A freshly registered PhaaS platform impersonates Allegro Lokalnie — Poland's largest marketplace (21M users) — via an account-restriction social engineering lure. Victims are routed to a fake "Verification Portal" that collects Visa, Mastercard, PayPal and Google Pay credentials. 3,309 URLs verified live by PhishTank on the day of investigation. The platform uses Cloudflare in a dual role: hosting (Cloudflare Pages) and bot protection (CF Bot Management), simultaneously enabling the phishing and blocking all automated research and takedown signals.
Domain seized. Following this report, NameSilo placed basicmodoralo.com on ClientHold status (ticket #468369) within 24 hours of submission. DNS now returns zero A records and all HTTP connectivity is dead. All 3,309 PhishTank-verified phishing URLs are offline. The full platform — including mx, go, track, admin, panel, and api subdomains — has been neutralised. NameSilo's response: "Thank you for reporting domain: basicmodoralo.com. We have placed the domain on ClientHold status."
The campaign entry domain allegrolokalnie.help was registered on 2026-08-15 — one day before this investigation — through Global Domain Group LLC, a registrar used consistently across the phishing domain cluster. The domain resolves to Cloudflare (188.114.96.3) and serves a single purpose: HTTP 302 redirect to the phishing platform.
The redirect target is basicmodoralo.com/mx/n/1855468643 from datacenter IPs, and basicmodoralo.com/n/438227451786911 from Belgian residential IPs — confirming geographic routing in the TDS layer. The /mx/ prefix routes non-EU traffic; Belgian IPs drop directly into the /n/ namespace.
basicmodoralo.com was registered on 2026-08-04 through NameSilo with PrivacyGuardian.org shielding the registrant identity. Within 12 days of registration it is operating at scale as a full phishing-as-a-service platform. All infrastructure sits behind Cloudflare Pages (188.114.96.2 / 188.114.97.2) with Cloudflare Bot Management blocking all automated access.
Six operational subdomains are exposed via DNS — each serving a distinct operational function: traffic routing, redirect shortening, victim tracking, operator admin, campaign management, and backend API. This mirrors the architecture of established PhaaS platforms and indicates a purpose-built operation, not a single-campaign deployment.
PhishTank — the largest crowdsourced phishing verification database — lists 3,309 verified live URLs targeting Allegro as of 2026-08-16. All follow a consistent naming pattern: allegro[lokalnie].[random-string].[tld]. The TLD spread is broad and uses new-gTLDs that are cheap and fast to register in bulk.
/oferta/id-[slug]) delivered to victims via chat or SMS. Direct access to root returns the Apache default — the phishing page is invisible to automated scanners that don't possess the exact victim link.Accessed from a Belgian Orange residential IP (incognito browser), the phishing page at basicmodoralo.com/n/438227451786911 presents a "Verification Portal" impersonating Allegro Lokalnie. The lure is an account restriction notice with a 24-hour deadline and a deletion threat — high-urgency social engineering designed to suppress victim hesitation.
The page collects payment credentials via five brand buttons: Visa, Mastercard, Maestro, Discover, PayPal, Google Pay. Clicking any method presents a card entry form. The "Status: Waiting for verification" message creates false legitimacy — implying a backend system is actively monitoring the victim's response.
This campaign uses Cloudflare in two simultaneous roles that together create a near-impenetrable operational envelope. Role 1 — Host: The phishing platform (basicmodoralo.com and all subdomains) is deployed on Cloudflare Pages (AS13335, 188.114.96.0/24 and 188.114.97.0/24). The real origin server IP is completely masked — no reverse-IP pivot is possible. Role 2 — Shield: Cloudflare Bot Management enforces a JavaScript challenge on every subdomain, blocking all curl-based checks, automated scanners, abuse pipeline bots, and CERT tooling from ever reaching the platform.
The result: the phishing platform is simultaneously hosted by Cloudflare and protected by Cloudflare from the automated systems that would trigger its takedown. Abuse reports to Cloudflare's Trust & Safety team are the single highest-impact remediation path.
Browser screenshots taken 2026-08-16/17 from Belgian incognito Chrome reveal a previously undocumented layer: an automated support chat widget that activates on the card form page. The chat presents a scripted agent named "Emma from Customer Support" and uses two separate messages to pressure victims into entering card details.
Message 1 — Push payment lure: "The buyer has already completed the payment for the order. To receive the funds, please provide your card details and complete a one-time secure identification." This completely inverts the victim's perception — they believe they are receiving money, not surrendering card credentials. Sellers on Allegro Lokalnie are particularly vulnerable because receiving payment notifications is a normal, expected event.
Message 2 — Trust theater: "We use end-to-end encryption and fully comply with GDPR standards. No data is stored on our servers. Please stay on this page until the transfer is complete." This overcomes any remaining security hesitation and keeps the victim on the page while the card data is exfiltrated. The GDPR compliance claim is fraudulent — the platform has no legal basis to process or retain payment data.
The full card harvest form collects: 16-digit card number, expiry month/year, CVV, cardholder name — all data required for CNP (card-not-present) fraud, international wire transfers, and card cloning.
Cloudflare Trust & Safety — abuse@cloudflare.com — highest priority. Platform hosted on Cloudflare Pages, protected by Cloudflare Bot Management. Single takedown removes both host and shield.
NameSilo Abuse — abuse@namesilo.com — basicmodoralo.com registrar. Domain suspension removes the entire platform.
Global Domain Group LLC — abuse@globaldomaingroup.com — registrar for phishing entry domains (allegrolokalnie.help and cluster).
CERT Polska (CERT.pl) — cert@cert.pl — Polish national CERT. Allegro is Poland's primary e-commerce platform, making this a national-scale incident.
Allegro Security Team — security@allegro.pl — brand abuse and user alert. Allegro can push in-app warnings to 21M users and file direct platform abuse claims with Cloudflare.
EC3 / Europol — ec3@europol.europa.eu — cross-border financial fraud (Poland, EU).