitoring of cloud-hosted content.

cloudphishingsecuritycloudflaregithub

Frequently Asked Questions

Why does this matter?

If you're using Cloudflare Workers or GitHub Pages for your projects, be aware that these same platforms are being exploited by attackers. This trend highlights the need for robust security measures and vigilant monitoring of cloud-hosted content.

What happened?

Threat actors are increasingly leveraging popular cloud hosting services to host phishing pages, making them harder to detect. This trend has security teams scrambling for new methods to combat these sophisticated attacks.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,646 builders reading daily.

Also get