Phishing Attacks Against Website Owners: What They Target and How to Stop Them

reading time Reading Time: 31 minutes

Table of Contents

Most phishing advice is written for employees being tricked into paying a fake invoice. Very little is written for the specific person reading this: someone who owns or runs a website, and who therefore holds a set of credentials that attackers value far more than a single fraudulent payment.

The distinction matters because the attacks are different. Nobody phishes a small business owner's hosting login hoping for a wire transfer. They do it because a hosting control panel, a domain registrar account or a WordPress administrator login is a durable asset. It can be used to inject spam links into your pages, host phishing content under your domain, redirect your traffic, read your email, or simply hold your business hostage.

There is also a consequence specific to website owners that ordinary phishing guidance never covers: if your site is compromised and used to serve malicious content, search engines can flag it, browsers can show visitors a warning before they reach you, and you can lose the organic visibility it took years to build. Recovery is a process rather than a switch.

This guide covers the phishing attacks aimed specifically at people who run websites, including a mail-based scam that has targeted Canadian businesses for over two decades and prompted enforcement action by the Competition Bureau. It also covers a verification procedure you can apply to any notice claiming to be from your host, registrar or Google, and what to do in the hours after someone in your organisation clicks something they should not have.

Why website owners are a specific target

It helps to understand what an attacker is actually buying with your credentials, because it explains which accounts they go after and how hard they will work.

Account compromised What the attacker gains Why it is valuable to them
Hosting control panel File access, database access, email accounts, DNS in some configurations Total control of the site. Can inject content, install backdoors, and read anything stored
Domain registrar DNS records, nameservers, ability to transfer the domain away The most damaging of all. Control the domain and they control the site and the email, regardless of who holds the hosting
WordPress administrator Content, users, plugins, themes, the ability to install code Easy to monetise through injected spam links or redirects, and easy to persist through a hidden admin account
Business email Password resets for everything else, plus your correspondence The pivot point. Email access usually unlocks hosting, registrar and payment accounts in turn
Payment or billing portal Card details, billing addresses Direct fraud, and the credibility to impersonate you convincingly

Two things follow. First, the domain registrar account is the one to protect hardest, and it is usually the one with the weakest security because it is touched once a year. Second, email is the master key. An attacker who reaches your inbox does not need to phish anything else; they can reset it.

The five phishing vectors aimed at website owners

These are the patterns that recur, roughly in order of how often they succeed against small businesses.

Vector The hook The tell
Domain renewal notices Your domain is expiring; pay now or lose it Arrives by post or from an unfamiliar sender. Names a company that is not your actual registrar
Hosting account alerts Your account is suspended, over quota, or has a failed payment Links to a login page on a domain that is not your host's. Urgency without a ticket reference
WordPress security or update alerts A critical plugin vulnerability requires immediate action WordPress does not email you asking you to log in via a link. Legitimate updates happen in your dashboard
Registrar transfer requests Confirm this transfer, or an unauthorised transfer is in progress You did not initiate a transfer. Real transfer notices reference a specific domain and an auth code
Fake Google or Search Console notices Your site has been penalised, deindexed, or needs verification Google communicates through Search Console itself. Check the account, never the link

The common structure is worth naming because recognising it is faster than evaluating each message: an authority you do depend on, a consequence you genuinely fear, a deadline that removes deliberation, and a link that takes you somewhere to type a password. When all four are present, treat the message as hostile until you have verified it independently.

Domain slamming: the scam that has targeted Canadian businesses for twenty years

This one deserves its own section because it is unusually persistent, unusually Canadian, and unusually effective on exactly the audience reading this. It also often arrives by post rather than email, which is precisely why it works: a letter feels more official than an inbox.

How it works

The practice is called domain slamming. An operator that is not your registrar sends you an official-looking notice, frequently designed to resemble an invoice, telling you your domain name is expiring and offering renewal at listed prices with a payment stub. If you pay, you have not renewed anything. Depending on the variant, you have either bought a different domain you did not want, or authorised a transfer of your domain away from your actual registrar to theirs.

The mailing list comes from public registration data. WHOIS records historically exposed the registrant's mailing address, and operators harvested those addresses to target domain owners directly. That is why the letter knows your business name and your domain, which is the detail that makes it feel legitimate.

There is a second variant that arrives by email rather than post. Rather than a renewal, it implies your domain ownership is somehow in question and recommends you register the same name in additional extensions to protect your brand. That is a sale dressed as a warning.

The Canadian enforcement history

This is not a theoretical risk, and Canadian authorities have been dealing with it for over two decades. The Canadian Intellectual Property Office maintains an IP Scam Awareness Zone that names domain slamming explicitly, describing operators who pose as your domain registrar and request renewal payments, and pointing readers to the Canadian Internet Registration Authority's advisory. CIRA is the organisation that actually administers .ca.

The Competition Bureau has issued warnings to Canadian businesses about deceptive domain renewal mailings, and enforcement action has followed in more than one case, including a prohibition order and fine against an operator sending deceptive domain renewal mailouts to Canadian businesses and non-profits. Separately, an operator trading as the Domain Registry of Canada had its certification to register .ca domains revoked by CIRA following domain slamming incidents. None of these organisations has any affiliation with the Government of Canada, despite letters designed to imply otherwise.

How to be immune to it permanently

This is one of the few attacks you can defend against structurally rather than through vigilance.

  • Know who your registrar actually is, and write it down somewhere your whole team can see. Most people who fall for this cannot immediately name their registrar, which is the entire vulnerability.
  • Verify by logging in to your registrar directly, never through a link or a phone number printed on the notice.
  • Enable auto-renewal and set your own calendar reminder, so a renewal notice is never news to you.
  • Enable registrar transfer lock, which prevents a transfer being initiated without you unlocking it deliberately.
  • Use WHOIS privacy protection where available, which reduces how easily your address is harvested.
  • Treat any postal notice about your domain as marketing until proven otherwise. Your registrar will contact you by email, in your account, or both.

If you receive one, CIRA has asked that copies be forwarded so it can act, and deceptive marketing can be reported to the Competition Bureau. Keeping a copy costs nothing and is more useful than throwing it away.

Hosting account phishing

The hosting variant plays on a fear that feels plausible to anyone running a business site: that the site is about to go down, or already has.

The recurring pretexts are narrow. Your account has been suspended for a policy violation. A payment failed and service will be interrupted. You have exceeded a resource limit and must act. Your server has been compromised and requires immediate verification. Each one drives you toward a login form on a domain that looks close enough to your host's to pass a glance.

What makes these effective is that the legitimate versions of these emails exist. Hosts do send suspension notices and payment failure warnings. So the defence cannot be recognising an implausible message; it has to be a habit.

The habit that solves most of this

Never log in via a link in an email about your account. Not once, not when it looks right, not when you are in a hurry.

Instead, open a new tab, type your host's address yourself or use your own bookmark, and log in there. If the message was genuine, the notice will be waiting in your account. If nothing is there, the message was not genuine.

This single habit defeats the overwhelming majority of credential phishing regardless of how convincing the message was, because it removes the attacker's link from the process entirely.

One further note specific to hosting. If you receive a notice claiming your site is compromised, the correct response is still to verify independently rather than to click, but do verify. Compromise notices are sometimes real, and a genuine one is worth acting on quickly. Check your host's control panel, check the Security Issues report in Search Console, and contact your host through a number or ticket system you already had.

WordPress administrator phishing

WordPress runs a large share of small business sites, and its administrator login is a well-understood target with a well-understood set of pretexts.

The common ones: a critical vulnerability in a plugin you actually use, requiring you to log in and apply a patch; a fake core update notice; a security scan result claiming malware on your site; a message appearing to come from a plugin developer about licence renewal; or a fake notice from your host about your WordPress installation specifically.

The structural defence is that WordPress does not work that way. Core and plugin updates appear in your dashboard, and you apply them there. No legitimate update process begins with an email asking you to enter your administrator password on a web page. If you internalise only that, most of this vector closes.

