Phishing kit
Also called: phishing-as-a-service
A phishing kit is a ready-made package of fake login pages, scripts and hosting tools that lets someone launch a phishing campaign without building it. Phishing-as-a-service platforms rent these kits by subscription. Some kits capture one-time codes and session cookies as well as passwords, so they can defeat weaker MFA.
How it works
A buyer picks a template that copies a bank, email provider or company login, points a domain at it and sends the link by email or text. The kit records what victims type and can pass it to the real site in real time, letting the operator sign in before a one-time code expires.
A real example
In April 2024 Europol said the phishing-as-a-service platform LabHost provided phishing kits, page hosting and tools for engaging victims for a monthly subscription, and that at least 40,000 phishing domains were linked to it.
Source: International investigation disrupts phishing-as-a-service platform LabHost — Europol, 2024-04-18
The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Phishing-resistant MFA, such as passkeys or FIDO2 keys, cannot be relayed through a kit's fake page. Retire SMS and one-time codes as fallbacks on important accounts.
Related terms
Sources
- International investigation disrupts phishing-as-a-service platform LabHost — Europol, 2024-04-18
Last reviewed Oct 2, 2026