<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Cloudflare Drop - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/cloudflare-drop/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Thu, 16 Jul 2026 13:58:54 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/cloudflare-drop/index.xml" rel="self" type="application/rss+xml"/><item><title>How Cloudflare Drop Turned Trusted CDNs Into Phishing Hosts</title><link>https://phishfort.com/cloudflare-drop-trusted-cdn-phishing-abuse/</link><pubDate>Thu, 16 Jul 2026 13:58:54 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/cloudflare-drop-trusted-cdn-phishing-abuse/</guid><description><![CDATA[<p>Cloudflare Drop launched on July 8, 2026. Drag a folder or a ZIP file onto <code>cloudflare.com/drop</code>, and the site is live on a <code>*.workers.dev</code> URL in seconds, with no account, no CLI, and no build step. For the first hour, the page is anonymous. No signup, no email verification, nothing tied to an identity.</p>
<p>That single design choice is why security teams need to pay attention. Trusted CDN abuse for phishing isn&rsquo;t new: Fortra recorded a 104% year-over-year jump in phishing hosted on Cloudflare Workers and a 198% jump on Cloudflare Pages, even before Drop existed. What Drop adds is speed. An attacker can now go from zero to a live, HTTPS-served, Cloudflare-branded phishing page faster than most security teams can triage an alert.</p>]]></description><content:encoded><![CDATA[<p>Cloudflare Drop launched on July 8, 2026. Drag a folder or a ZIP file onto <code>cloudflare.com/drop</code>, and the site is live on a <code>*.workers.dev</code> URL in seconds, with no account, no CLI, and no build step. For the first hour, the page is anonymous. No signup, no email verification, nothing tied to an identity.</p>
<p>That single design choice is why security teams need to pay attention. Trusted CDN abuse for phishing isn&rsquo;t new: Fortra recorded a 104% year-over-year jump in phishing hosted on Cloudflare Workers and a 198% jump on Cloudflare Pages, even before Drop existed. What Drop adds is speed. An attacker can now go from zero to a live, HTTPS-served, Cloudflare-branded phishing page faster than most security teams can triage an alert.</p>
<h2 id="why-a-trusted-domain-beats-a-convincing-fake">Why a Trusted Domain Beats a Convincing Fake</h2>
<p>Traditional phishing detection leans on domain reputation. Secure email gateways and corporate firewalls score <code>workers.dev</code>, <code>pages.dev</code>, and <code>vercel.app</code> as benign, because those domains host millions of legitimate developer projects. When a phishing link resolves to one of them, the filter checks the parent domain, sees a multibillion-dollar infrastructure provider, and lets the traffic through.</p>
<p>This is the mechanism behind a Vercel-hosted campaign that Cloudflare&rsquo;s own threat intelligence team documented running from November 2025 through January 2026. Attackers sent invoice-themed phishing emails linking to <code>vercel.app</code> pages disguised as PDF viewers or document portals, then used the pages to deliver a remote monitoring and management tool. The campaign later added a Telegram-gated delivery step specifically to filter out security researchers and sandboxes before serving the payload, evidence that the operators were actively tuning around detection.</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1784211511863-pasted-image_hu_30632e2a6e5cadf2.webp 480w, /img/1784211511863-pasted-image_hu_7f51341b56337e6.webp 768w, /img/1784211511863-pasted-image_hu_d70da14781de54eb.webp 1200w, /img/1784211511863-pasted-image_hu_18a25c2d3fef0941.webp 1600w, /img/1784211511863-pasted-image_hu_e30ffe6e4b2e9737.webp 2000w, /img/1784211511863-pasted-image_hu_2fa8b521ef44364e.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211511863-pasted-image.png"
          srcset="/img/1784211511863-pasted-image_hu_15f9ad638a844606.png 480w, /img/1784211511863-pasted-image_hu_1e89f4c6a80c0927.png 768w, /img/1784211511863-pasted-image_hu_20c3a147c7da22f1.png 1200w, /img/1784211511863-pasted-image_hu_2c0d74bf5c457b25.png 1600w, /img/1784211511863-pasted-image_hu_693cbe60252a01d.png 2000w, /img/1784211511863-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="1023"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p><a href="https://cloudflare.com/drop" target="_blank" rel="noopener noreferrer nofollow"><u><a href="https://cloudflare.com/drop" target="_blank" rel="noopener">https://cloudflare.com/drop</a>
</u></a></p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1784211527944-pasted-image_hu_75d3aa730fc1a631.webp 480w, /img/1784211527944-pasted-image_hu_da94a64ceffb2f34.webp 768w, /img/1784211527944-pasted-image_hu_32f18a06a54b8033.webp 1200w, /img/1784211527944-pasted-image_hu_c0e6e325666ac98d.webp 1600w, /img/1784211527944-pasted-image_hu_917fe48c5376368b.webp 2000w, /img/1784211527944-pasted-image_hu_fdf01d43c77e9f97.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211527944-pasted-image.png"
