Threats

Phishing

A fraudulent page or message that imitates a trusted brand in order to capture credentials, payment details or one-time codes.

Also known as credential phishing · phishing page

A phishing page is a copy of a login or checkout screen, hosted somewhere the brand does not control, built to make a victim type something they would only type into the real site. The copy is usually near-perfect, because it is literally the original HTML and CSS saved from the live site.

What makes phishing a brand problem rather than only a security problem is where the damage lands. The attacker never touches the brand's infrastructure. They rent a domain, upload a kit, send traffic to it, and every credential they collect is a customer of the brand, who will hold the brand responsible.

Detection and removal are separate jobs. Finding a phishing page is increasingly automated. Getting it offline means identifying which layer of the stack will actually act, filing an abuse report that meets that provider's evidentiary bar, and escalating when the first channel goes quiet. That is the part that takes hours or days rather than seconds.

Removing a single URL rarely ends the campaign. Kits are designed to redeploy, so a takedown that only removes today's page buys hours. A takedown aimed at the hosting and registrar layers, paired with monitoring for revival, is what ends it.

How Fraudox handles it

Phishing site takedown

See the service

Related terms

Seen this on your brand?

Send us the URL or account. We file, escalate and verify. You only pay when the content actually comes down.