Phishing sites impersonate a legitimate brand to steal credentials, payment details, or personal information — and modern ones are often visually identical to the real site.
Warning signs
- URL doesn’t exactly match the real domain (subtle misspellings, extra subdomains, or a different TLD)
- Urgency-driven messaging ("your account will be suspended") pushing you to act before checking carefully
- Requests for information a legitimate login page wouldn’t need (e.g. full card number on a simple login form)
- No valid SSL certificate matching the claimed domain, though many phishing sites do now use free SSL certificates too, so this alone isn’t conclusive
If you find one impersonating your brand
Report it to Google Safe Browsing and the hosting provider’s abuse contact, and warn customers through your own verified channels if the impersonation is active and convincing.
FAQ
Does having HTTPS mean a site isn’t phishing?
No — free SSL certificates are trivial for attackers to obtain too, so HTTPS alone no longer signals legitimacy the way it once did.