<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Phish Plug Blog</title>
    <link>https://phishplug.com/blog.html</link>
    <atom:link href="https://phishplug.com/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Field notes on phishing clones, mobile cloaking, lookalike domains and takedowns.</description>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:00:00 +0000</lastBuildDate>
    <item>
      <title>How to report a phishing site and actually get it removed</title>
      <link>https://phishplug.com/blog-report-phishing-site.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-report-phishing-site.html</guid>
      <category>Takedowns</category>
      <pubDate>Sun, 04 Oct 2026 08:00:00 +0000</pubDate>
      <description>Where to send a phishing report, what each abuse desk needs to see, and the evidence that turns a report into a removal instead of a dead-end ticket.</description>
    </item>
    <item>
      <title>Mobile cloaking explained: one URL, two realities</title>
      <link>https://phishplug.com/blog-mobile-cloaking.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-mobile-cloaking.html</guid>
      <category>Cloaking</category>
      <pubDate>Wed, 30 Sep 2026 08:00:00 +0000</pubDate>
      <description>How phishing pages show search crawlers a clean site and real mobile visitors a credential trap — and how dual-profile crawling proves the redirect.</description>
    </item>
    <item>
      <title>Typosquatting vs. homoglyph attacks, explained</title>
      <link>https://phishplug.com/blog-typosquatting-homoglyph.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-typosquatting-homoglyph.html</guid>
      <category>Detection</category>
      <pubDate>Sat, 26 Sep 2026 08:00:00 +0000</pubDate>
      <description>Two ways attackers fake your domain — one exploits typing mistakes, the other uses look-alike characters. How each works and how to catch both early.</description>
    </item>
    <item>
      <title>The phishing takedown process: abuse channels, step by step</title>
      <link>https://phishplug.com/blog-takedown-process.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-takedown-process.html</guid>
      <category>Takedowns</category>
      <pubDate>Tue, 22 Sep 2026 08:00:00 +0000</pubDate>
      <description>Registrars, hosts, CDNs and safe-browsing desks — where to file, what evidence each one wants, and why routing beats blasting.</description>
    </item>
    <item>
      <title>What is credential harvesting? How phishing steals logins</title>
      <link>https://phishplug.com/blog-credential-harvesting.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-credential-harvesting.html</guid>
      <category>Threats</category>
      <pubDate>Fri, 18 Sep 2026 08:00:00 +0000</pubDate>
      <description>Credential harvesting is the engine behind most phishing. How fake login pages capture passwords, where the data goes, and how to shut the pipeline down.</description>
    </item>
    <item>
      <title>How to detect lookalike domains before they go live</title>
      <link>https://phishplug.com/blog-lookalike-domains.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-lookalike-domains.html</guid>
      <category>Detection</category>
      <pubDate>Mon, 14 Sep 2026 08:00:00 +0000</pubDate>
      <description>Typosquatting, homoglyphs and combosquatting — the signals that expose impersonation domains early, from registration to first crawl.</description>
    </item>
    <item>
      <title>Fake login pages: how to spot one before you type</title>
      <link>https://phishplug.com/blog-fake-login-pages.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-fake-login-pages.html</guid>
      <category>Threats</category>
      <pubDate>Thu, 10 Sep 2026 08:00:00 +0000</pubDate>
      <description>Cloned sign-in screens are the sharp end of phishing. The tells that give them away, and why your customers need you watching rather than relying on their eyes.</description>
    </item>
    <item>
      <title>Brand protection best practices: a checklist for 2026</title>
      <link>https://phishplug.com/blog-brand-protection.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-brand-protection.html</guid>
      <category>Best practices</category>
      <pubDate>Sun, 06 Sep 2026 08:00:00 +0000</pubDate>
      <description>A practical playbook for protecting your brand from phishing impersonation — monitoring, evidence, takedowns and the metrics that matter.</description>
    </item>
    <item>
      <title>Brand impersonation on social media: a response playbook</title>
      <link>https://phishplug.com/blog-social-media-impersonation.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-social-media-impersonation.html</guid>
      <category>Threats</category>
      <pubDate>Fri, 28 Aug 2026 08:00:00 +0000</pubDate>
      <description>Fake profiles, cloned pages and lookalike handles target your customers off your own site. How to find, evidence and take down social impersonation.</description>
    </item>
    <item>
      <title>Why a screenshot isn't enough evidence for a takedown</title>
      <link>https://phishplug.com/blog-screenshot-not-evidence.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-screenshot-not-evidence.html</guid>
      <category>Evidence</category>
      <pubDate>Thu, 20 Aug 2026 08:00:00 +0000</pubDate>
      <description>A screenshot is easy to dismiss and easy to fake. What abuse desks actually need — headers, the cloaking diff and timestamps — to act on first submission.</description>
    </item>
    <item>
      <title>Certificate Transparency for brand monitoring</title>
      <link>https://phishplug.com/blog-certificate-transparency.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-certificate-transparency.html</guid>
      <category>Detection</category>
      <pubDate>Wed, 12 Aug 2026 08:00:00 +0000</pubDate>
      <description>Every TLS certificate is logged publicly. How to turn Certificate Transparency logs into an early-warning system for clones and lookalike domains.</description>
    </item>
    <item>
      <title>Phishing-as-a-Service (PhaaS), explained</title>
      <link>https://phishplug.com/blog-phishing-as-a-service.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-phishing-as-a-service.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 05 Aug 2026 08:00:00 +0000</pubDate>
      <description>Phishing is now a subscription product: kits, cloaking and hosting sold ready-made. What PhaaS is, why it scales attacks, and what actually stops it.</description>
    </item>
    <item>
      <title>Smishing: how SMS phishing works and how to fight it</title>
      <link>https://phishplug.com/blog-smishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-smishing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 29 Jul 2026 08:00:00 +0000</pubDate>
      <description>Phishing by text message bets on urgency and small screens. How smishing lures work, why links are so dangerous on mobile, and how to shut down the pages behind them.</description>
    </item>
    <item>
      <title>Vishing: voice phishing and callback scams explained</title>
      <link>https://phishplug.com/blog-vishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-vishing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 22 Jul 2026 08:00:00 +0000</pubDate>
      <description>Phone-based phishing uses a human voice to bypass caution. How vishing and callback scams work, the role of spoofed numbers, and where brand protection fits in.</description>
    </item>
    <item>
      <title>Business Email Compromise (BEC), explained</title>
      <link>https://phishplug.com/blog-business-email-compromise.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-business-email-compromise.html</guid>
      <category>Email security</category>
      <pubDate>Wed, 15 Jul 2026 08:00:00 +0000</pubDate>
      <description>BEC skips malware and targets trust: fake invoices, wire fraud and impersonated executives. How it works, why it is so costly, and how to defend against it.</description>
    </item>
    <item>
      <title>Spear phishing vs. mass phishing: what's the difference?</title>
      <link>https://phishplug.com/blog-spear-phishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-spear-phishing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 08 Jul 2026 08:00:00 +0000</pubDate>
      <description>One is a net, the other a spear. How targeted spear phishing differs from mass campaigns, why it works, and what defences actually apply to each.</description>
    </item>
    <item>
      <title>Whaling: phishing that targets the executives</title>
      <link>https://phishplug.com/blog-whaling.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-whaling.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 01 Jul 2026 08:00:00 +0000</pubDate>
      <description>Whaling aims at leadership, where one approval moves money. How executive-targeted phishing works and the controls that stop a convincing impersonation.</description>
    </item>
    <item>
      <title>Clone phishing: when a real email comes back poisoned</title>
      <link>https://phishplug.com/blog-clone-phishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-clone-phishing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 24 Jun 2026 08:00:00 +0000</pubDate>
      <description>Clone phishing copies a legitimate message and swaps the link or attachment. Why the familiarity makes it dangerous and how to recognise and stop it.</description>
    </item>
    <item>
      <title>QR code phishing (quishing): the scan-and-steal scam</title>
      <link>https://phishplug.com/blog-quishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-quishing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 17 Jun 2026 08:00:00 +0000</pubDate>
      <description>A QR code hides its destination until you scan it. How quishing abuses that trust, where fake codes appear, and how to defend your brand and customers.</description>
    </item>
    <item>
      <title>Pharming: when the right address sends you to a fake site</title>
      <link>https://phishplug.com/blog-pharming.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-pharming.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 10 Jun 2026 08:00:00 +0000</pubDate>
      <description>Pharming poisons the path between a correct address and the real server. How DNS-based redirection works, why it is hard to spot, and how to reduce the risk.</description>
    </item>
    <item>
      <title>Malvertising: fake ads that impersonate your brand</title>
      <link>https://phishplug.com/blog-malvertising.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-malvertising.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 03 Jun 2026 08:00:00 +0000</pubDate>
      <description>Attackers buy ads on your own brand terms to outrank you and send customers to clones. How malvertising works and how to detect and take it down.</description>
    </item>
    <item>
      <title>How to spot a phishing email: the red flags that matter</title>
