Monthly Intelligence Reports
Click any month for detailed report with domain cards, registrar analysis, and AI-generated expert assessment.
So far in September 2026 (month in progress), PhishDestroy detected 12,472 phishing domains. 3,683 of them (29.5%) have already been neutralized, while 8,749 remain live and under active escalation. The most abused registrar was Dynadot Inc with 1,016 malicious domains, followed by REGISTRAR_NOT_FOUND (995). Attackers targeted Unknown hardest, with across a close second.
In August 2026, PhishDestroy detected 17,755 phishing domains, a 4.1% decrease from July. 8,524 of them (48%) have already been neutralized, while 9,125 remain live and under active escalation. The most abused registrar was NICENIC INTERNATIONAL GROUP CO., LIMITED with 1,689 malicious domains, followed by Cloudflare Pages (1,061). Attackers targeted Unknown hardest, with MetaMask a close second.
In July 2026, PhishDestroy detected 18,506 phishing domains, a 18.5% decrease from June. 8,618 of them (46.6%) have already been neutralized, while 9,590 remain live and under active escalation. The most abused registrar was NICENIC INTERNATIONAL GROUP CO., LIMITED with 2,265 malicious domains, followed by Fewmoretaps OU d/b/a Trustname.com (922). Attackers targeted Unknown hardest, with google a close second.
In June 2026, PhishDestroy detected 22,710 phishing domains, a 207% increase from May. 11,718 of them (51.6%) have already been neutralized, while 10,423 remain live and under active escalation. The most abused registrar was NICENIC INTERNATIONAL GROUP CO., LIMITED with 3,580 malicious domains, followed by Wix Studio (1,112). Attackers targeted Unknown hardest, with Trezor a close second.
In May 2026, PhishDestroy detected 7,398 phishing domains, a 55.8% decrease from April. 4,879 of them (66%) have already been neutralized, while 2,487 remain live and under active escalation. The most abused registrar was NICENIC INTERNATIONAL GROUP CO., LIMITED with 711 malicious domains, followed by Cloudflare, Inc. (644). Attackers targeted Unknown hardest, with Ledger a close second.
In April 2026, PhishDestroy detected 16,720 phishing domains, a 20.2% decrease from March. 10,893 of them (65.1%) have already been neutralized, while 5,798 remain live and under active escalation. The most abused registrar was Cloudflare, Inc. with 4,466 malicious domains, followed by Wix Studio (1,620). Attackers targeted Ledger hardest, with genericcrypto a close second.
In March 2026, PhishDestroy detected 20,962 phishing domains, a 48.1% decrease from February. 14,194 of them (67.7%) have already been neutralized, while 6,641 remain live and under active escalation. The most abused registrar was NICENIC INTERNATIONAL GROUP CO., LIMITED with 4,861 malicious domains, followed by CloudFlare, Inc. (4,340). Attackers targeted Unknown hardest, with Ledger a close second.
In February 2026, PhishDestroy detected 40,368 phishing domains, a 352.7% increase from January. 29,479 of them (73%) have already been neutralized, while 9,965 remain live and under active escalation. The most abused registrar was NiceNIC International Group Co., Limited with 8,735 malicious domains, followed by Cloudflare, Inc. (6,193). Attackers targeted Unknown hardest, with genericcloudflare a close second.
In January 2026, PhishDestroy detected 8,917 phishing domains, a 24% decrease from December. 6,777 of them (76%) have already been neutralized, while 2,080 remain live and under active escalation. The most abused registrar was NiceNIC International Group Co., Limited with 1,316 malicious domains, followed by PDR Ltd. d/b/a PublicDomainRegistry.com (972). Attackers targeted Unknown hardest, with genericcrypto a close second.
In December 2025, PhishDestroy detected 11,736 phishing domains, a 6.6% decrease from November. 8,156 of them (69.5%) have already been neutralized, while 3,513 remain live and under active escalation. The most abused registrar was NiceNIC International Group Co., Limited with 1,283 malicious domains, followed by Cloudflare, Inc. (1,144). Attackers targeted Unknown hardest, with coinbase a close second.
In November 2025, PhishDestroy detected 12,561 phishing domains, a 42.2% increase from October. 10,101 of them (80.4%) have already been neutralized, while 2,425 remain live and under active escalation. The most abused registrar was Dynadot LLC with 2,118 malicious domains, followed by Cloudflare, Inc. (1,503). Attackers targeted Google hardest, with Unknown a close second.
In October 2025, PhishDestroy detected 8,831 phishing domains, a 21.1% increase from September. 7,221 of them (81.8%) have already been neutralized, while 1,582 remain live and under active escalation. The most abused registrar was NiceNIC International Group Co., Limited with 1,206 malicious domains, followed by Cloudflare, Inc. (827). Attackers targeted Unknown hardest, with Google a close second.
In September 2025, PhishDestroy detected 7,293 phishing domains, a 92.9% increase from August. 5,770 of them (79.1%) have already been neutralized, while 1,407 remain live and under active escalation. The most abused registrar was NiceNIC International Group Co., Limited with 774 malicious domains, followed by Web Commerce Communications Limited (677). Attackers targeted across hardest, with Unknown a close second.
In August 2025, PhishDestroy detected 3,780 phishing domains, a 440.8% increase from July. 2,947 of them (78%) have already been neutralized, while 823 remain live and under active escalation. The most abused registrar was Web Commerce Communications Limited with 277 malicious domains, followed by NameSilo, LLC (254). Attackers targeted across hardest, with Unknown a close second.
In July 2025, PhishDestroy detected 699 phishing domains, a 23200% increase from June. 616 of them (88.1%) have already been neutralized, while 83 remain live and under active escalation. The most abused registrar was Web Commerce Communications Limited with 85 malicious domains, followed by NameSilo, LLC (78). Attackers targeted Unknown hardest, with across a close second.
In June 2025, PhishDestroy detected 3 phishing domains. 3 of them (100%) have already been neutralized. The most abused registrar was NameSilo, LLC with 1 malicious domains, followed by Web Commerce Communications Ltd. (1). Attackers targeted chainlink hardest, with amazon a close second.
Detection Trends
Monthly domain volume, kill rate, and live threats over time.
Monthly Detected Domains
Kill Rate %
Explore More
Related intelligence pages and data feeds.