Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A 2021 Cyren report described a sharp rise in phishing URLs targeting Chase, but it does not show that Chase customers are being targeted at that rate today. The campaign matters because its reported fake login flow sought more than bank credentials—and sending a visitor to Chase’s real website afterward did not make the earlier page legitimate.

What the 2021 report found

SecurityWeek reported on October 5, 2021, that Cyren detected a 300% increase in phishing URLs targeting Chase in its own telemetry from mid-May to mid-August 2021. That figure is a relative increase in URLs observed by one security vendor during that three-month period—not a count of victims, confirmed account compromises, losses, or every phishing attempt against Chase. The report also ranked Chase as the sixth most-targeted brand in those observations; that ranking applies only to the dataset and period described, not to phishing activity today. SecurityWeek’s account of Cyren’s findings also described Chase as a close second to Office 365 among kits Cyren collected during the preceding six months.

The report identified XBALTI as a kit used against Chase and Amazon. A later 2024 ACM CCS paper excerpt also lists XBALTI among multi-target kits and includes Chase and Amazon target instances in its dataset. That later reference shows the kit name continued to appear in analysis; it does not establish that a live XBALTI campaign targeting Chase is active now, or how common it is. The paper excerpt is not evidence of a current alert.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the reported XBALTI Chase flow worked

In the example described in 2021, a fake Chase page was hosted on a compromised Brazilian website. The flow reportedly requested a Chase username and password, email credentials, additional personal information, credit-card details, and address information. After collecting submitted information, it redirected the visitor to the official Chase site. The reporting said the information was emailed to the attacker and stored in an HTML file on the compromised site. These details describe the analyzed example; they do not establish that every version of XBALTI behaves the same way.

Why a real Chase page afterward proves nothing

A redirect can happen after a fake page has already captured information. Likewise, a familiar logo or convincing design does not establish that a page belongs to Chase. If a message brought you to a login page, treat the link as untrusted even if the final screen looks genuine. Leave it, then open the Chase app or enter an address you already know is legitimate.

How to check a suspicious Chase message

  • Do not click unexpected links, open attachments, or reply with personal or account information.
  • To verify a message, contact Chase through its app, a known official website, or a phone number you already trust—not details supplied in the message. The FTC advises: “If you think the message could be legit, contact the company or bank using a phone number, email, or website you know is real.” FTC, “Protect yourself from phishing scams” (April 2025).
  • For a suspicious email claiming to be from Chase, Chase’s security guidance says to forward it to phishing@chase.com. Follow the current instructions on Chase’s protection page.
  • You can also report phishing to the FTC at ReportFraud.ftc.gov and forward suspicious email to reportphishing@apwg.org, following the organizations’ current instructions.

For more signs of phishing and ways to avoid it, see the FTC’s guide to recognizing and avoiding phishing scams.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you entered information

  1. Contact Chase promptly. Use a trusted channel, explain what information you entered, review recent transactions, and follow the bank’s instructions for securing your account. Do not use contact details from the suspicious message.
  2. Change exposed passwords. Change the Chase password and any other password you reused elsewhere. Use unique, strong passwords and enable multifactor authentication where available. CISA recommends these practices, but MFA is not a guarantee: some methods can be vulnerable to phishing, especially when a fake page asks for a one-time code. See CISA’s phishing security postcard and its guidance on implementing phishing-resistant MFA.
  3. Act on exposed identity information. If you gave out your Social Security number or other identity details, use IdentityTheft.gov for recovery steps tailored to your situation.
  4. Check your device if a file was downloaded. If clicking the link also downloaded software or a file, update your security software and scan the device, as the FTC recommends. The steps above are precautions; they do not by themselves mean your account or device was compromised. More FTC guidance is available in “What To Do if You Were Scammed”.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.