🌐 Dark Web Watch — UK Bank Phishing Domains Detected
Sunday, 02 August 2026
Our DarkWatch dark web monitoring system detected a fresh wave of phishing domains impersonating UK banks and major brands in the last 24 hours. These are live domains — not historical examples — flagged for "high" severity with direct UK relevance.
This is the kind of threat that ends up in your texts and inbox as fake bank alerts. Here's what we found and how to stay ahead of it.
What DarkWatch detected today
336 new threat items in the last 24 hours, including a cluster of lookalike domains targeting:
| Brand | Detected domains (examples) |
|---|---|
| Barclays | barclays-int.com, barclays4bikes.com, barclays-plc lookalikes, barclayscardsus.com |
| Lloyds | lloydsriskgroup.com variants, lloydsfinance.com.au |
| HSBC | hsbcshareprice.com delivery-scam variants |
| NatWest | natwest.suite.maximo.com auth lookalike |
| Nationwide | nationwidepeptides.st subdomain tricks |
| Halifax | halifaxdelivery.ca fake delivery pages |
| Royal Mail | royalmail.shipment-local.info parcel scam |
| Sky, BT, Vodafone | billing/subscription phishing domains |
| PayPal, Amazon | account alert phishing pages |
⚠️ The pattern to understand: the domains contain the brand name but are not the brand's real website.
barclays-int.comis not Barclays.royalmail.shipment-local.infois not Royal Mail. Criminals register these lookalikes daily and use them in texts, emails, and adverts.
What the criminals do with them
- Register a lookalike domain — containing the brand name so it passes a quick glance
- Build a convincing fake page — cloned login screens, delivery-tracking pages, billing alerts
- Send the bait — a text ("your parcel is held", "unusual activity on your account") or email with a link
- Harvest your details — card numbers, passwords, one-time codes
- Drain accounts fast — often within minutes of you entering details
How to protect yourself
- ❌ Never click links in unexpected texts or emails — go to the brand's official app or website directly
- ❌ Never enter card or login details on a page you reached via a message
- ✅ Check the domain — hover over links: the real domain is
barclays.co.uk,lloydsbank.com,hsbc.co.uk,royalmail.com— not a variant - ✅ Use the official app for banking and deliveries — real alerts appear there
- ✅ Forward suspicious texts to 7726 — free, blocks the sender network-wide
- ✅ Report phishing emails to [email protected]
- ✅ Never share one-time codes — with anyone, for any reason
The most common entry scams right now
- Parcel/delivery texts — see our parcel delivery scam guide
- Bank "fraud team" calls — see our vishing guide
- Bank transfer fraud — see how to get your money back after a scam
- Amazon impersonation — see our Amazon scam guide
What to do if you've already clicked
- Call your bank's fraud line immediately — cancel the card, check for test transactions
- Report to Action Fraud — 0300 123 2040 or actionfraud.police.uk
- Get a crime reference number — see our guide
- Change your passwords — especially if you reused them
- If money was taken, act fast — see how to get your money back after a scam
About this watch
This brief comes from DarkWatch — our live dark web monitoring pipeline that tracks phishing domains, ransomware groups, and emerging threats targeting UK families and businesses. You can see the live threat board at cyberawareuk.co.uk/darkwatch.
We publish these watches when the pipeline flags significant new activity, so you hear about threats before the scam texts reach your phone.
Related guides
- Smishing scams UK — fake texts explained
- Parcel delivery scam texts UK
- What is phishing and how to spot it
- The dark web explained in plain English
CyberAware UK — helping families report crime, recover from scams, and stay safe online.
CyberAwareUK