          srcset="/img/1784211527944-pasted-image_hu_689b7e8752bd3807.png 480w, /img/1784211527944-pasted-image_hu_b37a3b8b5f0e5b66.png 768w, /img/1784211527944-pasted-image_hu_2f8ea299937598c9.png 1200w, /img/1784211527944-pasted-image_hu_9f78bc9b428f2e1e.png 1600w, /img/1784211527944-pasted-image_hu_14aa20e1ec681e41.png 2000w, /img/1784211527944-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="828"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p><a href="https://vercel.com/drop" target="_blank" rel="noopener noreferrer nofollow"><u><a href="https://vercel.com/drop" target="_blank" rel="noopener">https://vercel.com/drop</a>
</u></a></p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1784211539888-pasted-image_hu_c86b3ca7fd1b719d.webp 480w, /img/1784211539888-pasted-image_hu_5142764a28d526b5.webp 768w, /img/1784211539888-pasted-image_hu_67e75369b2304f1.webp 1200w, /img/1784211539888-pasted-image_hu_d553612575229ae3.webp 1600w, /img/1784211539888-pasted-image_hu_cc0f398f798129ad.webp 2000w, /img/1784211539888-pasted-image_hu_de564c51ee0db9d2.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211539888-pasted-image.png"
          srcset="/img/1784211539888-pasted-image_hu_f8b29368ee0b0cb4.png 480w, /img/1784211539888-pasted-image_hu_13f16c0ce474dccb.png 768w, /img/1784211539888-pasted-image_hu_6b40f67f045745fe.png 1200w, /img/1784211539888-pasted-image_hu_668695a376141ed7.png 1600w, /img/1784211539888-pasted-image_hu_22a00be721772efb.png 2000w, /img/1784211539888-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="1196"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p><a href="https://app.netlify.com/drop" target="_blank" rel="noopener noreferrer nofollow"><u><a href="https://app.netlify.com/drop" target="_blank" rel="noopener">https://app.netlify.com/drop</a>
</u></a></p>
<h2 id="the-takedown-gap">The Takedown Gap</h2>
<p>Deployment now takes seconds. Takedown does not move at the same speed, and that mismatch is the real vulnerability.</p>
<p>An anti-phishing team publicly documented its own attempt to report abuse through Cloudflare&rsquo;s API on the same day Drop launched. Using a properly scoped token with account-level trust and safety permissions, every request to the abuse-reporting endpoint returned an HTTP 401 authorization error. The team&rsquo;s support ticket was met with an automated reply directing them to a manual web form instead. Cloudflare does operate a Trusted Reporter program with elevated access, but as of publication that program is scoped to child-safety organizations reporting CSAM, not phishing.</p>
<p><em>Industry estimate: across comparable free-tier hosting abuse cases tracked in 2025 to 2026, the gap between a phishing page going live and a takedown request being actioned has commonly run into hours, sometimes longer when reporting channels require manual review rather than an authenticated API.</em></p>
<h2 id="what-this-looks-like-at-scale">What This Looks Like at Scale</h2>
<p>A simple query on a platform like urlscan.io for pages hosted on <code>workers.dev</code> or <code>pages.dev</code> with a malicious verdict turns up a consistent pattern across three categories:</p>
<table>
  <thead>
      <tr>
          <th>Abuse type</th>
          <th>What it looks like</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Credential phishing</td>
          <td>Near-identical replicas of banking logins, Microsoft 365 portals, and Adobe sign-in pages</td>
      </tr>
      <tr>
          <td>Malware delivery</td>
          <td>RMM tools and executables disguised as invoices or shipping documents</td>
      </tr>
      <tr>
          <td>Command and control relays</td>
          <td>Edge routing used to pipe stolen data back to the attacker</td>
      </tr>
  </tbody>
</table>
<p>None of this requires the attacker to buy or register a domain. The infrastructure, the TLS certificate, and the reputation all come free with the platform.</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1784211665295-pasted-image_hu_1dd09f64a373c8e4.webp 480w, /img/1784211665295-pasted-image_hu_8f33ac8f749d284a.webp 768w, /img/1784211665295-pasted-image_hu_2d454ff519885ed8.webp 1200w, /img/1784211665295-pasted-image_hu_8bb0a28bc7040273.webp 1600w, /img/1784211665295-pasted-image_hu_4b9f393e799f6734.webp 2000w, /img/1784211665295-pasted-image_hu_52c1343b235a7080.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211665295-pasted-image.png"
          srcset="/img/1784211665295-pasted-image_hu_2772ca1b1607a898.png 480w, /img/1784211665295-pasted-image_hu_60c281bff54748da.png 768w, /img/1784211665295-pasted-image_hu_85c116d90b885e10.png 1200w, /img/1784211665295-pasted-image_hu_c379887968fa3d2b.png 1600w, /img/1784211665295-pasted-image_hu_b75ca38a2bdb51e6.png 2000w, /img/1784211665295-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="876"
          