Beyond recognition, WordPress gives you specific tools worth using:

  • Give every person the least privileged role that lets them do their job. A contributor who is phished cannot install a backdoor; an administrator can. We cover this in WordPress user roles and site security.
  • Limit the number of administrator accounts to the smallest workable number, and audit the list quarterly. Orphaned admin accounts from former staff or agencies are a standing risk.
  • Enable two-factor authentication on every administrator account without exception.
  • Limit login attempts and consider restricting access to the login page by IP where practical.
  • Keep core, themes and plugins current, since a phished credential and an unpatched vulnerability are two routes to the same outcome. See why patching matters for online security.
  • Remove plugins and themes you no longer use rather than deactivating them, because deactivated code is still code on your server.

If you would rather not carry the maintenance burden, managed WordPress hosting moves updates, patching and server-level hardening to the provider, which removes a category of risk rather than reminding you about it.

Fake Google and Search Console notices

A newer and increasingly common vector, aimed at anyone who cares about their search visibility, which is a reliable emotional lever for a business owner.

The pretexts: your site has received a manual penalty; your pages have been removed from the index; your Search Console verification has expired; your Business Profile requires reverification or will be suspended; or a new AI-related requirement demands you take action. Some of these mimic real Google communications closely, and a few reference genuine Google features to add credibility.

The verification rule is simple and absolute. Google communicates about your site inside Search Console. If there is a manual action against your site, it appears in the Manual Actions report. If there is a security problem, it appears in the Security Issues report. Both are visible when you log in to Search Console yourself. An email claiming a penalty that is not reflected in your Search Console account is not describing a real penalty.

A related scam worth naming since it targets the same anxiety: unsolicited email claiming your site is not indexed by Google and offering to fix it for a fee. Google's own guidance on hiring an SEO recommends treating unsolicited search-engine email with the same scepticism as any other spam. It is also frequently just inaccurate. If you want to know whether a page is indexed, check it yourself with URL Inspection, or read our SEO services material on diagnosing it properly.

What actually happens if an attacker succeeds

This is the part most phishing guidance omits for website owners, and it is the part that determines how urgently you should treat prevention.

The immediate technical damage

Typical outcomes: spam links injected into your existing pages, often invisibly; new pages created on your domain serving pharmaceutical, gambling or counterfeit content; phishing pages hosted under your domain to attack other people using your reputation; redirects sending some visitors, sometimes only mobile visitors or only search visitors, to another site; a hidden administrator account for persistence; and malware served to your visitors.

The redirect variants are particularly damaging because they are designed to hide from you. A redirect that triggers only for visitors arriving from search results, and not for a logged-in administrator typing the address directly, can run for weeks before anyone notices.

The search and reputation damage

Search engines detect malicious content, and the consequences arrive quickly. Google's Security Issues report in Search Console flags detected problems including malware and deceptive pages. Browsers can display an interstitial warning to visitors before they reach a site flagged as unsafe, which stops traffic in a way no ranking drop does. Where injected content or cloaked redirects are detected, a manual action can follow, and pages can lose visibility entirely.

The recovery sequence is: clean the site completely including any backdoors, patch whatever allowed entry, rotate every credential, then request a review through Search Console and wait. The waiting is the expensive part. Meanwhile your email deliverability may also suffer if your domain was used to send spam, and rebuilding a sending reputation is slower than rebuilding a site.

This is why phishing is a search visibility issue and not only an IT issue. The compromise is a bad afternoon. The consequences are a bad quarter.

A verification procedure for any notice

Rather than trying to memorise the tells of each attack, use one procedure for every message claiming to be from your host, registrar, Google, or any platform you depend on. It takes under two minutes.

  • Stop before clicking anything. Urgency is the attack, not the situation. Nothing genuine is destroyed by two minutes of verification.
  • Ask whether you were expecting this. An unexpected notice about an account you have not touched deserves more suspicion than a reply to something you initiated.
  • Check the sender address properly, not the display name. Display names are trivially forged.
  • Do not click the link. Go to the service directly, using your own bookmark or by typing the address, and log in there.
  • Look for the notice inside the account. Genuine account problems are visible in the account. Real Google issues appear in Search Console.
  • For domain notices, confirm who your actual registrar is before doing anything else.
  • If uncertain, contact the provider using a number or ticket system you already had, never contact details from the message.
  • Report and delete. Report it to the provider being impersonated so they can warn others.

Write this down and give it to everyone with access to anything. A procedure survives a stressful Tuesday afternoon in a way that general awareness does not.

