+ ← all writeups
+
+
+
+ case closed
+ security research
+
+ destroying a live parking phishing campaign
+
+ a fake parking-payment site was impersonating a real brand and collecting card data.
+ the campaign is gone now. this is the public version of what happened.
+
+
+
+
+
+ the job started with the usual smell: a parking-payment domain that looked close enough
+ to be trusted by someone in a hurry, but not close enough to survive inspection. the goal
+ was not to be dramatic. the goal was to gather evidence, route it to the right abuse desks,
+ and keep eyes on the target until it stopped being useful to the operators.
+
+
+
evidence first
+
+ takedowns work best when the evidence is complete and boring. i captured the landing page,
+ response headers, client scripts, hashes, screenshots, dns, hosting data, registrar path,
+ and the live collection behavior. nothing fancy, just a clean bundle that makes it easy for
+ every responsible party to act without another round trip.
+
+
+
pressure in the right places
+
+ the reporting path hit the infrastructure provider, registrar-side abuse channel, browser
+ blocklists, and the impersonated brand. public writeups should not include live endpoints,
+ operational tricks, or reusable indicators that help the next kit operator, so those details
+ stay out of this page.
+
+
+
result
+
+ - identified hosting, registrar, nameserver pattern, and collection flow
+ - submitted usable evidence to the parties that could actually take action
+ - monitored the campaign until it stayed down
+ - retired the monitors once the operation was no longer alive
+
+
+
+ the useful lesson: good anti-phishing work is paperwork with teeth. if the proof is clean,
+ the target is real, and the escalation path is correct, a campaign can disappear without
+ turning the process into theater.
+
+
+
+