Fictitious case. Fake Lloyds Bank email led to credential harvesting via cloned login page. £4,200 transferred from current account within minutes. IP addresses, device fingerprints and phishing infrastructure fully traced.
| Element | Finding | Risk |
|---|---|---|
| Sending domain | lloyds-banking.com — registered 2 days prior, no SPF/DKIM. Hosted on Hostinger (LT) | HIGH |
| Phishing domain | lloyds-secure-verify.com — registered 6 hours prior. Let’s Encrypt cert. Backend PHP kit “Kr3pto” | HIGH |
| Attacker IP | 185.234.XX.XX (NL, DataCamp VPS) — same IP linked to 47 other phishing domains | HIGH |
| Receiving account | Monzo — account opened 5 days prior, minimal KYC. Funds moved within 3 minutes | HIGH |
Statement of facts
I, REDACTED, report that on 22 May 2026 I was the victim of a phishing attack. A fraudulent email impersonating Lloyds Bank directed me to a cloned website where my online banking credentials and a one-time passcode were captured. The perpetrators used these to make an unauthorised Faster Payment of £4,200 from my current account.
Technical evidence
The attached forensic report identifies: the phishing infrastructure (domains, hosting, IP addresses), the phishing kit used (“Kr3pto” panel), the attacker’s access IP (185.234.XX.XX, Netherlands), and the money mule account receiving the funds. This evidence supports both a criminal complaint and a bank reimbursement claim under the CRM Code.
Generation time: ~45 seconds • Format: Print-ready PDFs • Supports bank dispute: Evidence formatted for CRM Code reimbursement claim • Updates: Free regeneration if new evidence emerges
Start your free report: within minutes you will receive a forensic investigation report and a formal statement ready to submit to the authorities.
Start your report →No obligation. You only pay if you decide to download the documents.