izumi-finance[.]pages[.]dev
Analysis of izumi-finance.pages.dev, observed on 2026-08-03, indicates that the domain is presently active and classified as a generic phishing site under investigation. Registration data shows the domain was provisioned through Cloudflare Pages, a hosting service that often supplies shared infrastructure and can obscure the true origin of the content. The domain is listed on three public security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL blocklist providers, demonstrating that multiple independent threat-intel feeds have identified it as malicious. A VirusTotal query performed on the domain engaged 91 antivirus and sandbox engines; at the time of the scan no engine reported a detection.
The absence of detections does not constitute a safety assurance, as many phishing payloads evade static analysis and rely on dynamic interaction. No additional telemetry such as IP address, autonomous system number, geographic location, SSL certificate details, HTTP response codes, or page-title metadata is currently available in the intelligence feed. Consequently, the full scope of the infrastructure and the precise phishing campaign tactics remain uncertain.
Defenders should continue to block the domain at perimeter and endpoint layers, incorporate the three blocklist sources into their URL filtering rules, and monitor for any newly observed indicators such as DNS resolution changes, TLS certificate updates, or content hashes. Ongoing re-scans with dynamic analysis platforms are recommended to capture potential payloads that static scanners may miss. Organizations that handle financial credentials should treat any traffic to izumi-finance.pages.dev as hostile and enforce multi-factor authentication to mitigate credential compromise.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive