Suped

Mortgage phishing uses UWM branding and fake Google sign-in pages

News
Published 21 Sep 2026
Updated 21 Sep 2026
3 min read
Summarize with
Mortgage phishing chain using UWM branding and a fake Google sign-in page
A mortgage-themed email reportedly impersonated United Wholesale Mortgage (UWM), promised closing documents and sent recipients through a hosted intermediary to servicecl[.]top, where a page posed as Google authentication.
The newly published account matters to mortgage, title, lending and real estate teams because familiar business context can make an inconsistent sender and destination easier to miss.

What the investigation found

The independent investigation was published on September 21, 2026 at 16:43:43 UTC. It describes an unrelated sender domain, UWM-branded closing language, a Lovable.app-hosted intermediary and a final fake Google sign-in page on servicecl[.]top. The sender was consistent with a compromised third-party account, but compromise was not proven.
The source does not establish SPF, DKIM or DMARC results, campaign volume, exact attack dates, successful credential theft or a breach of UWM, Google or Lovable. It also does not show that the domain remains active today.
Reported path from an unrelated sender to a fake Google sign-in page
Reported path from an unrelated sender to a fake Google sign-in page

Why authentication does not settle the request

A message can authenticate for an unrelated legitimate domain while its display name and business story claim another brand. DMARC checks whether the visible From domain matches an authenticated SPF or DKIM identity. It does not validate the claimed company, a closing request or the safety of a linked page.
Authentication boundary
Keep DMARC monitoring and enforcement as a baseline against unauthorized use of protected From domains. Do not treat DMARC as protection against every display-name impersonation, compromised account or malicious link.

Checks for operators

Treat the following as general response steps, separate from the investigation's observed facts:
  1. Correlate: Compare suspicious closing-document messages with sender domains and final link destinations.
  2. Search logs: Investigate servicecl[.]top in existing email and web logs without visiting it.
  3. Verify: Confirm document requests through known contacts or established portals.
  4. Validate: Use a DMARC checker to confirm the defensive baseline.
  5. Contain: If credential entry is confirmed, investigate and contain the affected account.
Do not block all Lovable traffic or every .top domain solely because they appear in this report. Base controls on verified indicators, context and local evidence.

Keep the controls separate

This publication reports observed activity, not a sender requirement, enforcement change or compliance deadline. Suped's product helps teams monitor DMARC, SPF and DKIM, detect source-level issues and receive real-time alerts. Those controls support authentication operations, while sender, destination and account checks cover the gaps this phishing path used.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing