The urlscan Threat Research Team identified a phishing site impersonating Prove , an identity verification provider, which stood out due to the notable nature of the company being targeted. A single distinctive JavaScript global variable present on the page provided an effective starting point for clustering, ultimately revealing a shared phishing framework used against a range of smaller and lesser-known financial sector brands. This brief documents the initial discovery, the pivots used to expand the cluster, and the resulting victimology, which shows a clear preference for targeting financi