Impersonation on a third-party website
Your Website Clone Is on Someone Else’s Domain: Choose the Right Removal Route
A customer finds a copy of your login page under another organisation’s website. Keep the complete URL: the healthy homepage and harmful deep page may coexist. Identify the affected path, its customer action and the party able to change it before asking for an intervention that could disrupt the entire domain.

The hostname alone does not describe the incident
A familiar organization can have a harmful page under a long path or subdomain. The surrounding website may still operate normally. Record the full address, not only the domain, and establish whether the reported content is accessible at that exact path.
Separate three questions: what the page claims, what it asks the visitor to do and who can control the relevant content. A copied header may support an impersonation assessment, while a login form or payment request changes the immediate customer-risk question. Do not infer that the legitimate site owner created the page.
Keep the harmful path attached to the evidence
A report that names only the root domain can send a reviewer to a harmless homepage. Preserve the route from the search result or shared link to the final page, including redirects. Capture the observation time, market and device alongside the page identity.
Use a non-sensitive capture. Do not test credential collection with a real account or upload identity documents. If a captured page contains personal information, keep that material out of public reports and use the agreed secure evidence process.

Separate copying from active deception
Copied content and trademark use require their own rights and context records. A page that presents itself as the official login and collects credentials raises a different issue from an independent article reproducing a small passage. Do not describe every unauthorized copy as phishing.
Record the claimed identity, action requested, form destination where safely observable and the entry point bringing customers to the page. The brand’s rights owner can establish what was copied and whether any permission exists. Security and legal owners can assess the parts that require their authority.
Assess the Affected Page
Discuss the observed source, available evidence and next action with AdFlagger.
Assess the Affected PagePublished incident research
A legitimate page can be replaced during the visit
Microsoft’s August 2025 ClickFix research ↗ describes a campaign that used compromised legitimate websites. The original page appeared briefly before a deceptive verification surface replaced it. Microsoft identified possible WordPress vulnerabilities as a route into those sites.
This observed campaign shows why a screenshot of the homepage can miss the customer-facing behaviour. Capture the affected route and what appears during the visit; give the legitimate operator or hosting provider enough information to find the injected content. A brand clone requires its own identity and rights evidence, while this research establishes the broader compromised-site mechanism.
ICANN distinguishes malicious registrations from compromised domains
These resolved compliance cases were classified by domain context. A case may include more than one domain; the counts describe cases, rather than a domain population or removal success rate.
Scale: 0 to 200 resolved registrar cases
Identify the party that can change the page
The website operator may be able to remove an injected page. A hosting platform may control a tenant account. A host may be able to disrupt an affected service. The registrar controls the domain relationship rather than individual page content. Establish these roles before selecting the escalation path.
ICANN’s DNS abuse advisory ↗ addresses collateral damage when legitimate domains are compromised. DNS-level suspension can disrupt benign pages and other services. This makes the complete path and the affected behavior important to a proportionate assessment.
Capture the page as a bounded incident
- Input
- The exact deep URL, branded entry point and non-sensitive screenshot.
- Check
- Open the reported route without submitting credentials. Record the response, any redirect, claimed identity and visible customer action. Compare the root page only to establish surrounding legitimate use.
- Interpretation
- A healthy root page alongside a harmful path supports a page-level investigation. A redirect into another hostname adds a second source to the record.
- Next action
- Identify the operator, platform or host that controls the affected content. Assess DNS-level action separately when the facts justify it.
For copied content, preserve the exact reproduced material and rights basis. For phishing, preserve the credential request and source behaviour. Keeping those records distinct makes a provider’s request for further evidence easier to answer.
Verify the page and every remaining entry point
After action, open the original complete URL through the recorded route. A homepage that still works is consistent with successful removal of one harmful path. Conversely, a changed homepage does not establish that a deep link or hosted copy is gone.
Record the page response, redirects, search visibility and remaining customer action separately. Check related paths discovered during the investigation without inventing variants or probing private areas. Search cleanup may require follow-up after source removal; it should not be reported as the same outcome.
Escalate a precise record
The next review should have one exact target, a clear explanation of the deceptive behavior, dated evidence, the provider’s reply and the unresolved route. This is more useful than repeatedly reporting the root hostname with an unchanged screenshot.
AdFlagger can assess the source, connect the branded entry point to the affected page and coordinate the relevant takedown workflow. Continued monitoring is justified when new paths or related sources repeatedly restore the same customer journey. Preserve legitimate surrounding services when defining the requested outcome.
Questions about this assessment
Assess the affected service and collateral impact. A compromised legitimate site may require targeted page or hosting action rather than domain-wide disruption.
No. Verify the exact reported path and route. Legitimate content can remain available after the harmful page is removed.
Use the observed customer action and identity claims. Copying alone does not establish credential theft or phishing.