login-appleid[.]name
Evidence Summary
As of August 2, 2026, the domain login-appleid.name is actively flagged as a credential-phishing site targeting Apple ID users. Infrastructure analysis reveals the domain is hosted on an IP with no prior association to legitimate Apple services. Two of ninety-one security vendors on VirusTotal detect the domain as malicious, and it appears on one public blocklist, including PhishDestroy. No additional context regarding the hosting provider, autonomous system number, or SSL certificate issuer is currently available in open-source intelligence.
The domain's naming convention—incorporating 'login' and 'appleid'—strongly suggests an attempt to deceive users into submitting credentials under the guise of an official Apple authentication portal. However, the exact content of the site remains unanalyzed; no page title, phishing kit fingerprint, or brand impersonation details have been confirmed. Defenders should treat this domain as high-risk for credential theft, particularly given its inclusion on commercial phishing blocklists.
Organizations are advised to block access to login-appleid.name at the DNS or proxy level and monitor for related indicators of compromise, such as unusual Apple ID authentication attempts or post-login redirections to secondary malicious infrastructure. Further investigation into the domain's registration details and hosting history may reveal additional links to broader phishing campaigns. No evidence currently indicates the use of evasion techniques such as domain shadowing or fast-flux DNS, but this remains a possibility given the domain's recent activation.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive