unphish
unphish unphish

Platform Phishing: When Trusted Infrastructure Becomes the Attack Vector

Platform Phishing

The domain is legitimate. The SSL certificate is real. The hosting provider is one of the most trusted names in tech.

And it’s still phishing.

This is platform phishing: attackers deploying malicious content directly on legitimate cloud platforms rather than registering their own domains. No registrar to report to. No obviously suspicious infrastructure. Just a phishing page sitting on a subdomain that inherits the trust of a major provider.

It’s becoming one of the fastest-growing enforcement challenges we deal with.

What Is Platform Phishing?

Platform phishing occurs when attackers host malicious content directly on legitimate Platform-as-a-Service (PaaS) providers instead of purpose-built domains. Think GitHub Pages, Firebase, Google Sites, Weebly, Vercel, Cloudflare Pages, or Shopify. The phishing content typically sits on the platform’s own subdomain (e.g., brand-login.vercel.app), and in some cases the platform infrastructure is used purely as a redirect layer pointing to a separate malicious domain rather than hosting the phishing content itself.

The scale of this is no longer a fringe tactic. Kaspersky identified more than 390,000 phishing attacks exploiting legitimate cloud platforms over the past 12 months, using services including Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to run multi-stage attacks designed to steal credentials and bypass MFA.

Why Attackers Do This

The industry calls it “inherited trust.” Threat actors select these platforms for much the same reasons legitimate developers do: they’re fast to deploy, come with automated SSL certificates, and inherit the reputation of the parent domain. A phishing page hosted on a trusted provider’s subdomain looks nothing like a suspicious, newly registered domain to most security tools.

The numbers back this up clearly. 43% of phishing campaigns now use legitimate cloud service links specifically to bypass security filters. And in one of the starkest data points, Cloudflare’s network alone fronted 39% of phishing sites in Q1 2026, largely because its DNS proxy hides the true origin of the malicious content behind a widely trusted domain.

Free tier access appears to be a major driver as well. Deploying on most of these platforms costs nothing, requires minimal verification, and can be spun up in minutes. For an attacker running high-volume, disposable infrastructure, that combination is hard to beat.

How It Differs From Dedicated Phishing Domains

Dedicated phishing domains are registered specifically for fraud, giving investigators a clear WHOIS trail, a dedicated IP, and a single enforcement target: the registrar.

Platform phishing removes most of that. There’s no domain registration to trace. The phishing content sits on infrastructure owned by a legitimate, often massive, technology company. The enforcement target shifts from “who registered this domain” to “who do we contact at this platform.”

Here's the difference:

Dedicated domain: brand-secure-login.com registered through a small registrar, easy to identify ownership and escalate

Platform phishing: brand-secure.vercel.app hosted on Vercel's infrastructure, no registrar involved, enforcement depends entirely on the platform's own abuse process

The Enforcement Challenge

This is where platform phishing gets genuinely difficult to action consistently.

Reporting goes to the platform first. Every provider has a different abuse reporting process, and not all of them are straightforward. Some have dedicated abuse forms. Others require digging through documentation to find a contact method at all.

Response times vary wildly. Some platforms act within hours. Others take weeks. A number will only act if the abuse report is submitted through their specific required format, meaning a technically accurate report can still get ignored if it doesn’t follow their process exactly.

Escalation is a fallback, not a first step. If the platform doesn’t respond, the next move is escalating to the underlying registrar or hosting provider tied to the platform itself. This adds time and complexity to what should be a straightforward takedown.

Detection relies on monitoring, not distribution tracing. Unlike dedicated phishing domains, which are often traced through a visible distribution chain (email, SMS, Meta ads), platform phishing cases are typically surfaced through active monitoring and client reporting rather than tracked through how victims are reaching the page. This makes continuous content and brand monitoring essential, since these pages won’t always announce themselves through the usual distribution warning signs.

Example From the Field

We investigated a case involving a fake financial services login page hosted directly on a major PaaS provider’s free-tier subdomain. The page was a near-perfect clone of a legitimate login portal, complete with matching branding and a working credential submission form.

Because the phishing page lived on the platform’s own trusted domain, it sailed past multiple automated security scans that would have flagged a standalone phishing domain immediately. The takedown required contacting the platform’s abuse team directly rather than a registrar, and resolution time depended entirely on how quickly their internal team actioned the report.

This is increasingly the norm rather than the exception.

Key Takeaways

Platform phishing exploits something dedicated phishing domains can’t: borrowed credibility. When the phishing content lives on infrastructure belonging to a name your security tools already trust, traditional red flags disappear.

Enforcement means knowing each platform’s abuse process in advance, submitting reports in the exact format required, and treating registrar escalation as a backup rather than a starting point. It also means accepting that detection will often come from client reports and scanning rather than a traceable distribution chain and building monitoring around that reality.

The infrastructure is legitimate. The intent isn’t. Knowing the difference and knowing exactly who to contact when you find it, is what separates a fast takedown from a phishing page that sits live for weeks.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account