Phishing incident response: what to do when customers are hit
When a phishing campaign hits your brand, the first hours decide how much damage it does. A calm, rehearsed incident response beats improvisation every time. Here is a practical playbook for when customers are being targeted in your name.
1. Confirm and contain
Verify it is a genuine impersonation — the lookalike domain, the cloned page, the lure. Then contain: start the takedown immediately, and if the campaign harvests credentials, prepare to force resets for anyone who may have been caught. The goal of this phase is to stop the bleeding.
2. Evidence it
Capture the proof before it changes: dual-profile screenshots (defeating any cloaking), raw headers, the redirect chain and timestamps. Good evidence speeds the takedown and supports any follow-up with registrars, hosts or authorities.
3. Take it down
Resolve the clone's host, registrar and CDN and file evidence-backed reports to each, plus safe-browsing feeds to protect users immediately. Track until the page is confirmed offline.
Containment and takedown run in parallel, not in sequence. Every minute the page stays up is more harvested credentials — move on both at once.
4. Communicate
Once you understand the scope, tell customers plainly: what the scam looks like, what you will never ask them to do, and what to do if they already interacted. Clear, factual communication limits harm and protects trust far better than silence.
5. Review and harden
- Confirm removal and close the case with its evidence retained.
- Review what let the attack work and reach customers.
- Harden the gaps — email authentication, monitoring coverage, verification processes.
- Prepare for the next variant; campaigns rarely stop at one page.
Phish Plug compresses the containment, evidence and takedown steps into one fast workflow — a 37-minute median time to filing — so your first hour counts.
The takeaway
A phishing incident is won or lost in the first hours. Confirm and contain, evidence it, take it down, communicate clearly, then review and harden. Have the playbook ready before you need it — and tooling that makes the fast steps fast.
Keep reading
Related articles
AI-powered phishing and deepfakes: the new frontier
AI writes flawless lures and clones voices and faces. How attackers use it, why old 'spot the typo' advice is failing, and what still works.
Read article Takedowns · 8 minHow to report a phishing site and actually get it removed
Where to send a phishing report, what each abuse desk needs to see, and the evidence that turns a report into a removal instead of a dead-end ticket.
Read article Cloaking · 9 minMobile cloaking explained: one URL, two realities
How phishing pages show search crawlers a clean site and real mobile visitors a credential trap — and how dual-profile crawling proves the redirect.
Read articleCut phishing off at the source
Run a free clone check on one domain — Phish Plug finds the clones, proves the cloaking and files the takedown.