Of all the ways a website gets misused, this is the one that feels most personal. Somewhere in your hosting account sits a perfect replica of a bank login page, and people are typing their credentials into it.
They believe they are on their bank's website. They are on yours.
Phishing pages on your website put you in an uncomfortable position: you are not the target, and you are still the one hosting the crime.
Why they use someone else's site
Attackers could register their own domain. Using yours is better for them in four specific ways.
Reputation. Your domain has age and history. Newly registered domains get flagged quickly; established ones do not.
A valid certificate. Your site already has HTTPS and a padlock, which is exactly what security advice tells people to check for.
Distance. When the scam is reported, the trail leads to your hosting account rather than theirs.
It costs nothing. No domain to buy, no hosting to pay for, and no loss when it gets taken down.
Nobody chose your business. Automated scanning found a vulnerability, and your domain's reputation was the asset worth taking.
How you usually find out
Rarely by noticing. The pages are hidden in deep folder paths, never linked from your site, and often serve a normal 404 to anyone without the exact URL.
Typical discovery routes are all external: your host suspends the account, Google flags the site as deceptive, a bank's fraud team contacts you, your domain lands on a blacklist, or a security vendor sends an abuse report.
By that point the pages have usually been live for weeks.
Finding them
- Read the abuse report carefully. If a host, bank or security vendor contacted you, they almost always included the exact URL. That is your starting point
- Check Google Search Console under Security Issues. "Deceptive pages" is this attack, and Google usually lists sample URLs
- Sort files by modification date. Phishing kits are uploaded in a batch, so they cluster around one timestamp
- Look for out-of-place folders — directories with names imitating banks, payment providers or courier companies, often nested several levels deep in uploads or a theme folder
- Search for HTML forms in unexpected places. Phishing pages are usually plain HTML and PHP rather than WordPress templates
- Look for a mailer script. Kits need to send captured credentials somewhere, so there is nearly always a small script handling that
Phishing kits are frequently uploaded as a single archive and extracted, which is why everything appears at once in one folder.
What makes this different from other clean-ups
Three things change the response.
Preserve evidence before deleting. Take a copy of the files and download the logs first. Banks and law enforcement sometimes request them, and you will want to know how long it ran.
Real people are being harmed right now. Unlike spam pages or a redirect, every hour this runs someone loses money. Taking the pages offline is genuinely urgent.
Your domain reputation takes the hit. Phishing gets you blacklisted faster and more widely than most malware — by Google, by browsers, by mail providers and by corporate filters.
The response
- Take a forensic copy of the site and download the logs
- Remove the phishing pages and the mailer script
- Find the backdoor. They uploaded files, which means they had write access. Removing the pages does not remove the access
- Clean the site properly — core files, themes, plugins, database
- Rotate every credential and regenerate the security keys in
wp-config.php - Patch the entry point, usually an outdated plugin or a weak password
- Request review in Search Console and delisting from the blacklists you appear on
- Reply to the abuse report explaining what you found and did
Our guide to removing malware from WordPress covers steps three to six in detail. Step three is the one that decides whether the pages come back next week.
Getting off the blacklists
This takes longer than the clean-up and matters more than people expect.
Google is handled through Search Console — see our guide to the Search Console security report. But phishing also gets you onto mail blacklists and browser safe-browsing lists maintained by several vendors, each with its own delisting process.
Until you clear them, your legitimate email will land in spam folders and some corporate networks will block your domain outright. Work through them methodically rather than assuming Google was the only one.
Should you tell anyone?
Two separate questions here.
The organisation being impersonated — yes, if you can identify them. Their fraud team wants to know, and cooperating puts you clearly on the right side of it.
Your own customers — usually not required. The phishing targeted the impersonated brand's customers, not yours, and their data was not involved.
That changes if the attacker also accessed your database. If your customer data may have been reached, notification obligations apply — generally 72 hours under GDPR and comparable windows under PDPL. Establish which situation you are in before deciding.
Why it happened
The entry point is almost always ordinary: an outdated plugin with a published vulnerability, a nulled theme carrying a backdoor, a weak administrator password, or a file upload feature that never checked what it accepted.
That last one is worth noting. Any form allowing file uploads — job applications, support tickets, image submissions — needs to validate types properly. Otherwise it is a delivery mechanism.
Blocking PHP execution in the uploads folder, covered in our hardening checklist, neutralises a large share of these attacks.
Catching it early
Phishing pages are invisible to you and obvious to a file integrity monitor. New files appearing in a folder that should only contain media is precisely what those systems flag.
The difference is stark: caught in hours, you remove a few files and nobody is harmed. Caught in six weeks, you are dealing with suspensions, blacklists, an abuse investigation, and people who lost money.
Our security monitoring service exists for exactly this gap.
If you have had an abuse report
This is one to act on immediately. Our WordPress security and error fixing service handles phishing incidents including evidence preservation, full clean-up, backdoor removal, and the delisting requests across every blacklist you have landed on.
Send us your web address and the report you received.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.