AllstateOuttake
Sample finding from the Outtake platform / Allstate brand impersonation

One fabricated investment portal. Two campaign tracks. The operator mail stack behind them.

This sanitized sample finding was pulled from the Outtake platform. It shows how Outtake proactively detects an external impersonation signal, investigates the infrastructure around it, connects related campaign tracks and operator mail systems, and prepares provider-level remediation against the hosting, registrar, certificate, and mail dependencies the operation reuses. Evidence is complete for the seed. Nothing here asserts compromise of an Allstate system, and nothing has been actioned.

Recon Agent / AllstateSeed malicious / 0.98
531
CLUSTER 01 CERTIFICATES
163
CLUSTER 02 CERTIFICATES
21
NODES MAPPED
10
CONFIRMED MALICIOUS

Investigated 2026-08-24. Campaign active since May 2025.

5 suspicious nodes remain unconfirmed. 39 leads are parked.

Relationships do not establish operator identity or account compromise.

01 / What Outtake observed

One confirmed seed, two correlated infrastructure tracks, and one active lead.

This sample was pulled from the Outtake platform after Recon Agent detected and investigated the seed on 2026-08-24. The platform expanded that signal into related web, certificate, registrar, hosting, PTR, and mail evidence while preserving confidence and state. The campaign has been active since May 2025. Nothing here asserts compromise of an Allstate system.

A / MaliciousConfidence 0.98 / Active

Seed fraud portal

allstateservice[.]org

Verbatim tagline and trademark theft, a credential-harvesting login modal, investor registration, a fabricated senior team and AUM figure, dedicated Hostwinds AS54290 infrastructure, eNom registration, and a Let's Encrypt certificate issued on 2025-07-20.

B / CorrelatedConfidence 0.85 to 0.90 / Mixed

Operator infrastructure and parallel track

Relationships, not identity

PTR, registrar, hosting ASN, sequential nameserver provisioning, a January 2026 open directory observation, a 163-certificate parallel track, an active recruitment portal registered 2026-04-17, and a variant impersonating two unrelated financial institutions.

C / CorrelatedConfidence High / Active

Dedicated operator mail and click-tracking stack

OVH AS16276

A dedicated IP, 103 certificate-bearing subdomains, mail and admin services, multi-provider SPF consistent with bulk sending, and a short-URL click tracker with urlscan malicious score 85 to 86. The stack is isolated from web hosting.

D / LeadConfidence Priority 0.90 / Active

Current active node

allstateinvestigations[.]net

Certificate issued 2026-05-12 and active DNS to AWS CloudFront, a provider unlike the rest of the campaign. This remains a lead requiring full node investigation.

02 / Evidence map

Observed relationships, with state and account boundaries preserved.

Shared infrastructure, certificates, provisioning, and timing indicate relationships. They do not establish operator identity, ownership, or compromise by themselves.

allstateservice[.]org
Confirmed malicious / active
Hostwinds AS54290
Dedicated web hosting
PTR pivot
Operator mail identity
Parallel brand track
163 certificates / mixed
Operator webmail
Compartmentalized stack
OVH AS16276
Mail infrastructure
Short-URL tracker
urlscan 85 to 86
allstateinvestigations[.]net
Lead / active / 0.90
AWS CloudFront
Emerging migration target
Allstate defensive registrations
Legitimate / excluded
03 / Attribution limits

What the evidence connects, and what it does not prove.

01

Operator identity is not exposed. Seed contact details are placeholders.

02

A WHOIS state field is only a possible location signal and is not named here.

03

Five nodes remain suspicious and uninvestigated. They are not confirmed malicious.

04

Three defensive registrations are legitimate Allstate properties and are excluded from the campaign.

05

Exposure is not attribution. Co-hosting is not campaign size.

04 / Infrastructure concentration

From proactive detection to remediation at the source dependencies.

Outtake identifies where campaign infrastructure concentrates so teams can coordinate provider-level remediation against the hosting, mail, registrar, certificate, and delivery dependencies operators reuse. This is concentration intelligence, not an action list. Nothing has been actioned.

01
Hostwinds AS54290
Confirmed fraud web hosting on dedicated IPs
02
OVH AS16276
Operator email stack isolated from web hosting
03
eNom
Core fraud-domain registrar and sequential provisioning
04
Namecheap
Privacy-protected mail-infrastructure registration
05
Let's Encrypt R13
Certificate issuance supporting domain cycling
06
AWS CloudFront
Emerging infrastructure on the active lead
Immediate validation

Current active node

Priority 0.90 / Critical

Complete the unmapped AWS pivot and validate the current CloudFront-backed lead.

Further investigation

C2, recruitment, and admin paths

0.88 / 0.82 / 0.80

Investigate the suspected C2 backend and live recruitment portal. Use passive collection only for the operator admin panel and internal tooling.

Provider coordination

Dependencies the operation reuses

Evidence-led, not actioned

Prepare provider-specific evidence and coordination paths. Nothing has been actioned, and no remediation outcome is claimed.

Private platform walkthrough

See how Outtake detects the signal, maps the operation, and coordinates remediation at the source.

Review this sanitized sample finding from the Outtake platform, the proactive detection and investigation workflow behind it, and the provider dependencies that can make the operation more costly to continue. Nothing has been actioned.