RESEARCH DATASET

PhiShark 2026: A Research Dataset for Phishing Website Analysis

Created byFurkan ÇolhakatPhiShark ↗

Description

PhiShark 2026 is a hosting-aware phishing website dataset created for reproducible cybersecurity research. It contains 53,591 scan-level observations: 25,598 phishing and 27,993 benign records collected between April and July 2026.

Unlike URL-only collections, this release pairs labels with available rendered page artifacts and raw technical observations. Detector scores, model-generated explanations, and internal risk indicators are excluded from the public research package.

53,591Total observations
25,598Phishing
27,993Benign
23.97 GBCompressed size

Files

2 release components
ZIP
phishark2026dataset.zip

53,591 self-contained scan archives with raw evidence and available artifacts.

23.97 GBRestricted access
CSV
phishark2026_public_metadata.csv

Scan identifiers, labels, source, hosting category, timestamps, status, and artifact availability.

53,591 rowsIncluded with access

Archive structure

One ZIP archive per scan

Every scan is packaged independently. Availability varies by observation, and missing evidence is represented explicitly rather than inferred.

phishark2026dataset/
└── <scan_id>.zip
    ├── metadata.json
    ├── data/
    │   ├── dns.json
    │   ├── whois.json
    │   ├── ip_geo.json
    │   ├── ip_whois.json
    │   ├── ports.json
    │   ├── tls_certificate.json
    │   ├── web_page.json
    │   ├── compliance_files.json
    │   ├── redirection.json
    │   └── geo_accessibility.json
    └── artifacts/
        ├── screenshot.png
        ├── favicon.ico
        └── page.html.gz
Responsible handling notice

The archive may contain captured material and references associated with phishing observations. Use an isolated environment and do not execute captured content, visit live targets, submit forms, probe systems, or contact observed parties.

How to request access

Access applications are collected through a detailed Google Form. Applicants provide their academic affiliation, institutional contact details, research purpose, intended outputs, and secure data-handling plan. After manual approval, PhiShark provides a Data Use Agreement for signature. Google Drive Viewer access is granted only after the agreement has been completed.

ACADEMIC ACCESS

Applications are opening soon

Access requests are collected through a detailed Google Form. Approved academic and nonprofit applicants receive a PhiShark Data Use Agreement, and Google Drive Viewer access is granted after the agreement is signed.