          loading="lazy"
          >
      </picture>
    
  


















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1784211683461-pasted-image_hu_c493d3675a201d69.webp 480w, /img/1784211683461-pasted-image_hu_2c465d7f409349a1.webp 768w, /img/1784211683461-pasted-image_hu_11110ddb8ed9a5e5.webp 1200w, /img/1784211683461-pasted-image_hu_cc8176cc5b9ec5b.webp 1600w, /img/1784211683461-pasted-image_hu_26ad0d0076d298d5.webp 2000w, /img/1784211683461-pasted-image_hu_ce431b06064cc832.webp 2007w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211683461-pasted-image.png"
          srcset="/img/1784211683461-pasted-image_hu_e2e455d4c86da65e.png 480w, /img/1784211683461-pasted-image_hu_3544aed2b7940338.png 768w, /img/1784211683461-pasted-image_hu_36a732a0cd976c8f.png 1200w, /img/1784211683461-pasted-image_hu_8133bb2f774444ea.png 1600w, /img/1784211683461-pasted-image_hu_f1d56c80da39c0c6.png 2000w, /img/1784211683461-pasted-image.png 2007w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2007" height="1159"
          
          loading="lazy"
          >
      </picture>
    
  


















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1784211695515-pasted-image_hu_155fe266a783d976.webp 480w, /img/1784211695515-pasted-image_hu_45de0c4bc3ddf704.webp 768w, /img/1784211695515-pasted-image_hu_dfc070e2972505dd.webp 1200w, /img/1784211695515-pasted-image_hu_ba96be657d8febf2.webp 1600w, /img/1784211695515-pasted-image_hu_9c6be04c7d810ad3.webp 2000w, /img/1784211695515-pasted-image_hu_664fc79a67217183.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211695515-pasted-image.png"
          srcset="/img/1784211695515-pasted-image_hu_a19f15ad416e1f7a.png 480w, /img/1784211695515-pasted-image_hu_91b56872a1b97675.png 768w, /img/1784211695515-pasted-image_hu_76e99685441b66a7.png 1200w, /img/1784211695515-pasted-image_hu_72d5d996c6825cf9.png 1600w, /img/1784211695515-pasted-image_hu_773849fba9014376.png 2000w, /img/1784211695515-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="1221"
          
          loading="lazy"
          >
      </picture>
    
  


















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1784211705645-pasted-image_hu_e4ad7fae5f3858f2.webp 480w, /img/1784211705645-pasted-image_hu_708d307f1f807881.webp 768w, /img/1784211705645-pasted-image_hu_1cc122fdca34c0f4.webp 1200w, /img/1784211705645-pasted-image_hu_7fd72c2da79a5ea6.webp 1269w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1784211705645-pasted-image.png"
          srcset="/img/1784211705645-pasted-image_hu_6c392cb7d4301607.png 480w, /img/1784211705645-pasted-image_hu_33efa502d1e8b118.png 768w, /img/1784211705645-pasted-image_hu_f75392cfac5c3fc0.png 1200w, /img/1784211705645-pasted-image.png 1269w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1269" height="1191"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>No auth - just drop your zip and have it live using a global trusted CDN. Seems like a scammer&rsquo;s dream come true, doesn&rsquo;t it? Which leads to the next logical question.</p>
<h2 id="did-anyone-think-this-through">Did Anyone Think This Through?</h2>
<p>The most baffling part of this trend is the apparent surprise from the platforms themselves. It seems real-world threat actors consistently outpace internal risk assessments and red teams. The tech industry remains stuck in a cycle of &ldquo;move fast, break things, and deal with the consequences (if any) later &quot;</p>
<p>When features are shipped on pure vibes without robust, AI-driven upfront abuse detection or strict identity verification, the results are entirely predictable. It shouldn&rsquo;t take a zero-day exploit to realize that anonymous, unauthenticated web hosting will immediately be weaponized by phishers.</p>
<h2 id="the-bottom-line">The Bottom Line</h2>
<p>Lowering the barrier to entry for developers is a noble goal, but it cannot come at the expense of global web safety. Trust is the hardest currency to earn on the internet, and by turning a blind eye to immediate abuse vectors, web giants risk burning the institutional reputation they spent over a decade building.</p>
<p>Speed is great, but a 30-second verification check might be the only thing keeping the web from collapsing under the weight of its own convenience.</p>
<h2 id="so-what-security-teams-should-do-now">So, What Security Teams Should Do Now?</h2>
<ol>
<li><strong>Stop trusting the parent domain by default.</strong> Treat <code>workers.dev</code>, <code>pages.dev</code>, <code>vercel.app</code>, and similar shared subdomains as unknown reputation, not inherited trust. Route them through the same scrutiny as any newly registered domain.</li>
<li><strong>Monitor for brand impersonation on these platforms specifically.</strong> A logo, login form, or invoice template mimicking your brand can go live on infrastructure your existing domain-monitoring tools were never built to watch.</li>
<li><strong>Build a reporting path that doesn&rsquo;t depend on a single platform&rsquo;s abuse form.</strong> If a takedown request can stall behind an authorization error or a manual queue, a parallel escalation path, direct outreach, registrar-level reporting, or a specialized takedown partner, matters more than it used to.</li>
<li><strong>Educate users past the padlock.</strong> A valid HTTPS certificate and a recognizable domain no longer mean a page is safe. Phishing simulations should specifically cover this pattern.</li>
</ol>
<h2 id="faq">FAQ</h2>
<p><strong>What is Cloudflare Drop and why is it a security concern?</strong> Cloudflare Drop is a browser-based tool that publishes a live, HTTPS-served website from a dragged folder or ZIP file with no account required for the first hour. The concern is that this removes the identity and verification steps that normally slow down phishing and malware deployment.</p>
<p><strong>How does trusted CDN abuse bypass security filters?</strong> Email gateways and firewalls typically score domain reputation at the parent-domain level. A phishing page hosted on a shared subdomain like <code>workers.dev</code> or <code>vercel.app</code> inherits that parent domain&rsquo;s trusted reputation, so filters that would block a suspicious new domain let the traffic through.</p>
<p><strong>Is this only a Cloudflare problem?</strong> No. Vercel and Netlify offer similar drag-and-drop deployment and have both been documented hosting phishing and malware campaigns, though public reporting shows Cloudflare&rsquo;s free-tier products carrying the highest abuse volume.</p>
<p><strong>How can a brand find out if its identity is being impersonated on these platforms?</strong> Continuous monitoring across CDN-hosted subdomains, not just registered lookalike domains, is required, since impersonation on these platforms won&rsquo;t show up in standard domain-monitoring tools built around WHOIS and DNS registration data.</p>
<hr>
<p>Trusted CDN abuse for phishing succeeds because detection tools are still built around the assumption that a reputable parent domain means a safe page. That assumption breaks the moment deployment takes seconds and identity verification takes none. <a href="https://phishfort.com/capabilities/takedowns/" target="_blank" rel="noopener noreferrer nofollow">PhishFort&rsquo;s phishing detection and takedown team</a> monitors impersonation across CDN-hosted infrastructure, not just registered domains, so brand abuse on platforms like these gets caught and removed before it reaches your customers.</p>
<hr>
<h3 id="related-content">Related Content</h3>
<ul>
<li><a href="https://phishfort.com/hackers-target-gmail-users-via-google-calendar/" target="_blank" rel="noopener noreferrer nofollow">Hackers Target Gmail Users via Google Calendar</a></li>
<li><a href="https://phishfort.com/social-engineering-zoom-calls/" target="_blank" rel="noopener noreferrer nofollow">Social Engineering Over Zoom Calls</a></li>
<li><a href="https://phishfort.com/fake-login-pages/" target="_blank" rel="noopener noreferrer nofollow">Fake Login Pages: Detection and Risk</a></li>
<li><a href="https://phishfort.com/phishing-kits-analysis/" target="_blank" rel="noopener noreferrer nofollow">Phishing Kits Analysis</a></li>
<li><a href="https://phishfort.com/modern-phishing-techniques/" target="_blank" rel="noopener noreferrer nofollow">Modern Phishing Techniques</a></li>
</ul>
]]></content:encoded><category>Cybersecurity</category><category>phishing</category><category>security</category><category>trusted CDN abuse</category><category>Cloudflare Drop</category><category>Cloudflare Workers phishing</category><category>Vercel abuse</category><category>Netlify Drop</category><category>living off trusted sites</category><category>brand impersonation</category><category>free-tier hosting abuse</category></item></channel></rss>