Scammers use AI to create fake phishing pages of well-known brands
Cybercriminals have started to actively use artificial intelligence to create phishing pages that mimic famous brands and institutions. The new method, known as Phantom Squatting, is capable of bypassing most existing security systems.
According to a study by Palo Alto Networks’ Unit 42, attackers use large language models (LLM) to create non-existent domains systematically generated by AI. When users or developers turn to artificial intelligence for documentation or the address of a well-known service, AI often provides false information in the form of a non-existent site, known as “hallucination”.
Hackers preemptively find these popular fictional addresses and register domains on them, creating fake sites for stealing passwords and installing viruses. The key point is that these newly created sites do not have a “bad history”, so security systems do not block them, considering them to have a “zero reputation”.
Researchers have identified over 13,000 malicious links using these methods and about 250,000 names potentially suitable for phishing attacks. One example is a constantly fictional address for a well-known marketplace that attackers launched 23 days after its first detection. On the fake site, bank card data and identification documents were stolen.
In June 2026, Ukraine was included in the EU Cybersecurity Reserve, whose main goal is to counteract large-scale cyberattacks. This decision increased the level of cooperation and information exchange among EU countries in the field of cybersecurity.
| Number of malicious links | Potential names for attacks | Time of domain registration by the attacker |
|---|---|---|
| 13,000+ | 250,000 | 23 days after detection |




