SardineCon SF/2026

Learn More

What is Phishing-as-a-Service?

SUBSCRIBE

Phishing-as-a-Service is subscription kits that hand an attacker ready-to-run phishing setups: spoofed page templates, hosting, and live capture of logins and one-time codes. They industrialize credential theft and increasingly proxy the victim's session in real time to defeat one-time passcodes.

What is Phishing-as-a-Service?

Phishing-as-a-Service, or PhaaS, is a subscription product for running phishing attacks. Instead of building spoofed pages and infrastructure themselves, buyers rent a kit that includes convincing page templates, hosting, and a back end that captures whatever the victim types, including usernames, passwords, and one-time codes.

It sits under the crime-as-a-service umbrella and its purpose is industrializing credential theft. A low-skill actor can launch a professional-looking campaign in minutes, complete with a dashboard of captured credentials. The kits handle the hard parts, so the barrier to stealing logins at scale collapses.

The most consequential feature of modern kits is the real-time proxy. Rather than just harvesting a password, the kit sits between the victim and the real site, relaying everything live. That means it can capture a one-time passcode as the victim enters it and pass it straight through, defeating a control many teams still treat as strong and feeding directly into account takeover.

How a modern kit works

A real-time proxy phishing kit runs through these stages:

  1. Lure — Send the bait. The buyer sends a message pointing to a spoofed page hosted by the kit.
  2. Relay — Proxy the session. The fake page relays every entry to the real site in real time, so the victim sees a working login.
  3. Capture — Grab the code. When the victim enters a one-time passcode, the kit captures and forwards it before it expires.
  4. Take over — Hijack the account. With the live session or token, the attacker steps into the account before the victim reacts.

What it looks like in practice

In practice

A customer gets a text about a locked account and taps the link, landing on a login page that looks exactly right. They enter their username and password, then the code from their authenticator app. The page briefly says please wait and then errors out, so they shrug and try the real app instead.

Behind the scenes, a rented phishing kit relayed every keystroke to the real site as they typed, captured the one-time code the instant they entered it, and handed the attacker a live session. Within a minute the account is accessed from a device the customer has never used, a new payee is added, and a transfer is queued. The one-time passcode did nothing, because it was harvested and used live.

Why training alone falls short

Teams have long leaned on user education to stop phishing, and awareness still helps, but the ground has shifted. When the theft happens live, mid-session, faster than a user can react, telling people to be careful is a weak backstop. The victim did nothing obviously wrong; they entered a real code into a page that looked real, and it was stolen in transit.

That is why the durable defenses are structural rather than educational. Phishing-resistant login, such as passkeys, does not hand over anything a proxy can replay, so it defeats the real-time relay by design. Alongside it, behavioral and device monitoring catches the takeover that follows: a login from an unfamiliar device, impossible-travel patterns, or session traits that do not match the real customer. Leaning on education to stop theft that now happens live is the weak spot; the fix is login that cannot be relayed and monitoring that catches the aftermath.

What to watch in the data

  • Fresh-credential logins. Successful logins using credentials that appear to have just been entered elsewhere, followed by unusual actions.
  • Impossible travel. One account authenticating from two far-apart locations in a span too short to be physically possible.
  • New device, immediate action. Access from an unrecognized device that quickly adds a payee, changes contact details, or moves money.
  • One-time code, then takeover. A passcode entered successfully followed by session behavior inconsistent with the real customer.
  • Odd session traits. Device, browser, or network characteristics that suggest a relay or proxy sitting between the user and your site.

Quick questions

How is this different from ordinary phishing?

Ordinary phishing is a one-off attacker building their own pages. Phishing-as-a-Service rents ready-made kits with hosting and capture, so anyone can run professional campaigns, and modern kits add real-time proxying.

Do one-time passcodes stop these kits?

Often no. Real-time proxy kits relay the victim's session and capture the passcode as it is entered, passing it through before it expires. That is why passkeys and other phishing-resistant methods matter.

What makes passkeys resistant?

Passkeys authenticate in a way tied to the real site and device, so there is no reusable secret or code for a proxy to relay. A relayed login simply does not produce anything the attacker can replay.

Is user training useless then?

Not useless, but insufficient on its own. When theft happens live and faster than a person can react, education is a weak backstop. Pair it with phishing-resistant login and behavioral monitoring.

How does it connect to account takeover?

Directly. The captured credentials or live session are used to hijack the account, add payees, and move funds, so a phishing kit is frequently the front end of an account-takeover scheme.

What catches the attack after the fact?

Behavioral and device monitoring. A login from a new device, impossible travel, or session traits that do not fit the customer can flag the takeover even when the credentials were valid.

Go deeper

What to know alongside Phishing-as-a-Service