Resources / Threat report
Financial Services · EMEA

Q1 2026 Threat Report: Financial-Services Impersonation in EMEA

Sector data on phishing campaigns targeting UK and EU banks in Q1 2026, with median takedown times by the kind of company we acted through, and where the delays build up.

<3%*

of domains set DMARC to block, the only setting that stops email faked from their own address.

19 min

median takedown time for domain cases across the quarter.

3,410

impersonation cases resolved for financial-sector brands in Q1 2026.

* JSsec Internal Prospective Report, 2025. Case figures from the JSsec takedown desk, Jan–Mar 2026.

Financial services stayed the most heavily impersonated sector we tracked in the first quarter of 2026. Across UK and EU banks, payment providers, and investment platforms, the JSsec takedown desk confirmed and removed thousands of pages built to harvest customer credentials and payment details.

This report summarises what we saw between January and March: where the attacks concentrated, how fast we were able to bring them down, and which parts of the infrastructure stack still slow removal down.

The shape of the quarter

Volume tracked campaigns rather than a steady baseline. Confirmed impersonation pages arrived in bursts, usually clustered around statement runs, tax-season messaging, and a handful of coordinated crypto-recovery scams that reused the same kit against multiple brands.

The tactics themselves were not novel. Cloned login pages, lookalike domains one keystroke away from the real thing, and fake "account locked" flows accounted for the overwhelming majority of what we removed. What changed was the operators' willingness to rotate infrastructure quickly once a page was reported, which is why point-in-time scanning consistently missed the live window.

Where removal time goes

Takedown speed is almost entirely a function of who controls the record. When abuse sits with a registrar we already hold a pre-authenticated channel with, a confirmed case is usually actioned within minutes. When it sits behind a CDN or a deliberately unresponsive host, the same evidence can take hours or days to land.

That distribution is the single most useful thing a security team can plan around, so we have broken the quarter's cases down by infrastructure type below.

What it means for financial-services teams

Three things carried the difference between fast and slow removals: email authentication enforced to p=reject so spoofed mail never reaches customers in the first place, continuous monitoring rather than scheduled scans, and escalation paths that already exist before an incident starts.

The headline findings from the quarter, and the median removal times by infrastructure type, follow.

Key findings
Most phishing sites sit with a small number of hosting companies and domain sellers (registrars), and that concentration is exactly what makes coordinated takedowns work.
Confirmed pages go live in bursts tied to campaigns, so scheduled scanning misses the window; monitoring has to be continuous.
Lookalike domains copying retail-bank login pages were the largest single category, ahead of fake investment portals and crypto-recovery scams.
Attackers increasingly give each victim their own link, which slows blocklists and browser warnings from spreading but makes it easier for us to tie a case to one customer.
Takedown time by where it was hosted
Where we acted
Median takedown
Share of cases
Domain seller (registrar)
19 min
41%
Shared hosting
1.8 h
33%
Content delivery network (CDN)
6.4 h
18%
Host that ignores complaints
3.1 d
8%
Methodology

Figures are drawn from cases worked by the JSsec takedown desk between 1 January and 31 March 2026, covering brands in UK and EU financial services. Median times are measured from confirmed detection to the page being removed or the domain being cut off. External benchmarks are cited inline.