There’s a small business owner out there right now whose website is stealing credentials from someone else’s customers. They have no idea.
Their site looks normal. Their business is running fine. But buried in a subdirectory, attackers have injected a fully functional phishing page impersonating a major brand. Every day it stays live, real people are entering their usernames, passwords, and payment details into a fake login portal hosted on a legitimate domain.
This is compromised website phishing, and it requires a completely different takedown approach than a purpose-built phishing domain.
What Is Compromised Website Phishing?
Compromised website phishing occurs when attackers exploit security vulnerabilities in a legitimate website to inject malicious content without the owner’s knowledge. Rather than registering a new domain for fraud, they piggyback on an existing site’s trusted reputation.
This isn’t rare. Compromised websites account for approximately 16% of all phishing URLs, and the average domain age for phishing attacks that successfully bypass email security gateways is over 10 years. Attackers deliberately target established, trusted domains because they inherit years of built-up reputation, making them far harder for security filters to detect and block.
You can usually spot a compromised site by its structure:
- Phishing content hosted on a subdirectory (e.g., legitimate-business.com/rewards/login/)
- New pages added that have no connection to the site's actual content
- The root domain hosts a completely unrelated, legitimate business
- Long domain registration history with no prior abuse flags
The attackers are strategic about this. They’re not targeting enterprise websites with dedicated security teams. They’re going after small businesses, local shops, and personal sites running outdated software with known vulnerabilities.
Why Attackers Target Legitimate Websites
The appeal is simple: trust and invisibility.
A newly registered domain like brand-rewards-login.com immediately raises red flags for security tools. But a phishing page hosted on a 10-year-old kitchen design company’s website? That sails through email filters, avoids domain reputation blocklists, and looks clean to most automated security scans.
The vulnerability landscape makes this easy. In 2025 alone, over 11,000 new WordPress vulnerabilities were discovered, a 42% increase year on year. 91% of those vulnerabilities came from plugins, not WordPress core. And 43% of them could be exploited without any authentication at all. Attackers aren’t breaking through advanced security. They’re walking through unlocked doors.
Once inside, they create a subdirectory, upload a phishing kit, and start distributing links. The legitimate website continues operating normally. The owner sees no disruption. The phishing page can run for weeks before anyone notices.
How to Take Down Compromised Website Phishing
Here’s where the approach diverges from standard phishing takedowns. With a compromised site, there are two victims: the brand being impersonated AND the website owner whose site has been hacked. Your goal is to remove the malicious content, not take down the entire website.
Step 1: Contact the website owner directly.
Use the contact details on their legitimate website. Send them the specific URL where the phishing content is hosted along with screenshots showing the malicious page. Keep the tone cooperative. You’re alerting them to a security breach, not accusing them of anything.
Here’s the difference:
"Your website is hosting phishing content targeting our client. Remove it immediately."
"Your website appears to have been compromised. We've identified unauthorised phishing content at [URL]. We've included screenshots below. We recommend removing this content and conducting a security review to prevent reoccurrence."
The reality: Most website owners never respond. It’s a thankless part of the job. But when they do, resolution can be very fast because they want the malicious content gone as much as you do.
Step 2: Notify the hosting provider.
If the website owner doesn’t respond, escalate to their hosting provider. This is where precise language matters. You’re requesting removal of specific malicious content, not suspension of the entire website.
Your report should clearly state:
- The specific URL path where phishing content is hosted
- That the website has been compromised (the owner is likely unaware)
- A request to disable the malicious content while preserving the legitimate website
- Screenshots showing the phishing page with timestamps
Step 3: Recommend a security review.
Whether you’re contacting the owner or the hosting provider, always include a recommendation to conduct a full security audit. If the vulnerability that allowed the compromise isn’t patched, attackers will simply re-inject phishing content after removal.
Why Website Security Maintenance Matters
Compromised website phishing is almost entirely preventable. The reason it’s so common is that many small business owners treat their website as “set and forget.” They build it, launch it, and never touch the backend again.
Here’s what that means in practice. If a WordPress site is running plugins that haven’t been updated in six months, there’s a strong chance known vulnerabilities exist that attackers can exploit without authentication. When exploits are being weaponised within hours of disclosure, outdated software isn’t just a technical risk. It’s an open invitation.
Basic security hygiene that prevents most compromises:
- Keep CMS platforms, plugins, and themes updated
- Remove unused plugins entirely (deactivating isn't enough)
- Use strong, unique admin credentials
- Enable two-factor authentication on admin accounts
- Regularly scan for unauthorised files or directory changes
These aren’t advanced security measures. They’re the digital equivalent of locking your front door.
Key Takeaways
Compromised website phishing requires a fundamentally different approach than dedicated phishing domains. You’re dealing with two victims, not one. The goal is surgical content removal, not domain suspension.
Contact the website owner first. Escalate to the hosting provider if they don’t respond. Always recommend a security review. And remember that the tone of your report matters. A security notification gets cooperation. An abuse complaint gets defensiveness.
If you’re a business owner reading this, check your website. Update your CMS. Patch your plugins. Because if your site gets compromised, you might never even know it’s happening.