Defences that work even when someone clicks

Assume that eventually somebody will click. The goal is that a clicked link and an entered password do not result in a compromised business.

Defence What it stops Notes
Phishing-resistant authentication Credential theft, even when the password is entered on a fake page Passkeys and hardware security keys are bound to the real domain, so they do not work on a lookalike site. The strongest single control available
Two-factor authentication (app-based) Most credential reuse Far better than nothing. Note that codes can still be relayed by a real-time phishing page, which is why passkeys are stronger
Registrar transfer lock Domain theft and slamming transfers Set once, protects continuously. Almost nobody enables it
A password manager Password reuse, and it will not autofill on a lookalike domain The refusal to autofill is itself a warning signal worth heeding
Least-privilege access Escalation after a compromise A phished editor cannot install code. A phished administrator can
SPF, DKIM and DMARC Attackers spoofing your own domain to phish your customers or staff Protects your reputation and your recipients, not your inbox
Tested off-site backups Everything, eventually The difference between an incident and a catastrophe. Untested backups are a belief
Separate admin and daily-use accounts Casual compromise reaching privileged systems Do not read email from the account that administers your server

If you do only two things from that table, enable phishing-resistant authentication on your registrar and email accounts, and turn on registrar transfer lock. Those two cover the highest-consequence outcomes at almost no ongoing cost.

Worth adding at the site level: keep SSL certificates valid and current so your visitors have a consistent expectation of what your site looks like, and read our web application security best practices for the application-layer picture, since phishing is one of several routes to the same compromise.

If someone has already been phished

Order matters here, because doing these in the wrong sequence lets an attacker undo your work while you are doing it.

  • Change the password on the compromised account, and on any account sharing that password. Start with email, because email resets everything else.
  • Revoke active sessions and application tokens, not just the password. A password change alone does not always eject someone already logged in.
  • Enable or re-enable two-factor authentication, ideally phishing-resistant, and check whether the attacker registered their own second factor.
  • Check for persistence: new administrator accounts, changed recovery email addresses, new forwarding rules on your mailbox, added SSH keys, altered DNS records, unexpected scheduled tasks.
  • Check DNS and nameservers specifically. A changed nameserver is the quietest and most damaging modification available.
  • Scan the site and inspect recently modified files. Look at what changed, not only at what a scanner flags.
  • Check the Security Issues report in Search Console, so you learn about search-side consequences from Google rather than from a customer.
  • Notify your host. They can see server-level activity you cannot, and a competent host would rather hear early.
  • Restore from a known-good backup if the compromise cannot be fully traced, then patch before bringing the site back.
  • Consider your privacy obligations. If personal information may have been accessed, breach assessment and possible notification duties can apply. See PIPEDA and Canadian data residency, and get qualified advice rather than guessing.

In Canada, fraud and phishing can be reported to the Canadian Anti-Fraud Centre. Deceptive marketing practices, including domain renewal mailings of the kind described earlier, can be reported to the Competition Bureau, and domain-specific complaints about .ca to CIRA. Reporting will not usually recover money, and it does contribute to the enforcement record that eventually stops these operations.

When your site becomes the phishing infrastructure

There is a scenario website owners rarely consider until it happens: your site is not the target, it is the tool. Attackers who gain access frequently do not want to damage your business at all. They want somewhere reputable to host phishing pages aimed at other people.

The logic is straightforward from their side. A phishing page on a freshly registered domain gets flagged quickly. A phishing page in an obscure subdirectory of an established Canadian business site with years of history behind it survives much longer, because the domain has reputation the attacker did not have to build. Your credibility is the asset being stolen.

How it typically looks: a directory you did not create, often nested several levels deep with an innocuous name, containing a convincing clone of a bank, a courier, a government service or a cloud provider login. Your own pages are untouched, your traffic is unaffected, and nothing on your homepage looks wrong. Some operators go further and configure the pages to serve normally only to visitors arriving from a specific campaign link, showing everyone else a blank page or a 404, which defeats casual checking.

The consequences arrive from directions you are not watching. Browser safe-browsing systems flag the domain, so your legitimate visitors start seeing a warning interstitial before they reach you. Your domain can end up on blocklists, which affects email deliverability as well as web traffic. Your host may suspend the account, since they are receiving abuse reports. And you will often learn about all of this from a customer rather than from a monitoring system.

