Australia Based · Operating Internationally · OSCE / OSCP Certified
☏ 1300 859 443

Phishing: How to Take a Phishing Site Offline

featured phishing guide
How to take a phishing site offline — Core Sentinel

“Congratulations, you just won a trip!” “Update your password now.” “Confirm your account information.” These classic phishing lures are still with us — but in 2026 they’ve been joined by something far harder to spot. This guide covers both the timeless, effective process for taking a phishing site offline, and what’s changed: the rise of AI-generated phishing, and how to defend against it.

What’s changed in 2026: AI-generated phishing

AI phishing went from 31% less effective in 2023 to 24% more effective in 2026

Phishing has taken a qualitative leap. Where attacks once gave themselves away with spelling errors and clumsy domains, attackers now use large language models to generate emails that are practically indistinguishable from genuine internal communication — correct corporate tone, accurate context, signed by a real manager, sent at exactly the right moment. The effectiveness data tells the story: AI-generated phishing went from 31% less effective than human-crafted attacks in 2023 to roughly 24% more effective by 2026, with global phishing losses estimated around $25 billion annually.

The threat is now multimodal: voice cloning to impersonate executives, deepfakes, and QRishing (malicious QR codes on printed materials and in offices) all sit alongside email. Traditional, checkbox-style awareness training is no longer enough on its own.

How to take a phishing site offline

When a fraudulent site is abusing your brand to deceive your customers, the most effective response is to get it taken offline. The following process reliably has phishing sites suspended and blocked by browsers and content filters — often within 24 hours.

Step 1 — Examine the email

Examine the fraudulent email for malicious domain links and sender addresses, and record them.

Step 2 — Report the email and URL

Forward the phishing email to the relevant anti-abuse addresses, and report the malicious URL to the major anti-phishing services (Google Safe Browsing, PhishTank, Microsoft, Netcraft and others) to get it blocked in browsers and filters quickly.

Step 3 — Look up the domain (WHOIS)

Use a WHOIS lookup to find the (1) name servers, (2) registrant and registrar, and (3) abuse contacts. The name servers point to the host — the most important contact for a successful suspension — so repeat the lookup on them to find how to make contact.

Step 4 — Contact host and registrar

Notify the hosting service and domain registry (usually abuse@), requesting suspension, and follow up with a phone call to both.

Step 5 — When a legitimate site has been hacked

Often the host is a legitimate business whose site was compromised, with the phishing kit uploaded to a subdirectory. (This is exactly why a web application penetration test matters — finding the flaw before criminals do.) Contact the business, notify them, and ask them to remove it — and, where possible, to provide a copy of the phishing kit for analysis.

Step 6 — Report malicious email accounts

For any fraudulent email accounts identified, notify the email provider’s abuse team.

Defending against AI-era phishing

Because AI phishing defeats the old “spot the typo” advice, defence in 2026 has to be layered:

  • Phishing-resistant MFA — hardware security keys, not just SMS or app codes.
  • Internal verification protocols — a quick phone check for any urgent request involving money, credentials or sensitive data stops most attacks cold.
  • Endpoint detection & response (EDR) — catches attacker activity after a successful lure, containing damage.
  • Modern, threat-informed awareness training — comprehensive training can cut phishing susceptibility dramatically; static annual modules can’t.
  • AI-assisted, multimodal detection — modern filters analyse communication patterns, text, images and behaviour, and AI helps defenders triage at the same speed attackers operate.

Where AI assists defenders, it mirrors its role in penetration testing: superb at scale and pattern-spotting, but most effective under expert human direction.

If you’ve been targeted, or want to test your resilience to modern phishing, seek expert assistance or call 1300 859 443.

Originally published 20 May 2017. Last updated 20 July 2026 to cover AI-generated phishing and modern defences.