The zero-hour phishing gap
July 1st 2026
Grizzly vs Blocklists
Blocklists and Grizzly answer different questions. A blocklist like Google Safe Browsing answers "has this URL already been reported and confirmed malicious?" — a lookup against an accumulated list of known-bad pages. Grizzly answers "is this page phishing right now?" — a verdict computed from the page's own structure, branding, and infrastructure, with no prior reputation required. That's why a gap exists: a page that went live an hour ago can't be on a list of known-bad URLs yet — nobody's reported it — but Grizzly doesn't wait for a report; it reads the page directly. The window between a page going live and reaching a blocklist is what we measure.
Our headline claim is deliberately narrow: at the moment we flag a branded credential-phishing page, nearly half are not yet on Google's Safe Browsing list — the list that produces the red warning in a default Chrome, Safari, or Firefox. This is the protection a default-browser user has the instant a page goes live. It is not a claim that Google never catches up; some of these pages get listed eventually, most do not.
Data and methodology
The sample comes from the OpenPhish Premium feed — a third party, not filtered on Grizzly's own verdicts, so we aren't grading our own homework. We restrict to branded credential-phishing pages (the risky-intent slice). Sample: 550 pages, first seen June 18–24, 2026, each tracked for a full seven days. For each URL, at ingestion we record Grizzly's verdict and query the Google Web Risk Lookup API — which checks the same Safe Browsing threat lists that trigger browser warnings — then re-check over the following days to see whether, and when, Google catches up.
At N=550, the ingestion-gap estimate carries a margin of roughly ±4 points, so "nearly half" is a robust reading rather than a knife-edge — and it converged as the sample grew, drifting only fractions of a point over the last several hundred pages (44.5% → 45.2% → 45.3% → 44.7%). The scope is deliberate: branded credential-phishing, the risky-intent slice Grizzly acts on, is a bounded population — the relevant universe here, not all web pages — where a few hundred well-sampled pages pin the rate down.
Phishing arrives in campaigns, and a single brand can flood the feed and skew the average. So we cap each brand at 10 pages (around the 90th percentile of per-brand volume, keeping the earliest by first-seen), so no one campaign steers the headline. The cap leaves most brands untouched and only trims a couple of large bursts; the gap holds steady across nearby cap levels, so it isn't an artifact of where we draw the line.
The comparison results
| Live phishing pages (N=550) | At ingestion | After 1 day | After 3 days | After 7 days |
|---|---|---|---|---|
| Flagged by Grizzly | 92.9% | — | — | — |
| On Google's list | 55.3% | 69.8% | 70.5% | 71.3% |
The same 550 pages throughout — each first seen June 18–24 and observed for a full seven days — so every horizon is measured on one matured cohort, not a shifting sample.
The Google-coverage row is the inverse of the headline gap: Google covered 55% of these pages at ingestion, leaving 45% — nearly half — with no browser warning the moment Grizzly flagged them.
Grizzly flags these the moment they go live. Google closes most of the gap it ever will within the first day — then stalls, gaining only ~1.5 more points over the rest of the week and never reaching Grizzly's ingestion-time coverage.
What these numbers don't say
- Our sample is OpenPhish-listed pages — already reported to a feed, so the ones Google is likeliest to have. Phishing that never reaches a public feed is even less likely to be on Google's list, yet Grizzly still flags it on sight. So this number is conservative: the real-world gap is likely wider.
- The gap is durable, not a momentary head start: most pages missing at ingestion are still unlisted a day later, and most remain unlisted at seven days. One honest bound: "never listed" means within our seven-day window — a page could be listed later, and whether it ever is depends partly on how fast feeds propagate — but on this matured cohort the durability is clear, not marginal.
- This isn't a one-sided scoreboard. Grizzly missed a small minority of pages too. Of those misses, only about a third were on Google's warning list at ingestion — genuine head-to-head losses; the rest weren't on Google's list either when we saw them, which makes them hard for any detector at zero-hour rather than Grizzly-specific blind spots.
- Grizzly deliberately stays neutral on phishing that impersonates brands too obscure for confident recognition. Flagging on thin brand signal would risk false alarms on legitimate sites — and Grizzly is tuned to keep false positives low, even at the cost of missing some long-tail impersonation. These aren't detection failures; they're the system declining to guess. (Recurring regional targets get added to the profiled registry, so this blind spot shrinks over time.)
Some real examples
Xfinity credential collection
Grizzly flagged this as credential-phishing on first sight, while Google's warning list had no entry for it at scan time.

- Impersonating
- Xfinity
- URL
- https://sluehwe8ns3d.swipepages.net/xfini/
- Scanned
- June 24, 2026 · 15:22 UTC
Reasons
- DNS nameservers do not match Xfinity's known infrastructure
- TLS certificate has no organization information
- Domain is not operated by Xfinity
- Domain not registered through Xfinity's usual registrar
Coinbase Crypto Wallet Drainer
A different mechanic, same outcome. Instead of a password, this page asks you to "connect a wallet" — the on-ramp to handing over your recovery phrase, which gives an attacker total, permanent control of every asset on every chain. Grizzly flagged it on sight, reading the Coinbase impersonation straight off the page.

- Impersonating
- Coinbase
- URL
- http://ipsmedisalud.org/base
- Scanned
- June 21, 2026 · 04:16 UTC
Reasons
- Domain is not operated by Coinbase
- Domain not registered through Coinbase's usual registrar
Discussion
Blocklists work — that's why every major browser ships one. A confirmed-bad list is cheap to distribute, near-zero false positives, and catches the enormous volume of phishing that reuses known infrastructure. For the bulk of the threat, reputation is the right tool.
The limitation is structural, not a matter of effort, and it shows up as false negatives. By design a blocklist contains only what's already been reported, fetched, and confirmed — so for a page too new to have been reported, its answer is "not found." At zero-hour that "not found" is a false negative, not a clean bill of health: the page is live and harvesting credentials, it simply hasn't reached the list yet, and confirmation takes time. Google's own reason for moving Safe Browsing to real-time checks is that the average malicious site exists for under ten minutes — but a real-time lookup doesn't change what's in the list: the URL still has to reach it first. The first minutes of a page's life — when a victim clicks through from a fresh email or text — are exactly when the list is likeliest to wave a phishing page through.
And it isn't only a matter of time. If the gap were pure latency, waiting would close it — but it doesn't. Google's coverage climbs over the first day, then plateaus well short of Grizzly's and effectively stops; the pages missing at zero-hour are mostly still missing a week later. The list isn't just late — for much of this traffic, the warning never arrives within any window that matters.
This is the premise of page-level detection: Grizzly doesn't ask whether a URL has a reputation, it reads the page and decides. That trades the blocklist's near-zero false-positive rate for the harder job of judging a page on its own evidence — which is why Grizzly is tuned conservatively, accepts the long-tail blind spots above, and complements reputation systems rather than replacing them. A page already on Google's list doesn't need Grizzly; the ones it's missing — many of which it never will catch — are where the gap lives.
None of this makes blocklists obsolete. It makes them late by design — and, for most of what slips through at zero-hour, incomplete by design too: the warning comes slowly for some pages and never for most. While a page sits unlisted it reads as safe. Closing that false-negative gap is a different job.