What actually catches this: reviewing the Security Issues report in Search Console periodically rather than only when something feels wrong, watching for unexplained bandwidth or traffic in your hosting statistics, checking file modification dates in your web root occasionally, and taking abuse notifications from your host seriously rather than assuming they are mistaken. If your host contacts you about content you did not upload, they are almost certainly right.

Stopping attackers from phishing your customers using your name

The mirror image of everything above, and the part with the clearest reputational stakes. Attackers impersonate businesses to reach their customers, and if your domain is easy to spoof, you are a convenient disguise.

Three email authentication mechanisms exist to prevent this, and they work together rather than as alternatives.

Record What it does What it does not do
SPF Publishes which servers are authorised to send email for your domain Nothing on its own if receiving servers are not told what to do with failures
DKIM Cryptographically signs your outgoing mail so tampering and forgery are detectable Prevent spoofing by itself, since an unsigned message can still arrive
DMARC Tells receiving servers what to do when SPF and DKIM checks fail, and sends you reports on attempted abuse Protect your own inbox. It protects your recipients and your reputation

The practical sequence: publish SPF listing every service that legitimately sends on your behalf, which usually includes your mail provider, your website, your CRM and any marketing platform. Enable DKIM signing. Then publish DMARC starting in monitoring mode so you receive reports without rejecting anything, read those reports to find legitimate senders you forgot about, and only then tighten the policy toward quarantine and eventually rejection.

That order matters. Publishing a strict DMARC policy before you have inventoried your senders will silently break your own invoices, booking confirmations and newsletters, which is a worse outcome than the spoofing you were preventing. Monitoring mode first is not caution for its own sake; it is the only way to discover what actually sends mail as you.

Two adjacent protections worth considering. Register the obvious lookalike variants of your domain if they are cheap, particularly common misspellings and the hyphenated forms, so an attacker cannot trivially acquire a convincing near-match. And tell your customers plainly, on your site, what you will never ask them for by email. A short published statement gives a suspicious customer something to check against, and it costs one paragraph.

A special case: agencies and anyone holding client credentials

If you manage websites for other people, you are a disproportionately valuable target, and the attacks against you are usually more researched than generic phishing.

The reason is arithmetic. Compromising one agency account can yield access to dozens of client sites, and agencies routinely hold hosting logins, registrar access, WordPress administrator accounts and analytics for every client. Attackers know this, which is why agency-directed phishing tends to be targeted rather than mass-mailed: a message referencing a real client by name, or appearing to come from a client, or appearing to come from a platform the agency demonstrably uses.

Practices that materially reduce the exposure:

  • Never share credentials. Use each platform's own delegated access so clients grant you permissions rather than handing over passwords, and so access can be revoked without a password change.
  • Keep client access in a password manager with per-client separation and audited sharing, not in a spreadsheet or a shared inbox.
  • Use phishing-resistant authentication on your own accounts, since yours are the keys to everyone else's.
  • Offboard properly. When an engagement ends, revoke your access deliberately and confirm the client has removed you. Lingering agency access is a standing risk for both parties.
  • Verify unusual client requests out of band. A client email asking you to change DNS urgently is worth a phone call, and business email compromise frequently arrives as exactly that.
  • Keep an inventory of what you hold for whom. If you are compromised, the first question is scope, and you cannot answer it from memory.

The same logic applies in reverse if you are a business that uses an agency. Grant delegated access rather than sharing your password, keep your own administrator account, and remove access when the relationship ends. Being phished through your agency is still your outage.

Training that works, and awareness theatre that does not

Most phishing training is delivered once, generates a completion certificate, and changes nothing. A few things genuinely help.

What works: a written verification procedure that people can follow under pressure, of the kind in the previous section. Making it explicitly safe to report a mistake, because the damage from a phished credential multiplies with every hour it goes unreported, and shame is the main cause of delay. Naming the specific attacks your business will actually see, since a hosting suspension notice is more relevant to your team than a generic warning about suspicious attachments. And removing the decision entirely where you can, which is what phishing-resistant authentication does.

