<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Threat Data Feeds Phishing URL?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Phishing URL records</strong> – URLs, hosts, domains and masks covering confirmed phishing resources.<br /><strong>Actionable context</strong> – Threat type, timestamp, popularity index, geography, IP and whois.<br /><strong>Near real-time updates</strong> – New records generated continuously from Kaspersky Security Network data.<br /><strong>Open delivery formats</strong> – JSON for enterprise, plus conversion to STIX, OpenIoC and CSV.<br /><strong>HTTPS and TAXII</strong> – Token-based TAXII access for the most popular feeds.<br /><strong>Important</strong> – No management console, no agent and no built-in reporting.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Threat Data Feeds Phishing URL?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Threat Data Feeds Phishing URL is a machine-readable feed of confirmed phishing URLs and URL masks, published as one of more than 25 feeds in the Kaspersky Threat Intelligence range. It has no console and no agent: you download the data over HTTPS or TAXII and your own SIEM, firewall or gateway performs the matching.<br /><br /><strong>Proxy log matching</strong> – Check web and mail logs against confirmed phishing URLs.<br /><strong>Faster alert triage</strong> – Context fields answer who, what and where per record.<br /><strong>Lower SIEM load</strong> – CyberTrace matches events before they reach the SIEM.<br /><strong>Deny list feed</strong> – Dynamically updated block lists for firewalls and gateways.<br /><strong>No telemetry required</strong> – Kaspersky supplies text data; matching stays on your systems.<br /><strong>Vendor-neutral integration</strong> – Connectors for QRadar, Splunk, Sentinel, MISP and Suricata.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Threat Data Feeds Phishing URL suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you already operate a system that can consume indicators. A company without a SIEM, next generation firewall or web gateway has nowhere to load the feed and gains nothing from it. Organisations that run a security operations function, or a service provider that does so on their behalf, are the realistic buyers.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">SIEM or gateway able to consume indicators</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Phishing URL meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss reporting obligation does not apply to every company. Since 1 April 2025 the revised Information Security Act obliges operators of critical infrastructure, among them energy and drinking water suppliers, transport companies, listed hospitals, cloud and data centre providers and cantonal and municipal administrations, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. This feed supports that obligation at one point only: the context attached to each record, including threat type, timestamp, popularity index, top affected countries, resolved IP addresses and whois data, gives an analyst material for the initial assessment of whether a phishing hit is relevant enough to escalate. It does not detect the incident on its own, retains no evidence, and generates no report that could be submitted to BACS, because it has no console and no reporting component at all. It also covers phishing indicators only, so an attack arriving through a malicious attachment, a compromised server or stolen credentials will not appear in this feed. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Phishing URL meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures rather than software. NIS 2 requires essential and important entities to implement risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in acquisition and development, procedures for assessing the effectiveness of measures, cyber hygiene and training, cryptography, access control and multi-factor authentication. This feed contributes to incident handling, by supplying detection tools with confirmed phishing indicators and enough context to triage an alert, and marginally to the assessment of effectiveness, since matches can be counted per intelligence source. It contributes nothing to business continuity, access control, cryptography, multi-factor authentication, staff training or supply chain governance, and it produces no documentation that an auditor could accept as evidence. Treat it as one input into an existing detection stack rather than as a measure in its own right.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official measures are in force and both are worth understanding precisely, because neither covers this product in the way buyers often assume. The German Federal Office for Information Security has warned against the use of Kaspersky virus protection software since 15 March 2022; the warning remains in force and has been regulated under Section 13 of the BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a final determination on 20 June 2024 prohibiting new transactions from 20 July 2024 and signature updates, Kaspersky Security Network operation and resale from 29 September 2024 — but that determination expressly excludes Kaspersky Threat Intelligence products and services, which is the category this feed belongs to. Kaspersky rejects both assessments, states that the German warning was not based on an objective technical analysis of its software, and points to third-party audits and its transparency centres, one of which operates in Zurich. In Switzerland the Federal Office for Cybersecurity has issued no warning and no internal directive on Kaspersky products, and has stated that its technical assessment was not changed by the American ban, although Kaspersky software is no longer in use in the federal administration. In practice this matters most for public sector tenders, for companies with a German parent or German public sector customers, and for supply chain questionnaires that ask about the country of origin of security suppliers; for a privately held Swiss company running the feed inside its own SIEM, it is a procurement question rather than a technical one.