Table of contents
What this Q2 report measures
The fixed database query returns 46,871 unique domain records. Stored detections run from 1 April through 30 June 2026. Records appear on 90 of the quarter's 91 dates; 5 June contains no stored records.
The counts below are reproducible from the current PhishDestroy database. However, they describe only domains observed by this project. They are not estimates of all phishing activity, unique victims, criminal campaigns or market share.
46,871 is the observed PhishDestroy cohort, not a global Q2 total. A date with records also does not prove every ingestion source operated continuously for the whole day.
What the current observation window contains
| Stored detection period | Unique domains | Coverage note |
|---|---|---|
| 1–30 April 2026 | 16,732 | Records exist on all 30 calendar dates. |
| 1–31 May 2026 | 7,405 | Records exist on all 31 calendar dates. |
| 1–30 June 2026 | 22,734 | 5 June contains no stored records; the other 29 dates contain records. |
| Observed cohort total | 46,871 | Project observations; not a global Internet total. |
Zero rows on a date can mean zero observations, an import gap or a collection interruption. Without a source-by-source ingestion ledger, we cannot infer which explanation applies. This report therefore calls those dates “dates with no stored records,” not “days with no phishing.”
Field availability in the observed cohort
The following values describe database coverage when queried on 4 August 2026. Enrichment may have occurred after the original detection, so these are not point-in-time Q2 vendor verdicts.
| Stored field or evidence | Records populated | Interpretation |
|---|---|---|
| URLScan evidence identifier | 38,052 / 46,871 | A stored browser-scan identifier indicates evidence availability, not an independent phishing verdict. |
| Abuse report count above zero | 18,147 / 46,871 | A positive count records at least one report. It does not measure recipient action. |
| Google Safe Browsing check timestamp | 46,797 / 46,871 | A check was stored; the count does not state how many were flagged. |
| VirusTotal check timestamp | 46,871 / 46,871 | A query was stored; a checked record is not necessarily detected. |
| Usable registration creation date | 43,663 / 46,871 | Registration-age analysis must exclude the remaining unknown dates. |
| Age at detection from 0 to 30 days | 30,999 / 46,871 | Computed only where creation is not later than detection. Age supports triage; it is not the phishing verdict. |
| Known registrar value | 45,473 / 46,871 | Placeholder and empty values are excluded. |
| Target brand populated | 22,853 / 46,871 | Absence means no stored brand value, not that no brand was impersonated. |
These coverage numbers are useful for planning a release. They are not suitable for vendor-performance comparisons because the table does not measure consistent observation time, submission policy or detection latency across vendors.
How the cohort was produced
The cohort uses the stored first-detection field, a half-open UTC-style date interval and domain-level deduplication:
start: detected_at >= 2026-04-01 00:00:00
end: detected_at < 2026-07-01 00:00:00
unit: one distinct lowercase domain
query executed: 2026-08-04What is counted
- one stored row for each unique domain returned by the date predicate;
- the timestamp when the record entered PhishDestroy, not the unknown start of the criminal campaign;
- domain records, not URLs, screenshots, individual pages, victims or threat-actor groups.
What was not inferred
- missing dates were not filled using averages;
- unchecked vendors were not converted to zero detections;
- current site status was not treated as the status at detection;
- missing brand, registrar or registration fields were not generated by a language model;
- the cohort was not extrapolated to global Internet prevalence.
What can and cannot be concluded
The current database query returns 46,871 unique domains between 1 April and 30 June.
Whether every source operated continuously on dates that contain records.
A global Q2 total, market share, victim count or quarter-over-quarter trend.
The cohort supports data-engineering work, field-coverage review and case-level research. It also supports an exact headline about PhishDestroy observations. It does not support a claim about all global phishing.
Release criteria for a fixed Q2 extract
A downloadable, immutable Q2 data release should be generated only after the following checks pass:
- Explain the date with no stored records. Reconcile 5 June against each ingestion source and job log.
- Verify collection continuity. A date containing records does not by itself prove that every input operated normally.
- Freeze an immutable export. Assign a version, checksum, extraction time and stable download location.
- Preserve source lineage. Distinguish upstream source identifiers from source systems and document deduplication.
- Separate event-time and current fields. Status, vendor results and enrichment collected later must be labeled by observation time.
- Run quality checks. Validate timestamps, registered-domain parsing, duplicate handling, placeholders and impossible creation dates.
- Publish denominators. Every percentage must identify the eligible records, missing fields and calculation.
Future versions can add source-level continuity analysis and a fixed downloadable extract while preserving this method and change log.
Reuse, citation and corrections
The live DestroyList dataset is published separately under the project's CC0 1.0 public-domain dedication. This page does not provide a fixed Q2 download; the values are direct query results and can change if records are corrected or backfilled. Cite the query date with any reuse.
Recommended citation:
PhishDestroy Research (2026). Crypto Phishing Q2 2026: Observed Data and Methodology, version 1.1. Published 4 August 2026. https://phishdestroy.io/reports/crypto-phishing-q2-2026/
Corrections should identify the disputed value, the query or source record used for comparison and the proposed correction. Material changes will update the modification date and the visible release note.
Review the current dataset documentation and licensing. Live totals may differ from this query-dated cohort.
Data documentation and standards
Scope, project data and access information for the live dataset.
Project-specific evidence, reporting, classification and appeal information.
Registration-data event definitions used when interpreting domain creation and re-registration timestamps.
Primary documentation for interpreting the aggregated vendor results stored in the cohort.
Primary documentation for URL checks against Google-maintained unsafe-resource lists.
Primary documentation for browser-scan identifiers, screenshots, final pages and result metadata.