Skip to content

Comment on Ask HN: How to get a phishing website that steals credentials taken down?

Comments

You did an impressive number of steps and follow-ups already.

If it's faking a Apple website it might help to report it to Apple, too. I reported fake bank websites to the (real) banks and they were responsive because it's in their best interest as their customers are likely the targeted audience. That would hopefully get their security team (or a project manager) on the case. I didn't follow up though how long deletion took.

Thanks to you and the other poster on this suggestion, it hadn't occurred to me that Apple will have such a reporting channel as well.

I've had good luck reporting bank/credit union phishing to the banks as well. They tend to have processes and contacts to get things taken down quickly (including toll free numbers, etc), and I'd imagine Apple does too.

Also worth finding the scammer's hosting, and DNS services and report to those abuse contacts too.

Agree with this, if the malicious site is phishing by purporting to be a corporate entity, report it to them if you can. Most of them have Brand Protection™ services on retainer which will have their own relationships with registrars and know the ICANN dispute/seizure process very well.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.