🌐 Dark Web Watch — UK Bank Phishing Domains Detected

Sunday, 02 August 2026

Our DarkWatch dark web monitoring system detected a fresh wave of phishing domains impersonating UK banks and major brands in the last 24 hours. These are live domains — not historical examples — flagged for "high" severity with direct UK relevance.

This is the kind of threat that ends up in your texts and inbox as fake bank alerts. Here's what we found and how to stay ahead of it.

What DarkWatch detected today

336 new threat items in the last 24 hours, including a cluster of lookalike domains targeting:

Brand Detected domains (examples)
Barclays barclays-int.com, barclays4bikes.com, barclays-plc lookalikes, barclayscardsus.com
Lloyds lloydsriskgroup.com variants, lloydsfinance.com.au
HSBC hsbcshareprice.com delivery-scam variants
NatWest natwest.suite.maximo.com auth lookalike
Nationwide nationwidepeptides.st subdomain tricks
Halifax halifaxdelivery.ca fake delivery pages
Royal Mail royalmail.shipment-local.info parcel scam
Sky, BT, Vodafone billing/subscription phishing domains
PayPal, Amazon account alert phishing pages

⚠️ The pattern to understand: the domains contain the brand name but are not the brand's real website. barclays-int.com is not Barclays. royalmail.shipment-local.info is not Royal Mail. Criminals register these lookalikes daily and use them in texts, emails, and adverts.

What the criminals do with them

  1. Register a lookalike domain — containing the brand name so it passes a quick glance
  2. Build a convincing fake page — cloned login screens, delivery-tracking pages, billing alerts
  3. Send the bait — a text ("your parcel is held", "unusual activity on your account") or email with a link
  4. Harvest your details — card numbers, passwords, one-time codes
  5. Drain accounts fast — often within minutes of you entering details

How to protect yourself

  • Never click links in unexpected texts or emails — go to the brand's official app or website directly
  • Never enter card or login details on a page you reached via a message
  • Check the domain — hover over links: the real domain is barclays.co.uk, lloydsbank.com, hsbc.co.uk, royalmail.com — not a variant
  • Use the official app for banking and deliveries — real alerts appear there
  • Forward suspicious texts to 7726 — free, blocks the sender network-wide
  • Report phishing emails to [email protected]
  • Never share one-time codes — with anyone, for any reason

The most common entry scams right now

What to do if you've already clicked

  1. Call your bank's fraud line immediately — cancel the card, check for test transactions
  2. Report to Action Fraud — 0300 123 2040 or actionfraud.police.uk
  3. Get a crime reference number — see our guide
  4. Change your passwords — especially if you reused them
  5. If money was taken, act fast — see how to get your money back after a scam

About this watch

This brief comes from DarkWatch — our live dark web monitoring pipeline that tracks phishing domains, ransomware groups, and emerging threats targeting UK families and businesses. You can see the live threat board at cyberawareuk.co.uk/darkwatch.

We publish these watches when the pipeline flags significant new activity, so you hear about threats before the scam texts reach your phone.

Related guides

CyberAware UK — helping families report crime, recover from scams, and stay safe online.