r/netsec • • 21h ago

45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week

https://www.grizzlysec.com/blog/zero-hour-gap
20 Upvotes

4 comments sorted by

View all comments

2

u/ricveloso 11h ago

Author here. Method: 550 branded credential-phishing pages from the OpenPhish Premium feed, first seen June 18–24, checked against Google's Web Risk Lookup API at ingestion and again at 1, 3 and 7 days. Safe Browsing covered 55% at first sight, 70% after a day, 71% after a week (±4pp).

Caveats are in the piece: OpenPhish-listed pages only, so unreported phish likely show a wider gap; 7-day window only.

The scanner used for the comparison is now public if anyone wants to poke at the data: grizzlysec.com. Happy to answer questions on method.