Phishing that uses your brand: what to do when you find it

Someone is sending email or running a site that looks like yours to steal from your customers. What to do on day one and what makes it rarer.

3 minread 737words last updated

The short answer

Someone is sending emails that appear to come from you, or running a website that looks like yours, to steal money or credentials from your customers. That is brand phishing. Usually it is not a breach of your systems; it is abuse of your name, and it needs a fast, methodical response: confirm whether your own accounts were involved, collect evidence, report the fake domain and hosting for takedown, report to the safe-browsing lists that browsers and email providers use, warn customers through your real channels, and tighten the email authentication that makes exact impersonation of your domain much harder.

The first day

  1. Confirm the source. Get a copy of the phishing email with full headers, or the fake site’s address. Check whether the email genuinely came from your domain and passed authentication. If it did, treat it as an account compromise and follow the incident guide. If it failed authentication or came from a look-alike domain, proceed as brand abuse.
  2. Collect evidence. Screenshots, headers, the domain’s registration details, the hosting provider, timestamps. You will need them for every report.
  3. Report for takedown. The registrar of the fake domain, the hosting provider of the fake site, and the email provider the phishing was sent through, each with the evidence and a clear statement of impersonation.
  4. Report to safe-browsing programmes so browsers and email filters start warning users within hours.
  5. Warn the people at risk. A notice on your real site, an email from your authenticated domain, posts on verified profiles: what the fake looks like, what you never ask for, how to recognise the real site.
  6. Check your own authentication. SPF, DKIM and DMARC on your domain. If DMARC is not at reject, this is the moment to plan the move.
  7. Record everything. What was found, when, what was reported to whom, and the outcomes.

What reduces it happening again

MeasureWhat it does
DMARC at reject, with SPF and DKIM correctMail that claims to be from your exact domain and fails authentication is rejected by receiving servers
Look-alike domain monitoringNew registrations resembling your domain are flagged for review and takedown
Defensive registrationsOwning the most obvious variants removes the cheapest options
Consistent customer communicationCustomers know you never ask for payment changes by email alone, and know how to verify
Brand marks in emailVerified sender indicators in supporting mail clients make your real mail recognisable
A named processWho receives reports from customers, who acts, where the evidence goes

Keeping a record

A customer defrauded by someone impersonating you may look to you for answers, and occasionally for compensation. A clear record of what you found, when, what you reported and how quickly, together with evidence that your own authentication was in order, is what shows you acted responsibly. Keep it from the first hour.

What this means for you

Brand phishing will happen to any business with customers worth deceiving. Have the process ready: confirm the source, collect evidence, report for takedown and to safe-browsing lists, warn customers through real channels, and record it all. Then make it harder: DMARC at reject, look-alike monitoring, a few defensive registrations and customers who know what you never ask. The attackers move on to easier names.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

A customer received an invoice from our address with different bank details. Were we hacked?

Possibly, and you must check: if the email genuinely came from your domain and passed authentication, an account of yours may be compromised. If it came from a look-alike domain or a spoofed address that failed authentication, your systems are likely fine and your name was abused. The message headers tell you which. Treat it as a possible compromise until the headers say otherwise.

Can we get a fake website taken down?

Usually, and often within a day or two. Report it to the domain registrar, the hosting provider and the browser safe-browsing programmes, with evidence. Trademark rights help; clear proof that it impersonates your business and harvests credentials usually suffices. A partner who has done it before knows where each report goes.

How do we warn customers without causing panic?

Briefly and factually, through channels they already trust: a notice on your real website, a short email from your authenticated domain, a post on your verified profiles. Say what the fake looks like, what you will never ask for, and how to check they are on the real site. Customers appreciate the warning; silence is what damages trust.

Sources

  1. Anti-Phishing Working Group (accessed 2026-09-11)