New BEC in the Financial Services Sector Threat Report Finds Nearly 4000 Malicious Domains in Q2 2025 

BforeAI has released its new threat report analyzing BEC in the financial services sector, finding 3756 suspicious and newly registered domains in April, May, and June of this year.

In Q2 2025, BforeAI observed 

  • Top 3 registrars: GoDaddy.com, LLC, Dynadot Inc., Tucows Domains Inc.
  • Top 3 registering countries: United States, China, United Kingdom
  • Top 5 TLDs (Top Level Domains): .com (1992), .info (260), .xyz (203), .online (105), .icu (104)
  • Finance-based TLDs: .finance, .financial, .money, .loan, .cash, .fund, .credit, .cards, .accountant, .bank, .investments, .capital, .exchange, .market, .insurance

Domain registration trends throughout the quarter showed a notable spike in activity, especially targeting financial brands. 

April saw a high volume of registrations, followed by a slight dip in May, and then a sharp rise in June, especially towards the end of the month. 

June also recorded the highest number of domain registrations overall. Between June 22 and June 30, 2025, there were at least 22 domains registered daily, peaking at 81 registrations on June 27 alone.

Beyond this, a consistent count of 10 or more newly registered domains was observed daily, with fluctuations continuing through the end of the quarter.

This sudden surge could indicate a sign of preparation for upcoming seasonal retail sales or early travel-related promotions, during which many financial institutions roll out offers and rewards, making this period a prime target for cybercriminals looking to spoof legitimate offers.

You can read the report here: https://bfore.ai/report/bec-in-the-financial-services-sector/

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading