An empty masquerade eye mask on a stick in blue halftone, beside the headline Fake Site Using Your Brand? Report It Fast.

Phishing Website Using My Brand: How to Report It

Fake login page using your Malaysian company's name? Save evidence, report it to Cyber999, Google Safe Browsing, the registrar and host, and warn customers.

10 min read
Short answer

Save the phishing link and dated screenshots without entering any data. Report it to CyberSecurity Malaysia's Cyber999, which handles phishing and fraud sites, and to Google Safe Browsing so browsers show a warning. Send abuse reports to the registrar and host, then warn customers through your official channels. Those parties decide on blocking or removal.

Summary
  • A phishing site that copies your brand is built to steal your customers' logins or payment details, so treat it as a security incident, not a marketing problem.
  • Capture the full link and dated screenshots first, and never type a real or fake username, password or card number into the page.
  • In Malaysia, CyberSecurity Malaysia's Cyber999 is the primary agency for phishing and fraud sites, with the police involved where there is a criminal element.
  • Report the link to Google Safe Browsing so browsers can warn visitors, and send abuse reports to the domain registrar and hosting company.
  • Warn customers on your official channels, tell anyone who lost money to call their bank or NSRC 997, and ignore takedown agents who ask for admin logins or upfront payment.
  • Agencies, registrars, hosts and Google decide what happens to the site, so nobody can promise a takedown, but a clear, well-evidenced report gives them what they need.
Table of contents11 sections
  1. 01How Do You Report a Phishing Website Impersonating Your Brand in Malaysia?
  2. 02Is It Phishing, a Clone Site or a Fake Page?
  3. 03Capture the Evidence Without Touching the Form
  4. 04Report the Site to CyberSecurity Malaysia Cyber999
  5. 05Ask Google Safe Browsing to Warn Visitors
  6. 06Find the Registrar and Host and File Abuse Reports
  7. 07Warn Your Customers Without Spreading the Link
  8. 08Lookalike Domains: The Slower Legal Route
  9. 09Mistakes That Slow a Phishing Takedown
  10. 10When a Case Review Makes Sense
  11. 11Frequently Asked Questions

A customer forwards you a link. The page looks exactly like your login screen or checkout, with your logo and colours, but the address is not yours. Someone is using your brand to collect passwords, card numbers or one-time codes from people who trust you.

The short answer: save the evidence without typing anything into the page, report it to CyberSecurity Malaysia's Cyber999 and to Google Safe Browsing, send abuse reports to the domain registrar and the host, and warn your customers from channels you control. Do these in parallel, not one after another.

This guide is for the business or brand owner. If you or a customer already entered details into the fake page, our guide on what to do after clicking a phishing link covers the victim's side.

Last checked: 5 October 2026.

#How Do You Report a Phishing Website Impersonating Your Brand in Malaysia?

Report it in four places at once. First, CyberSecurity Malaysia's Cyber999 incident response centre, which accepts reports by online form, email, phone and its mobile app. Second, Google Safe Browsing, so Chrome and Google Search can show a warning. Third, the abuse contact of the registrar that sold the domain. Fourth, the company hosting the site. Then post a warning on your official website and social accounts. If a customer lost money, they should call their bank or the National Scam Response Centre on 997 and make a police report. This is general information, not legal advice.

#Is It Phishing, a Clone Site or a Fake Page?

The route depends on what the site does. A phishing site asks visitors for credentials or payment details so the operator can steal them. A clone site copies your name, text or design but may only sell fake goods or confuse buyers. A fake social media Page lives inside Facebook, Instagram or TikTok and is reported to that platform instead.

Matching what you found to the right reporting route. Many incidents mix two rows, so use both.
What you foundWhat it usually isWhere to start
A copy of your login, banking or checkout page on a domain you do not ownPhishing, built to harvest usernames, passwords, cards or codesCyber999, Google Safe Browsing, registrar and host abuse reports (this guide)
A lookalike shop or company site reusing your text, photos or logoA clone site; may be fraud, copyright or trade mark infringementOur guide to a fake website copying your business
A Facebook Page or Instagram account posing as your businessPlatform impersonationOur guide to fake Pages using your business name
A sponsored post or ad sending people to a fake siteA scam ad, plus a phishing or fraud landing pageReport the ad to the platform, and the landing page through this guide
An email or SMS using your name with a link to the fake pageA phishing campaign; the page and the messages are both evidenceKeep the full message and headers for Cyber999, then follow this guide

Phishing often arrives through ads. If the link came from a paid post, our guide to reporting scam ads that use your brand covers the ad side while you deal with the website here.

#Capture the Evidence Without Touching the Form

Evidence first, because phishing sites are often moved or taken offline by their operators without warning. You need enough for an agency, a registrar and a host to act without visiting the page themselves.

  • The full URL copied as text, including everything after the domain. Write it with brackets, such as example[.]com, when you paste it into emails so nobody clicks it by mistake.
  • Screenshots of the page with the address bar and your device clock visible, taken from a work device that is patched and has no saved customer logins.
  • The message that delivered the link: the email with full headers, the SMS with the sender ID, or a screenshot of the ad or post.
  • When and how you found out, and the names of customers who reported it, kept private in your own records.
  • Your own genuine domain and login page, so reviewers can compare the two.
  • Any trade mark registration for your brand name or logo, which matters later for domain disputes.
  • A log of every report you file: where, when, the reference number and any reply.

Cyber999 asks for the same kind of material. Its page lists the source of attack, the destination, email headers, log files and the time of attack as useful items to include in an email report.

#Report the Site to CyberSecurity Malaysia Cyber999

Cyber999 is the national point of contact for reporting computer security incidents, run under CyberSecurity Malaysia. Its page says it provides technical analysis of incidents and helps Malaysian Internet users escalate abuse reports to the relevant parties, which is exactly what a brand owner needs when the registrar or host is overseas.

CyberSecurity Malaysia's agency referral table names it as the primary agency for fraud, including fraud sites, impersonation and spoofing, and phishing, with the Royal Malaysia Police (PDRM) as the supporting agency where there is a criminal element. Online scams where people lost money sit with the NSRC instead.

  1. Open the Cyber999 page and choose the online form, the Cyber999 app or email to cyber999 [at] cybersecurity.my.
  2. Describe the incident in a few factual lines: your brand, your real domain, the fake URL, when it appeared and how customers received it.
  3. Attach your screenshots, the delivering message and its headers.
  4. Keep the reference number in your report log and use it in every follow-up.

Cyber999's page notes that its hotline is monitored during business hours and lists a separate emergency line for phishing. Use the online form outside office hours so the report is waiting when the team starts.

#Ask Google Safe Browsing to Warn Visitors

A Safe Browsing warning does not delete the site, but it can stop many people reaching it. Google's Report a Page to Google Safe Browsing form exists for unsafe pages where a warning should appear but does not, and Google says Safe Browsing protects users from social engineering content such as phishing.

  • Report the page as unsafe, choose phishing or social engineering as the threat and paste the exact URL.
  • Use the details box to say which brand is impersonated and what the page collects.
  • Note that Google says it may share the URL and its status with third parties and in its Transparency Report.
  • Check progress on Google's Safe Browsing site status page; Google does not publish a review time.

#Find the Registrar and Host and File Abuse Reports

Two companies keep a phishing site online: the registrar that sold the domain name, and the host whose servers deliver the page. Either may suspend it under its own terms. That decision is theirs.

For domains such as .com, .net or the newer endings, look the domain up in ICANN's registration data lookup tool, which WIPO also recommends for finding the registrar. For .my domains, use MYNIC's WHOIS. MYNIC says personal details of the registrant are no longer shown for privacy reasons, so you will mostly see the registrar, which is all you need.

ICANN's page on registrar abuse reports says accredited registrars must publish an abuse contact, show an abuse email and phone number in WHOIS results, and take reasonable and prompt steps to investigate and respond to reports. ICANN itself does not control website content, so send your report to the registrar, not to ICANN. If a registrar ignores those obligations, ICANN accepts a complaint about the registrar.

  1. Email the registrar's published abuse address with the subject line "Phishing: [domain] impersonating [your brand]".
  2. Give the defanged URL, what the page imitates, what it collects and your evidence.
  3. Say plainly that you own the genuine brand and domain, and attach proof if you have it.
  4. If the site sits behind a proxy or content delivery service, use that company's abuse form too, as it may be able to pass the report to the real host.
  5. Mention your Cyber999 reference number so each party knows the national CERT already has the case.

Finding the host can take more work than finding the registrar. If you cannot identify it, say so in your Cyber999 report; escalating abuse reports to the relevant parties is part of its stated role.

Your customers act on what you tell them, so a short, calm notice is as useful as any takedown. Post it on your website, your verified social accounts and in any customer email list you already run.

  • Name your only genuine domain and login address in plain text.
  • Describe the fake without a clickable link: what it looks like, and how it arrives (email, SMS, ad).
  • Say what you will never ask for, such as passwords or one-time codes by message, if that is true for your business.
  • Tell anyone who entered details to change their password, contact their bank straight away if they gave card details, and call NSRC 997 if money left their account.
  • Give one official channel for questions, and update the notice when the site goes down.

Customers who lost money also need a police report. Our explainer on what happens when you call NSRC 997 walks them through it.

A registrar suspension ends one site. When someone keeps registering domains that contain your trade mark, a domain dispute can transfer the name to you. This is a legal process that a lawyer usually handles, and the following is general information, not legal advice.

  • For .my domains, MYNIC's .MY Domain Name Dispute Resolution Policy (MYDRP) governs disputes between the holder of a .my domain and a complainant over its registration or use, and aims to protect intellectual property rights.
  • For generic domains such as .com, WIPO says the UDRP applies, and the complainant must prove three things: rights in a trade mark, that the registrant has no rights in the domain, and that it was registered and used in bad faith.
  • A domain dispute takes time, money and legal preparation, so it suits repeated or high-impact abuse rather than a single site that a registrar has already suspended.
  • Only file for marks your business genuinely holds. WIPO notes that a respondent can ask a panel to find a complaint was brought in bad faith.

#Mistakes That Slow a Phishing Takedown

  • Reporting only to one place and waiting for an answer before trying the next.
  • Sending a bare screenshot without the full URL, so the reviewer cannot find the page.
  • Posting the live link in a public warning, which sends more people to it.
  • Testing the form with fake details or probing the server, which can contaminate evidence.
  • Exaggerating the report or filing duplicates from many staff accounts. Accurate, single reports with a reference number are easier to act on.
  • Forgetting the delivery channel: the fake page is often one of several, and the email or ad shows where the rest are.
  • Deleting the original phishing email before the headers are saved.

#When a Case Review Makes Sense

Many businesses can file every report above themselves. Outside help is worth considering when the same brand is copied across several domains, ads and social accounts at once, when customers are already losing money, or when your team has no time to track replies. SocialSafe by AwareXone reviews the case first, tells you which reports are still open to you, and prepares rights-based reports through official channels only, without asking for your logins or codes. Our impersonation removal service explains the scope, and the Trust Center sets out what we will and will not do.

#Frequently Asked Questions

Who do I report a phishing website to in Malaysia?
CyberSecurity Malaysia's Cyber999 is the primary agency for phishing and fraud sites, with PDRM involved where there is a criminal element. If people lost money, the NSRC on 997 and a police report come first for them.
Can Cyber999 take down a phishing site?
Cyber999 analyses incidents and helps escalate abuse reports to the parties who control the site, such as registrars and hosts. Those parties decide whether to suspend it, so there is no promise of removal.
How do I find out who owns a phishing domain?
WHOIS lookups through ICANN or MYNIC usually show the registrar, but personal details of the owner are often hidden for privacy. You do not need the owner's identity to report the site; the registrar and host are the parties that act.
Will Google remove the phishing site from the internet?
No. Google Safe Browsing can add a warning in browsers and Search, which stops many visitors, but the site stays online until its registrar or host acts.
Should I send a legal letter to the person running the site?
Contacting the operator directly rarely helps and can tip them off to move the site. Report through the official routes first, and speak to a lawyer if you are considering formal legal action.

Official sources

Need harmful content reviewed?

Send us the links and what you have already reported. We review the case first, prepare rights-based reports through official platform and legal channels only, and never file false claims. The platform makes the final decision. Related service: Impersonation removal.