Skip to content

CR-2026-0181 · Public sector

Lookalike domain cluster impersonating national e-services portals

Severity
High
Published

Summary

A cluster of registered domains is impersonating national digital-identity and e-services portals across several EU member states. Registration timing and shared hosting characteristics indicate a single operator preparing a coordinated phishing campaign rather than unrelated opportunistic squatting.

Who this affects

Public bodies operating citizen-facing digital identity or e-services portals, and their users.

Recommended action

  1. 01

    Monitor for newly registered domains combining your service name with common national and administrative terms.

  2. 02

    Publish and enforce DMARC at p=reject so impersonation via email is materially harder.

  3. 03

    Prepare takedown routes with your registrar and CERT in advance; time-to-takedown is decided before an incident, not during one.

Technical detail

Indicators and detection logic

The full technical package — infrastructure indicators, hashes, sender patterns and ready-to-deploy detection rules — goes to platform customers ahead of publication. If you are in an affected sector and not a customer, ask us and we will send this one anyway.