February 2026 Phishing Report: Google Safe Browsing Missed 84% of Confirmed Phishing Sites
By
jdup7
The bagel they save for the regulars. Don't skim, savour.
Summary
Norn Labs' Huginn phishing discovery tool analyzed phishing sites in February 2026, finding that Google Safe Browsing missed 84% of confirmed phishing sites in their dataset. The report details phishing attack trends, breaks down interesting attacks, and evaluates how existing detection tools are performing. This is the first in a planned monthly series sharing findings from Huginn's active phishing discovery efforts.
Key quotes
· 4 pulledGoogle Safe Browsing missed 84% of confirmed phishing sites in our dataset.
This is the first in what we plan to be a monthly series where we share what Huginn has been finding in the wild, break down interesting attacks, and report on how existing detection tools are performing.
Our hope is that these posts are useful both as a resource for understanding the current phishing landscape and as a way to demonstrate what our tools can do.
Huginn, our active phishing discovery tool, was being used to seed Yggdrasil and that we'd have more to share soon.
You might also wanna read
Security Researchers Discover Critical XSS Vulnerabilities in Mintlify Platform Affecting Major Tech Companies
A 16-year-old hacker and his friends discovered critical cross-site scripting vulnerabilities in Mintlify, an AI documentation platform used
Edmunds Data Breach: 178,000 Records Exposed by ShinyHunters Hacking Group
In January 2026, the automotive research and car-shopping platform Edmunds was breached by the ShinyHunters hacking group. The compromised d
Project Glasswing: AI-assisted vulnerability detection finds over 10,000 critical software flaws
Project Glasswing is a collaborative effort launched to secure critical software against potential threats from increasingly capable AI mode
Project Glasswing: AI-assisted vulnerability detection finds over 10,000 critical software flaws
Project Glasswing is a collaborative effort launched to secure critical software against potential threats from increasingly capable AI mode
Iran threatens to charge undersea cable operators in Strait of Hormuz, highlighting vulnerability of global internet infrastructure
Iranian state-linked media has proposed charging operators of undersea internet cables in the Strait of Hormuz for access to what Iran claim
Google Ads to require passkeys for sensitive account actions starting July 15, 2026
Google Ads will mandate passkeys for sensitive account actions starting July 15, 2026, replacing traditional passwords with biometric or dev
