Brandjacking: when someone hijacks your identity online
Brandjacking is the umbrella term for hijacking your brand's identity online. Phishing is part of it, but so are fake social profiles, impersonating ads, counterfeit apps and lookalike domains. If someone is wearing your name to deceive or profit, that is brandjacking — and it happens across more channels than most teams watch.
The forms it takes
- Lookalike domains — near-identical web addresses hosting clones or diverting traffic.
- Fake social profiles — accounts posing as your brand, support or executives.
- Impersonating ads — paid results on your brand terms pointing to clones.
- Counterfeit apps — fake apps using your name and logo in app stores.
- Logo and trademark abuse — unauthorised use of your identity to lend credibility to a scam.
Why it is damaging
Brandjacking does two kinds of harm at once: it defrauds your customers, and it erodes the trust you spent years building. Every scam in your name is a customer who associates your brand with being cheated — damage that outlasts the individual attack.
Brandjacking is a coverage problem. Attackers use whatever channel you aren't watching, so the defence has to span domains, social, ads and apps — not just your website.
How to reclaim and defend
- Monitor across channels — domains, social platforms, ads and app stores.
- Evidence the misuse before it can be edited or deleted.
- Take it down through each channel's process — abuse desks, platform impersonation reports, store removals.
- Reduce the openings — register key domains and handles, and keep trademarks current.
Phish Plug focuses on the infrastructure side of brandjacking — the lookalike domains and cloaked pages — detecting them, proving the abuse and filing takedowns.
The takeaway
Brandjacking is identity theft for brands, spread across every channel attackers can reach. Beating it means watching broadly, evidencing misuse, and taking it down channel by channel — while closing the easy openings before someone else claims them.
Keep reading
Related articles
Does the padlock mean a site is safe? The HTTPS myth
The padlock means encrypted, not trustworthy. Why most phishing sites now use HTTPS, and what actually tells you whether a login page is real.
Read article Threats · 8 minAccount takeover (ATO): how one phish becomes many
Account takeover is where phishing pays off. How stolen credentials turn into fraud, why reuse spreads the damage, and how to break the chain.
Read article Threats · 7 minCredential stuffing vs. brute force: know the difference
Both attack logins, but in opposite ways. How credential stuffing reuses stolen passwords at scale, how brute force differs, and what stops each.
Read articleSee your brand's exposure in one pass
Run a free clone check on one domain — lookalikes surfaced, cloaking proven, evidence captured.