What does not work: annual slide decks with a quiz. Punishing people for clicking, which reliably converts a reportable incident into a concealed one. Advice to look for spelling mistakes, which stopped being useful years ago. And expecting vigilance to substitute for controls, since the whole design assumption should be that someone will eventually click.

One organisational detail worth getting right: decide now who is called when something goes wrong, and make sure that person's contact details are available outside the systems that might be compromised. An incident response plan stored only in the email account that has just been taken over is not a plan.

Ten mistakes that make website owners easy targets

Mistake Why it matters
Not knowing who your registrar is The entire vulnerability behind domain slamming. If you cannot name it, you cannot verify a notice
Leaving registrar transfer lock off A single setting that prevents the highest-consequence attack available
Logging in via links in emails The habit that makes every other defence optional
No two-factor authentication on the registrar The least-visited account is usually the least protected and the most damaging to lose
Administering the server from your daily email account One compromise then reaches everything
Everyone is an administrator Turns any phished individual into a full compromise
Orphaned admin accounts Former staff and agencies whose access nobody revoked
Deactivating plugins instead of removing them Deactivated code is still code on your server
Assuming a compromise would be visible Search-only and mobile-only redirects are designed to hide from you specifically
Untested backups The recovery plan nobody has ever run is not a recovery plan
No DMARC policy Leaves your domain easy to spoof, which makes your customers the victims and your brand the disguise
Sharing passwords with an agency Removes accountability and means access cannot be revoked without disrupting everyone
Punishing staff for clicking Converts a reportable incident into a concealed one, which is far more expensive

Conclusion

Phishing aimed at website owners is a narrower and more predictable problem than general security anxiety suggests. The attacker wants one of five accounts, uses one of five pretexts, and relies on you clicking a link rather than opening a browser tab yourself. That is a small enough surface to defend deliberately.

The highest-value actions are unglamorous and mostly one-off. Find out who your registrar is and write it down. Turn on transfer lock. Put phishing-resistant authentication on your email and registrar accounts. Reduce the number of administrators on your site. Test a backup restore once. Adopt the habit of never logging in from an email link, and give the verification procedure to everyone with access.

The reason to treat this as a business priority rather than an IT chore is the consequence. A compromised website is not only a technical problem: browser warnings stop visitors before they arrive, search visibility can be lost while a review is pending, and email deliverability can take longer to rebuild than the site itself. The compromise takes an afternoon and the recovery takes a quarter.

If you would rather have more of this handled at the platform level than on your own checklist, that is a reasonable choice: reliable Canadian web hosting with server-level hardening and patching, managed WordPress hosting for a maintained WordPress environment, and domain registration kept with a registrar you can actually name all reduce the number of things left to your vigilance. And if you are mid-migration or inheriting a site from someone else, changing hosts without losing rankings covers the handover checks worth running while you have the access to run them.

9. FAQ

12 questions, each self-contained for featured snippets and AI answer engines.

What is domain slamming?

A scam in which an operator that is not your registrar sends an official-looking notice, often by post and often resembling an invoice, claiming your domain is expiring and offering renewal. Paying does not renew anything: depending on the variant you have bought a domain you did not want or authorised a transfer away from your real registrar. Canada's Intellectual Property Office names the practice explicitly in its IP scam guidance and points to CIRA's advisory.

I received a domain renewal letter in the mail. Is it legitimate?

Probably not, and you can settle it in two minutes without engaging with the letter. Log in to your actual registrar directly and check your renewal date and status there. If the company on the letter is not your registrar, it is marketing at best. Keep the letter, forward a copy to CIRA for a .ca domain, and consider reporting deceptive marketing to the Competition Bureau.

How do I tell a real hosting email from a phishing email?

Do not try to judge the message. Open a new browser tab, type your host's address or use your own bookmark, and log in. A genuine account problem will be visible in your account. If nothing is there, the message was not genuine. This habit works regardless of how convincing the email looked, because it removes the attacker's link from the process.

Does Google email website owners about penalties?

Google communicates about your site inside Search Console. Manual actions appear in the Manual Actions report and security problems in the Security Issues report, both visible when you log in yourself. An email claiming a penalty that is not reflected in your Search Console account is not describing a real penalty. Google's own guidance also recommends treating unsolicited search-engine email with the scepticism you would apply to any spam.

