Warning: Phishing Attacks Abuse Free Cloudflare Pages

KnowBe4 Team | Dec 15, 2025

phishing-website-1Malwarebytes warns that threat actors are abusing the free Cloudflare Pages service to host phishing portals, helping the phishing sites avoid detection by security scanners.

The attackers are building fake login pages impersonating banking, insurance, and healthcare entities. The pages are designed to harvest credentials as well as security questions and multifactor authentication codes.

“From the victim’s point of view, nothing seems unusual beyond an odd-looking link and a failed sign-in,” the researchers write. “For the attackers, the mix of free hosting, compromised redirectors, and Telegram-based exfiltration gives them speed, scale, and resilience.

“The bigger trend behind this campaign is clear: by leaning on free web hosting and mainstream messaging platforms, phishing actors avoid many of the choke points defenders used to rely on, like single malicious IPs or obviously shady domains. Spinning up new infrastructure is cheap, fast, and largely invisible to victims.”

Malwarebytes offers the following advice to help users avoid falling for these attacks:

  • “Always check the full domain name, not just the logo or page design. Banks and health insurers don’t host sign-in pages on generic developer domains like *.pages[.]dev, *.netlify[.]app, or on strange paths on unrelated sites.​
  • “Don’t click sign-in or benefit links in unsolicited emails or texts. Instead, go to the institution’s site via a bookmark or by typing the address yourself.​
  • “Treat surprise ‘extra security’ prompts after a failed login with caution, especially if they ask for answers to security questions, card numbers, or email passwords.​
  • “If anything about the link, timing, or requested information feels wrong, stop and contact the provider using trusted contact information from their official site.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Malwarebytes has the story.


Live Demo: Supercharge Your Anti-Phishing Defense with PhishER Plus

Email alone is the highest cause of data breaches and 56% of all attacks bypass your legacy security filters! The upshot? Legacy email security layers let these digital time bombs slip into the inboxes of your users. Introducing PhishER Plus - the most powerful anti-phishing protection available in the world.

PhishER-Plus

To learn how we can make such a claim, get a product demonstration of the new PhishER add-on, PhishER Plus. In this live one-on-one demo we will show you how you can:

  • Block email threats that have bypassed all other email security filters or systems before they reach your users’ mailboxes with the Global Blocklist
  • Isolate malicious emails that already bypassed your mail filters through automated quarantine with Global PhishRIP
  • Crowdsource threat intelligence from 10+ million KnowBe4 trained users
  • Save time and budget by reducing the volume of remediation efforts handled by your SOC Team
  • Leverage the power of triple-validated threat intelligence to protect your organization from new attacks

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/products/phisher-plus-request-a-demo



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.