PhishingReport

Report a phishing page. Cut the time it stays up.

Most phishing pages do their damage in the first few hours. A quick report gets the link checked and pushed into browser and email blocklists before more people are caught.

We never ask for passwords, payment, or login details. All we need is the suspicious link or message.

report intake // phisingreport.com

Reports are reviewed by an analyst. Don't include passwords or account numbers, we don't need them.

Report received.

Thanks. An analyst will review this. If you added your email, we'll let you know what we found and whether the link has been added to blocklists.

If anything claiming to be PhishingReport ever asks you for a password or payment, that's a phish. Report it.

What happens to your report

Three steps, usually inside a day. You don't need an account and you can report anonymously.

1

Received and de-duplicated

Your report is logged and matched against links we're already tracking, so nothing gets lost in the noise.

2

Verified by an analyst

A person confirms it's really phishing, captures evidence, and records the brand being impersonated.

3

Pushed to blocklists and partners

Confirmed links go to browser safe-browsing feeds, email providers, hosts, and the impersonated brand's abuse team.

Why hours matter

A phishing page is only useful to an attacker while it's reachable and trusted. Getting it onto blocklists early is what shuts it down.

Illustrative. Real takedown and blocklist times vary by host, registrar, and the brand being impersonated.

For security teams

If you run detection, brand protection, or a SOC, PhishingReport can plug into what you already do.

GET https://api.phisingreport.com/v1/feed/verified?since=2026-09-08 POST https://api.phisingreport.com/v1/reports { "url": "..." }

Want in on the feed or API? Email teams@phisingreport.com.

Why this exists

Phishing works because it scales. One kit, thrown at thousands of inboxes, only needs a handful of people to click. The defense scales too, but only if reports actually go somewhere and move fast.

PhishingReport is a place to send what you spotted and have it turned into a blocklist entry instead of a screenshot in a group chat. Every verified report makes the next person's inbox a little safer. That's the whole idea: a better internet, one dead phishing page at a time.

PhishingReport is an independent company. It is not affiliated with your bank, email provider, or employer, and it will never contact you asking for credentials or money.

Authorized security research and training. This service also supports authorized phishing-awareness training and detection research. Reports and anonymized samples may be used to improve filters and to train defenders. We don't sell report data. Questions: abuse@phisingreport.com.

About the company

PhishingReport is an independent company built around one problem: adversary-in-the-middle phishing. These are the reverse-proxy kits that sit between a person and the real login page, relay every keystroke in real time, and pass straight through multi-factor authentication. They are the fastest-growing form of credential theft, and most reporting tools were designed for an older, simpler kind of fake page.

Our pipeline pairs analyst review with machine-learning models trained on live phishing infrastructure. A reported link is classified, attributed to the brand it impersonates, and, once confirmed, pushed to browser and email blocklists. The form on this page is the front door to that system.

The detection pipeline is in beta. The goal is deliberately narrow and measurable: a shorter window of exposure on every phishing page that gets reported, and a safer inbox for the person who never sees any of it happen.

Britley HoffFounder and Chief Executive Officer