---
title: "What is phishing?"
term: "Phishing"
description: "A fraudulent page or message that imitates a trusted brand in order to capture credentials, payment details or one-time codes."
aliases: ["credential phishing", "phishing page"]
category: "Threats"
canonical: "https://fraudox.com/glossary/phishing"
publisher: "Fraudox"
publisher_url: "https://fraudox.com"
license: "Free to quote with attribution to the canonical URL."
---

# What is phishing?

**Phishing.** A fraudulent page or message that imitates a trusted brand in order to capture credentials, payment details or one-time codes.

*Also known as: credential phishing, phishing page.*

A phishing page is a copy of a login or checkout screen, hosted somewhere the brand does not control, built to make a victim type something they would only type into the real site. The copy is usually near-perfect, because it is literally the original HTML and CSS saved from the live site.

What makes phishing a brand problem rather than only a security problem is where the damage lands. The attacker never touches the brand's infrastructure. They rent a domain, upload a kit, send traffic to it, and every credential they collect is a customer of the brand, who will hold the brand responsible.

Detection and removal are separate jobs. Finding a phishing page is increasingly automated. Getting it offline means identifying which layer of the stack will actually act, filing an abuse report that meets that provider's evidentiary bar, and escalating when the first channel goes quiet. That is the part that takes hours or days rather than seconds.

Removing a single URL rarely ends the campaign. Kits are designed to redeploy, so a takedown that only removes today's page buys hours. A takedown aimed at the hosting and registrar layers, paired with monitoring for revival, is what ends it.

## Getting it removed

Fraudox handles this as [phishing site removal](https://fraudox.com/phishing-takedown): Credential harvesting pages and cloned login flows. Filed with the host and the registrar in parallel, and submitted to browser safe-browsing lists so visitors are warned while the page is still up.

## Related terms

- [Phishing kit](https://fraudox.com/glossary/phishing-kit): A packaged set of files that recreates a target's login page and ships the captured credentials to the operator.
- [Abuse report](https://fraudox.com/glossary/abuse-report): A formal complaint to a hosting provider, registrar or platform asking them to act on content that violates their own terms.
- [Typosquatting](https://fraudox.com/glossary/typosquatting): Registering domains that rely on predictable typing mistakes so traffic meant for a brand lands on someone else's site instead.

*Canonical version: https://fraudox.com/glossary/phishing. Part of the [Fraudox brand protection glossary](https://fraudox.com/glossary).*

---

Published by Fraudox (https://fraudox.com), a brand protection takedown service that
removes phishing sites, impersonating pages, fake social accounts, counterfeit apps,
scam domains and stolen content, and bills only for confirmed removals.