What happens to my SEO if my site gets hacked?

Search engines detect malicious content and act on it. Detected malware or deceptive pages appear in the Security Issues report, browsers can show visitors a warning before they reach your site, and where injected content or cloaked redirects are found a manual action can follow with significant visibility loss. Recovery means cleaning the site fully, patching the entry point, rotating credentials, then requesting a review and waiting.

What is phishing-resistant authentication and do I need it?

Passkeys and hardware security keys are cryptographically bound to the real website domain, so they do not function on a lookalike phishing page. That makes them fundamentally stronger than app-based codes, which can still be relayed in real time by a convincing fake login page. If you enable it on only two accounts, choose your email and your domain registrar, since those are the highest-consequence to lose.

Is app-based two-factor authentication good enough?

It is far better than a password alone and worth enabling everywhere. It is not equivalent to phishing-resistant authentication, because a real-time phishing page can prompt you for the code and relay it immediately. Treat app-based codes as a strong baseline and passkeys or security keys as the upgrade for your most important accounts.

Should I use WHOIS privacy protection?

Where it is available for your domain type, yes. Public registration data has historically been harvested to target domain owners with slamming letters and phishing, so reducing your exposure removes you from some of those lists. It is not a complete defence, since operators have other sources, and it costs little or nothing.

What is registrar transfer lock?

A setting in your registrar account that prevents your domain being transferred to another registrar until you deliberately unlock it. It defends against the highest-consequence attack available, because whoever controls your domain controls your website and your email. It takes a minute to enable and almost nobody does it.

Someone on my team entered their password on a fake login page. What now?

Work in order. Change that password and any account sharing it, starting with email. Revoke active sessions and tokens rather than only changing the password. Enable or re-enable two-factor authentication and check whether an attacker added their own. Then hunt for persistence: new admin accounts, changed recovery addresses, mailbox forwarding rules, added SSH keys, altered DNS and nameservers. Check the Security Issues report, notify your host, and restore from a known-good backup if you cannot fully trace what happened.

Do I have privacy obligations if a phishing attack exposed customer data?

Possibly. Under PIPEDA, organisations have obligations relating to breaches of security safeguards, including assessing real risk of significant harm and, where that threshold is met, notification duties. The specifics depend on your circumstances and your province, so this is a question for a qualified privacy professional or lawyer rather than for your hosting provider.

Where do I report phishing in Canada?

Fraud and phishing can be reported to the Canadian Anti-Fraud Centre. Deceptive marketing practices, including misleading domain renewal mailings, can be reported to the Competition Bureau. Complaints specific to .ca domains can go to CIRA. Also report the message to whichever provider was impersonated, so they can warn other customers.

10. Key takeaways

  • Attackers phishing website owners want one of five accounts: hosting, registrar, WordPress admin, email, or billing. Email is the pivot, because it resets the others.
  • The registrar account is the highest-consequence to lose and usually the least protected, because it is touched once a year.
  • Domain slamming has targeted Canadian businesses for over two decades. Canada's Intellectual Property Office names it explicitly and the Competition Bureau has taken enforcement action.
  • If you cannot immediately name your registrar, that is the vulnerability. Write it down.
  • Registrar transfer lock takes a minute to enable and defends against the worst outcome available.
  • Never log in from a link in an email. Open a tab, type the address, log in there. One habit defeats most credential phishing.
  • Google communicates about your site inside Search Console. A penalty email not reflected in your account is not a real penalty.
  • Passkeys and security keys are bound to the real domain, so they do not work on a fake login page. App-based codes can still be relayed in real time.
  • Your site may be compromised as phishing infrastructure rather than as a target, because your domain reputation is the asset being stolen.
  • Publish SPF, DKIM and DMARC, starting DMARC in monitoring mode, so attackers cannot spoof your domain to phish your customers.
  • Agencies holding client credentials are disproportionately targeted. Use delegated access, never shared passwords.
  • The compromise takes an afternoon; browser warnings, lost visibility and rebuilt email reputation take a quarter.

Get in Touch

message
Your form has been submitted successfully.
We'll be in touch with you shortly.
Your email address will not be published. Fields marked with an asterisk (*) are mandatory.
+1 S
You may also like: