11 days ago
I am writing to report multiple phishing websites hosted on your infrastructure (*.railway.app). These fraudulent sites are actively impersonating Banco Exterior (legitimate website: https://www.bancoexterior.com/) to deceive users and harvest sensitive credentials.
Here is the list of the malicious deployment URLs:
https://cuentaexteriornexodigitalus.railway.app
https://cuentamucopnexoclient.railway.app
https://iniciar-nexo-digital.railway.app
https://portalnexocorp.railway.app
https://portal-mucopnexo-us.railway.app
https://cuentaexteriornexousus.railway.app
https://iniciarnexodigitalve.railway.app
https://portalnexoseguro.railway.app/
https://iniciarnexodigitalus.railway.app/
https://iniciarmucopnexove.railway.app/
Please investigate these projects and take them down as soon as possible to prevent further financial fraud and protect users.
Thank you for your prompt attention to this security matter.
Best regards,
1 Replies
Status changed to Awaiting Railway Response Railway • 11 days ago
11 days ago
Thank you for the report. We were not able to match the addresses as listed to a service on our platform, which can happen when a hostname is slightly different from the one actually in use (our service domains end in .up.railway.app).
To act on this, please reply with the full address exactly as it appears in the browser's address bar for each site, a screenshot of each page showing the login or information form, and the date and time (with timezone) you last saw each one live. If you reached these sites through a link in an SMS, email, or ad, the original link is also helpful.
Status changed to Awaiting User Response Railway • 11 days ago
4 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 4 days ago