Impersonation on a third-party website

Your Website Clone Is on Someone Else’s Domain: Choose the Right Removal Route

A customer finds a copy of your login page under another organisation’s website. Keep the complete URL: the healthy homepage and harmful deep page may coexist. Identify the affected path, its customer action and the party able to change it before asking for an intervention that could disrupt the entire domain.

One imitation login page sits inside an otherwise ordinary multi-page website
A harmful page inside a legitimate website requires evidence and action at the affected path.

The hostname alone does not describe the incident

A familiar organization can have a harmful page under a long path or subdomain. The surrounding website may still operate normally. Record the full address, not only the domain, and establish whether the reported content is accessible at that exact path.

Separate three questions: what the page claims, what it asks the visitor to do and who can control the relevant content. A copied header may support an impersonation assessment, while a login form or payment request changes the immediate customer-risk question. Do not infer that the legitimate site owner created the page.

Keep the harmful path attached to the evidence

A report that names only the root domain can send a reviewer to a harmless homepage. Preserve the route from the search result or shared link to the final page, including redirects. Capture the observation time, market and device alongside the page identity.

third-party.example
Existing public website
/account/brand-login/ Reported impersonating path
The affected path is the investigation target. Its presence does not establish that every page on the hostname is abusive.

Use a non-sensitive capture. Do not test credential collection with a real account or upload identity documents. If a captured page contains personal information, keep that material out of public reports and use the agreed secure evidence process.

A healthy website homepage and ordinary page coexist with one injected account-access path
The harmful path belongs in the report even when the hostname’s main page appears normal.

Separate copying from active deception

Copied content and trademark use require their own rights and context records. A page that presents itself as the official login and collects credentials raises a different issue from an independent article reproducing a small passage. Do not describe every unauthorized copy as phishing.

Record the claimed identity, action requested, form destination where safely observable and the entry point bringing customers to the page. The brand’s rights owner can establish what was copied and whether any permission exists. Security and legal owners can assess the parts that require their authority.

Assess the Affected Page

Discuss the observed source, available evidence and next action with AdFlagger.

Assess the Affected Page

Published incident research

A legitimate page can be replaced during the visit

Microsoft’s August 2025 ClickFix research ↗ describes a campaign that used compromised legitimate websites. The original page appeared briefly before a deceptive verification surface replaced it. Microsoft identified possible WordPress vulnerabilities as a route into those sites.

This observed campaign shows why a screenshot of the homepage can miss the customer-facing behaviour. Capture the affected route and what appears during the visit; give the legitimate operator or hosting provider enough information to find the injected content. A brand clone requires its own identity and rights evidence, while this research establishes the broader compromised-site mechanism.

ICANN distinguishes malicious registrations from compromised domains

These resolved compliance cases were classified by domain context. A case may include more than one domain; the counts describe cases, rather than a domain population or removal success rate.

Scale: 0 to 200 resolved registrar cases

ICANN registrar DNS abuse report ↗. May 2024 to April 2025. Totals calculated from the twelve published monthly counts.

Identify the party that can change the page

The website operator may be able to remove an injected page. A hosting platform may control a tenant account. A host may be able to disrupt an affected service. The registrar controls the domain relationship rather than individual page content. Establish these roles before selecting the escalation path.

ICANN’s DNS abuse advisory ↗ addresses collateral damage when legitimate domains are compromised. DNS-level suspension can disrupt benign pages and other services. This makes the complete path and the affected behavior important to a proportionate assessment.

Capture the page as a bounded incident

Input
The exact deep URL, branded entry point and non-sensitive screenshot.
Check
Open the reported route without submitting credentials. Record the response, any redirect, claimed identity and visible customer action. Compare the root page only to establish surrounding legitimate use.
Interpretation
A healthy root page alongside a harmful path supports a page-level investigation. A redirect into another hostname adds a second source to the record.
Next action
Identify the operator, platform or host that controls the affected content. Assess DNS-level action separately when the facts justify it.

For copied content, preserve the exact reproduced material and rights basis. For phishing, preserve the credential request and source behaviour. Keeping those records distinct makes a provider’s request for further evidence easier to answer.

Verify the page and every remaining entry point

After action, open the original complete URL through the recorded route. A homepage that still works is consistent with successful removal of one harmful path. Conversely, a changed homepage does not establish that a deep link or hosted copy is gone.

Record the page response, redirects, search visibility and remaining customer action separately. Check related paths discovered during the investigation without inventing variants or probing private areas. Search cleanup may require follow-up after source removal; it should not be reported as the same outcome.

Escalate a precise record

The next review should have one exact target, a clear explanation of the deceptive behavior, dated evidence, the provider’s reply and the unresolved route. This is more useful than repeatedly reporting the root hostname with an unchanged screenshot.

AdFlagger can assess the source, connect the branded entry point to the affected page and coordinate the relevant takedown workflow. Continued monitoring is justified when new paths or related sources repeatedly restore the same customer journey. Preserve legitimate surrounding services when defining the requested outcome.

Questions about this assessment

Review the Copied Website