|  home > phishing

How to report phishing

If you are visiting a login web page from a link in an email, but appears to be fake - this is called phishing.

First, report the page you are visiting:
Second, report the emails.
If you are using hotmail, then just click 'Mark as' > 'Phishing scam'.

You can also report them by forwarding your email to one of the following (do include the header information)
  • General: spam@uce.gov
  • General: reportphishing@antiphishing.org
  • Banks: reports@banksafeonline.org.uk
Third, report it to the real website.
If, for example, the email was about login in to your bank account, then let your bank know you have received the email. The best method is to find their support email address from the (real) website, and forward your email to them. Try to include the email headers, which would need to be copied and pasted in to the email. They then can also attempt to stop the fake emails being sent out.

Four, attempt to fix it yourself
Find the email headers, this lists how the email was sent to you, and will contain the IP address of where it came from.

There are some websites that can help decode the header information:
  • http://www.mxtoolbox.com/EmailHeaders.aspx
  • http://whatismyipaddress.com/trace-email
  • http://www.ipaddresslocation.org/email-tracking/email-header.php
  • http://mxkit.com/webmaster-tools/analyze-header
Do a 'whois' on the source IP address.
  • http://support.businesswebsite.com/whois.php
Find the company responsible for their IP address, and send them an email.

It depends on which country and the network, as to whether you get response! Sometimes better if you contact them through their website. You will have to find the website using the whois address details via a search engine.

Similarly, you can also find the company who host their website, and ask them to take the website offline.
Note
Most phishing emails can take sometime to stop, and their websites to be taken down. But by doing all the above actions, action can be taken sooner.