The FBI has warned that cybercriminals are abusing Traffic Distribution Systems (TDSs) to silently route users through layered redirects to phishing pages, fake login portals, malware delivery sites, and other fraudulent destinations. In a Public Service Announcement issued through IC3, the bureau said attackers are funneling victims into these chains through phishing emails and links, SEO poisoning, malicious advertisements, and compromised legitimate websites, using intermediate redirect nodes to obscure the final destination and evade security controls.
The FBI said malicious TDS infrastructure can profile visitors by attributes including IP address, geography, browser, operating system, and device type, allowing criminals to selectively serve harmful content to intended targets while showing benign pages to researchers or users outside target regions. The bureau warned that resulting compromises can lead to credential theft, financial fraud, malware infections, and the resale of network access to ransomware operators, and urged organizations to strengthen defenses with multi-factor authentication, unique passwords, timely patching of CMS components and plugins, web application firewalls, endpoint monitoring for suspicious scripts, account audits, employee phishing awareness training, and incident reporting to IC3 or local FBI field offices.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
On 2026-06-18, the FBI issued a Public Service Announcement warning that cybercriminals are abusing traffic distribution systems to redirect users to phishing pages, malware delivery sites, fraudulent portals, and other malicious destinations. The alert said attackers feed victims into these chains through phishing, SEO poisoning, malicious ads, and compromised legitimate websites, and provided mitigation and reporting guidance.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.