Blog/Phishing

Reporting Phishing That Impersonates Your Organization

Criminals are sending emails or running fake sites in your organization's name. How to get the sites taken down, warn customers, lock down your email domain and keep records.

CyberWatch AI2 October 2026 · 2 min read
A business owner sitting with a laptop in an office lounge

A customer forwards you an email with your logo asking them to pay a new account. Or someone finds a website that copies yours. Brand impersonation affects organizations of every size, from global firms to local shops and charities. Here is how to respond.

First hour

  1. Collect evidence: the email with full headers, the links, screenshots of the site, dates and any customer reports.
  2. Check it is not coming from you. Could one of your own accounts be compromised? See checking for hidden rules and signs your email is hacked.
  3. Report the site to browser blocklists, the host and the registrar. See getting phishing sites taken down.

Warn the people being targeted

  • Post a short, factual warning on your website and social channels.
  • Tell customers how you will and will not contact them, for example: "We will never ask you to change payment details by email."
  • Give a safe way to check, such as a phone number on your official website.

Lock down your email domain

If criminals are sending email that appears to come from your exact domain, set up SPF, DKIM and DMARC with a strict policy. See email authentication explained. This does not stop lookalike domains, but it stops exact spoofing.

Reduce future risk

If customers lost money, encourage them to contact their bank and report to police. Keep a record of every report you receive.

For more, see how to report phishing in our complete guide.

Frequently asked questions

Are we responsible if customers are scammed using our name?

Legal responsibility depends on your country and circumstances, so take advice if losses are involved. Acting quickly, warning customers and reporting shows good faith and limits harm.

Should we tell customers publicly?

Usually yes. A short, clear warning on your website and channels, with how to reach you safely, protects customers and your reputation.

Can we stop lookalike domains being registered?

Not entirely, but you can register obvious variants yourself and monitor for new ones.

Sources

  1. Email security and anti-spoofing, UK National Cyber Security Centre
  2. ICANN Lookup, ICANN
  3. Report a phishing page, Google Safe Browsing
  4. Cybersecurity for Small Business, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.