🚨 Phishing site impersonating email provider – silly-croissant-d7294a.netlify.app

Post content:

Hello Netlify Team,

I would like to report a phishing site hosted on your platform that is actively attempting to steal login credentials from unsuspecting users.

  • Site name (Netlify subdomain): silly-croissant-d7294a.netlify.app
  • Issue type: Abuse / Phishing / Fraudulent impersonation
  • Target of impersonation: A legitimate German email provider

:pushpin: Description:

The page falsely claims that a user’s email account is scheduled for deactivation and urges them to click a button to “Cancel Deactivation Request.” This leads to a fake login interface designed to collect credentials.

The link was distributed via a suspicious email that has already been flagged as spam and is part of a credential harvesting campaign.


:warning: Why this is urgent:

This violates Netlify’s Terms of Use and poses a security risk to users. Please review and take appropriate action to remove the site.

Thank you in advance for your help.

Best regards,

@mbehring For future reference, when reporting Fraud/Abuse you will get a faster result by:

Using the Support Form here:
https://www.netlify.com/support/?topic=Report+Fraud+or+Abuse

Or the Abuse link on the bottom of the Netlify site:

To send an email to fraud@netlify.com