Q1 2026 Threat Report: Financial-Services Impersonation in EMEA
Sector data on phishing campaigns targeting UK and EU banks in Q1 2026, with median takedown times by the kind of company we acted through, and where the delays build up.
* JSsec Internal Prospective Report, 2025. Case figures from the JSsec takedown desk, Jan–Mar 2026.
Financial services stayed the most heavily impersonated sector we tracked in the first quarter of 2026. Across UK and EU banks, payment providers, and investment platforms, the JSsec takedown desk confirmed and removed thousands of pages built to harvest customer credentials and payment details.
This report summarises what we saw between January and March: where the attacks concentrated, how fast we were able to bring them down, and which parts of the infrastructure stack still slow removal down.
The shape of the quarter
Volume tracked campaigns rather than a steady baseline. Confirmed impersonation pages arrived in bursts, usually clustered around statement runs, tax-season messaging, and a handful of coordinated crypto-recovery scams that reused the same kit against multiple brands.
The tactics themselves were not novel. Cloned login pages, lookalike domains one keystroke away from the real thing, and fake "account locked" flows accounted for the overwhelming majority of what we removed. What changed was the operators' willingness to rotate infrastructure quickly once a page was reported, which is why point-in-time scanning consistently missed the live window.
Where removal time goes
Takedown speed is almost entirely a function of who controls the record. When abuse sits with a registrar we already hold a pre-authenticated channel with, a confirmed case is usually actioned within minutes. When it sits behind a CDN or a deliberately unresponsive host, the same evidence can take hours or days to land.
That distribution is the single most useful thing a security team can plan around, so we have broken the quarter's cases down by infrastructure type below.
What it means for financial-services teams
Three things carried the difference between fast and slow removals: email authentication enforced to p=reject so spoofed mail never reaches customers in the first place, continuous monitoring rather than scheduled scans, and escalation paths that already exist before an incident starts.
The headline findings from the quarter, and the median removal times by infrastructure type, follow.
Figures are drawn from cases worked by the JSsec takedown desk between 1 January and 31 March 2026, covering brands in UK and EU financial services. Median times are measured from confirmed detection to the page being removed or the domain being cut off. External benchmarks are cited inline.