Technology

Research-grade AI, deployed against real attackers.

Unphish turns the latest advances in machine learning, computer vision and autonomous agents into a live defense system. It reads the internet the way an attacker uses it, and takes their infrastructure apart faster than they can rebuild it.

Detection engine · live18,420 signals/sec
TIMESOURCEINDICATORSCOREVERDICT
14:02:11CT logmeridian-air-refunds.com0.994Phishing
14:02:11NRDblue-river-bakery.co0.021Benign
14:02:12Social@MeridianAirHelp0.962Phishing
14:02:12CT loglogin-meridianair.support0.931Pre-block
14:02:13AdsMeridian 90% off flights0.887Phishing
14:02:13DNSmail.acme-logistics.net0.034Benign
14:02:14Telegramt.me/meridian_refunds0.948Phishing
14:02:14CT logmeridlan-air.com0.712Watch
14:02:15App storeMeridian Rewards 2.10.905Phishing
14:02:15NRDharbor-dental-care.com0.012Benign
14:02:16CT logsecure-meridian-pay.com0.957Pre-block
14:02:16Dark webcombo list: meridian0.802Watch
1.5B+signals processed every day
200M+URLs, domains and accounts scanned daily
142 msmedian model inference per page
100+languages understood by our models
The Unphish stack

Five layers. One autonomous defense system.

Every layer is built in-house and tuned on more than a decade of real enforcement outcomes. Data flows up, decisions flow down, and every result makes the whole system smarter.

L5
Human expertiseSenior analysts review edge cases and train the models with every decision.
Analyst reviewApproval rulesFeedback labelingIncident response
L4
Autonomous actionAI agents that file, block, follow up and verify removal.
LLM enforcement agentsPlatform APIsBrowser blocklistingAuto-verification
L3
Threat GraphLinks every signal into live maps of attacker infrastructure.
Graph MLEntity resolutionCampaign clusteringActor attribution
L2
AI detectionModels that see, read and score every page, account and ad.
Vision-language modelsLLM classifiersPerceptual hashingKit fingerprintingAnomaly detection
L1
DataProprietary, real-time collection across the open and hidden internet.
Certificate transparencyNew domain registrationsPassive DNSSocial and ad librariesApp storesTelegram and dark web
01 · Multimodal detection

AI that sees a phishing page the way a victim does.

Attackers change URLs, text and code to dodge keyword filters. They can't change what the page has to look like to fool someone. Our vision-language models read the rendered screenshot, layout, logos, forms and source code together, and reach a verdict in milliseconds, in any language.

Vision-language models read screenshots, logos and layout
Works across 100+ languages and every script
Perceptual hashes catch cloned pages instantly
Kit fingerprints tie pages to known criminal tooling
https://meridian-air-refunds[.]com/login
MERIDIANlogo match 0.97
Claim your refundYour flight was cancelled. Verify your account to receive $412.60.
credential form
Visual similarity0.97
Kit signature7f3a
Lure intentrefund
Inference142 ms
VERDICTCredential phishing · 99.4% confidenceSent to enforcement
Same URL, six vantage pointsmeridian-air-refunds[.]com
New YorkMobile carrierPhishing page served
ChicagoResidential ISPPhishing page served
Los AngelesResidential ISPPhishing page served
VirginiaCloud datacenterBlank page (cloaked)
FrankfurtCloud datacenterRedirect to Google (cloaked)
SingaporeSecurity scanner404 Not Found (cloaked)
Cloaking detected: the kit hides from datacenters and bots, but serves the phishing page to US mobile and residential visitors. Verdict stands.
02 · Evasion-proof collection

Modern phishing kits hide from scanners. Ours look like victims.

Today's kits fingerprint visitors and show a harmless page to security tools. Unphish runs a distributed fleet of real browsers across residential, mobile and regional networks, so we see exactly what a targeted customer sees, and prove it with evidence.

03 · Threat Graph

Graph machine learning that exposes the whole operation.

Every detection becomes a node in a graph of attacker infrastructure. Entity resolution links domains, certificates, hosting, kits, accounts, phone numbers and wallets through shared fingerprints, so one sighting reveals the entire network behind it.

TLS fingerprint (JA4)Favicon hashKit signatureRegistrar patternHosting ASNShared analytics IDsCrypto walletPhone number
Threat Graph · Campaign MX-229163 assets · 41 removed
MX-2291networkPhishing kit · fingerprint 7f3a14 lookalike domains3 hosting providersTelegram channel2 scam ads6 fake accountsRogue APKShared registrar and SSL
Enforcement agent · case UP-48213resolved in 31 min
00:00
Threat confirmedphishing · confidence 0.994 · network MX-2291
00:01
Responsible parties identifiedhost: Cloudflare · registrar and ASN resolved
00:02
Notices drafted to each policy3 notices · evidence pack attached
00:02
Filed via APICloudflare abuse API · registrar abuse desk
00:03
Browser blocklisting submittedGoogle Web Risk · Microsoft SmartScreen
00:24
Linked assets queued13 related domains from the same kit
00:31
Removal verifiedoffline from 6 regions · case closed
04 · Agentic enforcement

AI agents that don't just alert. They act.

Our enforcement agents are large language models equipped with tools and a knowledge base of platform policies built from more than a decade of takedowns. They identify every responsible party, write the exact notice each one needs, file through APIs, block in browsers, and keep checking until the threat is gone.

05 · Predictive disruption

Stop the attack before it starts.

Attackers leave traces days before a campaign goes live. Our models watch certificate transparency logs, domain registrations and DNS changes in real time, and flag infrastructure while it is still being built.

Day 0 · 09:12Domain registeredA lookalike domain appears in registration feeds.
Day 0 · 09:14Certificate issuedA TLS certificate hits the transparency logs.
Day 0 · 09:14Flagged by UnphishModels score it 0.93 and link it to a known network.
Day 0 · 09:20Blocked pre-launchBlocklisted in browsers and reported to the registrar.
Day 2Campaign never landsThe kit goes live on a domain nobody can reach.
Continuous learning

Every attack makes Unphish smarter.

Each verdict, each analyst correction and each takedown outcome feeds back into our models. New attacker techniques seen against one customer strengthen detection for every customer, often within hours.

Senior analysts stay in the loop for edge cases. Their judgment is the training signal that keeps the AI precise.

UnphishmodelsDetectVerifyActMeasureRetrain
Unphish Labs

What we're building next.

Our government-backed research program is focused on the threats that generative AI is creating right now.

In research

Deepfake voice and video detection

Spotting synthetic executives and support agents in vishing and video-call fraud.

In research

AI-written phishing detection

Identifying lures generated by large language models at scale.

In development

Crypto wallet tracing

Following scam payments to link campaigns and actors across chains.

In development

Attacker behavior forecasting

Predicting the next targets and infrastructure a network will use.

Built for security teams

Enterprise-grade from the ground up.

Cloud-native on AzureScalable infrastructure with managed identity and no shared secrets.
Customer data isolationEach client workspace is logically separated end to end.
Encryption everywhereData encrypted in transit and at rest.
SSO and role-based accessSAML SSO, SCIM provisioning and granular permissions.
Full audit trailEvery action by people and agents is logged and exportable.
Open standardsREST API, webhooks and STIX/TAXII for every indicator.
Threats evolve. So do we.

See the technology at work on your own attack surface.

Book a 30-minute session with our engineers. We'll run the engine live against the threats targeting you.