      <link>https://phishplug.com/blog-phishing-email-red-flags.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-phishing-email-red-flags.html</guid>
      <category>Email security</category>
      <pubDate>Wed, 27 May 2026 08:00:00 +0000</pubDate>
      <description>The reliable signals of a phishing email — and the ones that no longer hold. A practical guide for people, plus why brands can't rely on it alone.</description>
    </item>
    <item>
      <title>DMARC, SPF and DKIM: stop attackers spoofing your domain</title>
      <link>https://phishplug.com/blog-dmarc-spf-dkim.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-dmarc-spf-dkim.html</guid>
      <category>Email security</category>
      <pubDate>Wed, 20 May 2026 08:00:00 +0000</pubDate>
      <description>Three email-authentication standards decide whether someone can send mail as you. What SPF, DKIM and DMARC do, and how to roll them out without breaking mail.</description>
    </item>
    <item>
      <title>Email spoofing: how attackers fake your 'from' address</title>
      <link>https://phishplug.com/blog-email-spoofing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-email-spoofing.html</guid>
      <category>Email security</category>
      <pubDate>Wed, 13 May 2026 08:00:00 +0000</pubDate>
      <description>Why email lets anyone forge a sender, how spoofing underpins phishing and BEC, and the authentication that makes your domain hard to impersonate.</description>
    </item>
    <item>
      <title>Domain monitoring: a practical buyer's guide</title>
      <link>https://phishplug.com/blog-domain-monitoring-guide.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-domain-monitoring-guide.html</guid>
      <category>Detection</category>
      <pubDate>Wed, 06 May 2026 08:00:00 +0000</pubDate>
      <description>What domain monitoring should actually do, the signals that matter, and the questions to ask — so you catch lookalikes early instead of paying for noise.</description>
    </item>
    <item>
      <title>Brandjacking: when someone hijacks your identity online</title>
      <link>https://phishplug.com/blog-brandjacking.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-brandjacking.html</guid>
      <category>Best practices</category>
      <pubDate>Wed, 29 Apr 2026 08:00:00 +0000</pubDate>
      <description>Brandjacking covers domains, social handles, ads and apps that seize your identity. The forms it takes and how to reclaim and defend your brand.</description>
    </item>
    <item>
      <title>Does the padlock mean a site is safe? The HTTPS myth</title>
      <link>https://phishplug.com/blog-https-padlock-myth.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-https-padlock-myth.html</guid>
      <category>Defense</category>
      <pubDate>Wed, 22 Apr 2026 08:00:00 +0000</pubDate>
      <description>The padlock means encrypted, not trustworthy. Why most phishing sites now use HTTPS, and what actually tells you whether a login page is real.</description>
    </item>
    <item>
      <title>Account takeover (ATO): how one phish becomes many</title>
      <link>https://phishplug.com/blog-account-takeover.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-account-takeover.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 15 Apr 2026 08:00:00 +0000</pubDate>
      <description>Account takeover is where phishing pays off. How stolen credentials turn into fraud, why reuse spreads the damage, and how to break the chain.</description>
    </item>
    <item>
      <title>Credential stuffing vs. brute force: know the difference</title>
      <link>https://phishplug.com/blog-credential-stuffing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-credential-stuffing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 08 Apr 2026 08:00:00 +0000</pubDate>
      <description>Both attack logins, but in opposite ways. How credential stuffing reuses stolen passwords at scale, how brute force differs, and what stops each.</description>
    </item>
    <item>
      <title>Dark web monitoring for leaked credentials</title>
      <link>https://phishplug.com/blog-dark-web-monitoring.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-dark-web-monitoring.html</guid>
      <category>Detection</category>
      <pubDate>Wed, 01 Apr 2026 08:00:00 +0000</pubDate>
      <description>Leaked passwords fuel account takeover. What dark web monitoring can and can't do, how to act on a hit, and where it fits in a brand-protection programme.</description>
    </item>
    <item>
      <title>Phishing incident response: what to do when customers are hit</title>
      <link>https://phishplug.com/blog-incident-response-phishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-incident-response-phishing.html</guid>
      <category>Defense</category>
      <pubDate>Wed, 25 Mar 2026 08:00:00 +0000</pubDate>
      <description>A clear, calm playbook for the first hours of a phishing attack on your brand — contain, evidence, take down, communicate and learn.</description>
    </item>
    <item>
      <title>AI-powered phishing and deepfakes: the new frontier</title>
      <link>https://phishplug.com/blog-ai-phishing.html</link>
      <guid isPermaLink="true">https://phishplug.com/blog-ai-phishing.html</guid>
      <category>Threats</category>
      <pubDate>Wed, 18 Mar 2026 08:00:00 +0000</pubDate>
      <description>AI writes flawless lures and clones voices and faces. How attackers use it, why old 'spot the typo' advice is failing, and what still works.</description>
    </item>
  </channel>
</rss>
