Where to report phishing in your country

    National reporting bodies collect evidence and can act inside their jurisdiction. They rarely remove the website itself: that is decided by the hosting provider and the registrar, wherever they happen to be. This page lists the official channels per country and explains how the two routes fit together.

    6 min readUpdated September 19, 2026

    Two routes, different outcomes

    Reporting phishing has two independent paths. The national route goes to your country's CERT, police or consumer authority: it builds the case record, feeds national statistics and can lead to prosecution. The infrastructure route goes to the hosting provider, the registrar and the browser blocklists: this is the path that actually gets a page removed or blocked, usually within hours.

    Both are worth doing. They do not compete, and neither one replaces the other.

    National and international reporting bodies

    Links go to the official reporting entry point of each organisation. If your country is not listed, use the FIRST directory to find the responsible national CERT.

    Country / regionReporting bodyWhat it handles
    GlobalAPWG (eCrime Exchange)Cross-border phishing clearinghouse used by browsers, registrars and banks.
    Globaleconsumer.govJoint consumer-fraud complaint portal of 40+ national consumer agencies.
    GlobalFIRST CSIRT directoryDirectory to find the national CERT/CSIRT responsible for your country.
    United StatesFBI IC3Internet Crime Complaint Center for phishing, fraud and financial loss.
    United StatesCISAReports phishing and malicious infrastructure affecting US organisations.
    United KingdomNCSC Suspicious Email Reporting ServiceForward phishing emails to report@phishing.gov.uk; scam sites via the web form.
    GermanyBSIFederal Office for Information Security; handles phishing and malware reports.
    FranceANSSI / CybermalveillanceNational cybersecurity agency and the public victim-assistance portal.
    NetherlandsFraudehelpdeskNational reporting point for fraud, phishing and scam websites.
    CanadaCanadian Anti-Fraud CentreCentral intake for fraud and phishing affecting Canadian residents.
    AustraliaACCC Scamwatch / ACSCScam reporting for consumers and the national cyber incident channel.
    IndiaCERT-In / Cyber Crime PortalNational CERT and the government's cybercrime complaint portal.
    JapanJPCERT/CCCoordinates phishing and malware takedowns with Japanese providers.
    SingaporeSingCERT (CSA)National CERT for phishing and incident reporting.
    BrazilCERT.brNational incident response team; accepts phishing and malware reports.

    What Fraudpol adds on top

    Fraudpol works the infrastructure route worldwide. A report is triaged, evidence is hashed and preserved, and the case is filed with the hosting provider, the registrar and the relevant blocklists. The status of the case stays visible to the reporter until it is closed.

    Fraudpol is not a public authority and does not replace one. Use both: file with your national body for the record, and report the URL here so the site itself gets pursued.

    Start with the report form, check a suspicious address first with the domain scan, or browse confirmed abuse cases to see how cases are documented.

    What to collect before you report

    • The full URL, including any path and query string, not just the domain.
    • A screenshot of the page, taken before it disappears.
    • The original email with full headers, if the link arrived by mail.
    • Dates and times, and whether any data or money was submitted.

    Have a URL to report right now?

    Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Report a website to Fraudpol