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at how the two vendors compare on detection performance and feature scope.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Phishing URL help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and for a narrow set of items. It gives you a documented answer to questions about which commercial threat intelligence sources you subscribe to, how current your indicators are, how phishing indicators reach your detection tooling, and which integrations carry them, since the feed ships with connectors for QRadar, Splunk Enterprise Security, ArcSight ESM, RSA NetWitness, Azure Sentinel, MISP, Suricata and others. It answers nothing about multi-factor authentication, encryption, patch management, backup and restore testing, access control, incident response procedures, staff awareness training, business continuity or supplier risk management, and it provides no certification such as ISO 27001 or SOC 2. It will also prompt a question you may not have faced before, because many questionnaires now ask for the country of origin of security suppliers. To close the technical gaps, the cheaper route is usually to stay inside the same family, adding endpoint and detection coverage from the Kaspersky Next range and Kaspersky CyberTrace for triage, rather than assembling parts from several vendors; where the origin question is a hard requirement in your customer base, no product choice inside the family will resolve it.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Phishing URL Data Feed and Phishing URL Exact Data Feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is how records are written and what has to match them. The standard Phishing URL Data Feed uses URL masks, so a single record can cover many related phishing addresses, but masked records need the Kaspersky CyberTrace matching engine to be evaluated correctly. The Phishing URL Exact Data Feed contains exact URLs, hosts and domains instead, and is intended for direct integration into security controls and threat intelligence platforms where masks or CyberTrace cannot be used. Both carry the same context fields. If your SIEM, firewall or platform can only ingest literal indicators, the Exact feed is the one to buy.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Phishing URL Data Feed</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Phishing URL Exact Data Feed</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Record type</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">URLs and masks</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Exact URLs, hosts, domains</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">One record covers several addresses</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Needs CyberTrace matching engine</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">For masks</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Direct import into any TI platform</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Context fields included</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This feed blocks nothing on its own. Kaspersky supplies text-based records only and all matching is performed by your tools, so without a SIEM, next generation firewall, proxy or mail gateway to load them into, the data has no effect. The masked records in the standard feed need the Kaspersky CyberTrace matching engine, and the free Community Edition of CyberTrace is capped at 250 events per second and one million loaded indicators across all sources, which the paid edition removes — a follow-up purchase that catches buyers out more often than any other. Coverage is confined to phishing web resources: malicious URLs, ransomware URLs, botnet command and control addresses, file hashes and vulnerabilities are separate feeds in the same range, each bought individually. No regional feature restriction applies to this feed itself, and it sits outside the American prohibition on Kaspersky cybersecurity software, but the German warning and public sector procurement rules described above may still rule the vendor out for some buyers regardless of technical fit.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in protection stops and why detection layers such as threat intelligence are added on top.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Threat Data Feeds Phishing URL</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky CyberTrace have to be paid for separately?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">CyberTrace is available in a free Community Edition, but it processes a maximum of 250 events per second and loads up to one million indicators from all threat intelligence sources combined, and it defaults to demo feeds with lower detection rates. Running commercial feeds such as this one in a production network requires the paid edition, which also adds multi-user and multi-tenancy handling for service providers.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What data does your organisation send to Kaspersky when using this feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">None for the purpose of matching. Your systems download the feed over HTTPS or TAXII and compare it against your own logs locally, so the URLs and events being checked never leave your infrastructure. This is the main structural difference between a data feed and an endpoint product that reports telemetry back to the vendor.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the feed be used to block traffic automatically?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, provided your equipment supports it. The records can be turned into a dynamically updated deny list for a next generation firewall, secure mail gateway or web gateway, or matched through network traffic analysis. The blocking decision and its enforcement remain entirely with your own device.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-email,sec-edr,compliance-supplier" data-audience="b2b" data-count="3"> </div>