700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud — Threadlinqs Intelligence
As of 2026-07-19, 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud is a medium-severity phishing threat attributed to Unknown (multiple opportunistic phishing, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1519 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
Attribution: Unknown (multiple opportunistic phishing · FINANCIAL
BforeAI's PreCrime platform tracked 701 typosquatted and lookalike domains (Nov 2025-May 2026) impersonating Chevron, ExxonMobil, Shell, Bechtel, and 20+ other energy-sector brands to run phishing,
In a report published June 23, 2026, domain-threat-intelligence vendor BforeAI (PreCrime platform) disclosed a sustained, multi-brand domain-abuse campaign targeting the oil and gas sector. Over a seven-month tracking window (November 2025-May 2026), BforeAI's predictive infrastructure-monitoring system identified 701 suspicious domains registered to typosquat or otherwise impersonate major energy companies, led by Chevron (171 domains, 24.4% of total), ExxonMobil (145 domains, 20.7%), Shell (53 domains, 7.6%), Bechtel (44), Comstock (32), Sempra (32), Motiva (26), Fluor (23), Technip (22), and Coterra (22), with additional targeting of Phillips 66, Diamondback Energy, ConocoPhillips, Kinder Morgan, and 20+ other companies across the sector.
The domains cluster into distinct abuse categories rather than a single attack pattern: HR/recruitment-fraud domains (e.g. hr-chevron.com, careerbechteljob.com, conocophillips-career.com, ngchevronrecruitment.com) harvest resumes/PII or solicit upfront 'onboarding' fees from job seekers; procurement/BEC domains (chevron-procurement.com, vendor-chevron.com, exxonmobilcontracts.com, vendor-exxonmobil.com) impersonate vendor or accounts-payable portals to redirect invoice payments or harvest supplier credentials; region-specific domains (indonesia-exxonmobil.com, chevronvenezuela.com, chevronafrica.co.za, exxonuae.com) target local subsidiaries and joint-venture staff, and project-specific domains (gorgonchevronproject.com, impersonating Chevron's Gorgon LNG facility) exploit named capital projects to lend phishing lures credibility. A smaller cluster is repurposed for e-commerce fraud (phillips66vzla.com selling counterfeit goods), gambling redirection (shellgasstations.com), and lottery/social-engineering scams (clubeshell.com 'spin-the-wheel', exxonmobilfuels.com fake loyalty program).
Infrastructure analysis shows attackers prioritize communication capability over web presence: over 85% of the 701 domains use privacy-proxy registration services (predominantly NameBright Privacy and Fundacion Privacy Services LTD) to obscure registrant identity, register almost exclusively on 1-year expiration cycles, and disproportionately favor cheap/disposable TLDs (.xyz, .top, .online, .sbs, .cfd, .store) alongside standard .com/.net and country-code variants (.de, .pl, .ar, .br, .cz, .co.za, .co.ke, .uk, .biz.id). Critically, many domains that serve no live website nonetheless maintain active MX, SPF, and DKIM records, confirming the domains exist principally to send convincing, authenticated-looking phishing/BEC email rather than to host content. At publication, only 5.6% of the tracked domains were reported as deregistered/unregistered, meaning 94.4% of the identified infrastructure remained live and actionable for defenders and takedown teams.
BforeAI assesses the campaign(s) are opportunistic and financially motivated brand-abuse operations rather than a single coordinated APT effort, most likely run by multiple independent phishing/BEC crews and domain-squatting operators exploiting the oil-and-gas sector's high public profile, complex global-subsidiary structure, and large indirect/contractor workforce. The report flags a set of predictable future activation triggers energy-sector defenders should watch for renewed domain-registration and phishing spikes around: quarterly earnings announcements, M&A activity, AI-partnership announcements, new LNG export facility news, regional expansion initiatives, OPEC+ production-policy changes, and contractor/vendor onboarding cycles.
Target sectors: energy, oil-and-gas, manufacturing, engineering-and-construction
Target regions: North America, Latin America, Africa, Middle East, Asia-Pacific, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1591.003, T1598.003, T1583.001, T1585.002, T1587.003, T1586.002, T1566.002, T1566.003, T1199, T1204.001