⚡ Found something damaging online? Get a FREE Confidential Exposure Scan → · Urgent? Response within 1 hour →
📁 Case Study · Attack Website

A founder, an offshore host, and the site built to end him

The founder of an international property group was named on an anonymous "scam" website: stolen photos, fraud allegations, his wallet addresses, claims about his health. The host was offshore and proud of it. He hesitated to act, on the theory that cutting one head grows two.

Attack website removed from Google search results
3 weeks

from instruction to Google confirming removal

2

other vendors had already failed on the same target

The situation

The site had one purpose. It named the founder and his associates, carried stolen photographs, alleged fraud and money laundering, published cryptocurrency wallet addresses to trace his personal finances, made claims about drug use and rehab, solicited further material from readers through an anonymous mailbox and urged them to report him to law enforcement. A marketing agency was buying search ads against his name plus "reviews" to push it higher. He believed the operator was a specific, technically capable individual.

His first instinct was to leave it. Remove it and he builds another. We put the counter-argument plainly: delay favours the attacker, because every month the site stays indexed it gathers links, screenshots and readers, and a second site is easier to fight when the first has already been taken down on grounds that travel. Eighteen days later he instructed us.

Why a single-purpose attack site is different from bad press

A newspaper archive is indifferent to you. An attack site is designed around you. Every element of it, from the domain name to the page titles to the choice of photographs, is built so that a search for the founder's name returns it, and the operator maintains it in response to whatever the target does. That is a different problem from an article that was published once and forgotten.

It also escalates in ways press does not. Wallet addresses turn a reputational page into a financial surveillance tool. An anonymous mailbox soliciting further material turns readers into contributors, which is how a single-page site becomes an archive. An appeal to report the subject to law enforcement is an attempt to convert online allegations into official attention. Paid search against the name plus "reviews" buys visibility that the site could not earn.

The combination of health claims, criminal allegations and stolen photographs is also, in practical terms, an opportunity. Content that would be merely offensive on an ordinary complaint site becomes squarely regulated material once it publishes health information and criminal-offence allegations about a named living person, and that is what made the routes here available.

The objection every founder raises

Cut one head off and two grow back. It is the most common reason founders leave an attack site up, and it is not silly. The operator here was active and technically capable and the founder said so in writing before instructing us.

The reason to act anyway is that time is not neutral. Every month a site stays indexed, it accumulates inbound links, cached copies, screenshots on other platforms and readers who will recognise it later. It also becomes reference material: a second site built on the remains of a first one starts with an audience and a set of allegations already in circulation, and the evidence you would need to fight it degrades as pages change.

The other half of the answer is that grounds travel. An argument that persuaded a host or a search engine once is an argument that can be filed again within days against a new domain, with the file already built and the identity evidence already accepted. Establishing a route on the first site is what makes the second one a short matter instead of a long one.

The host said no

The site sat with an offshore host selected for exactly this situation. We did not argue defamation, because defamation is the argument such hosts are built to refuse. We argued the host's own zero-tolerance clause on doxxing, its phishing and scam clause, and GDPR Articles 6, 9 and 10 on the publication of health data and criminal-offence data. The host declined, demanded a court order from its own jurisdiction and said the decision was final. We escalated to its legal and compliance function and rejected the finality.

Hosts that market themselves on resistance to takedown requests are advertising to exactly the customers who need it, and their public position is that they do not remove lawful content on a complainant's say-so. Arguing that a page is untrue invites the answer they have prepared. Arguing that a page breaks the terms the host itself wrote, or that it publishes categories of personal data with no lawful basis, is a different conversation and it reaches a different department.

A refusal that says the decision is final is also not always final. Abuse desks and legal or compliance functions are separate, they apply different standards, and an escalation with a properly evidenced data-protection argument is assessed by people whose job is the company's own exposure rather than customer service.

Why the argument was built on data protection, not truth

Defamation asks whether something is false. That requires a decision about facts, which is why hosts and search engines point to courts, and why an offshore host in a jurisdiction chosen for hostility can simply decline to engage.

Data protection asks a different question: whether there is a lawful basis to publish this information about this identified living person. Health information and allegations about criminal offences are treated as especially sensitive categories, with narrow conditions for processing them, and the balance against freedom of expression and journalism is not automatically resolved in favour of an anonymous site with no publisher, no byline and no editorial process.

That framing has three advantages. It does not require the founder to prove a negative. It applies to the site and to the search results independently, so the same file supports both applications. And it is portable, which matters when the operator is expected to try again.

Winning at Google

The same personal-data grounds went to Google as a legal de-indexing request the day the host was first approached, supported by passport-backed identity verification. Three weeks after instruction Google confirmed removal of the site from results for the founder's name, and reconfirmed it a week later. Source removal continued against the host.

Filing at both layers on the same day is deliberate. The host and the search engine are independent decision makers with different obligations, and a refusal by one says nothing about the other. Waiting for the host to answer before approaching the search engine would have cost weeks on a site that was actively being promoted through paid search.

Identity verification is what makes a personal-data application processable. A request of this kind is a personal right, so the applicant has to establish who they are, and a passport-backed submission removes the first and most common reason such requests are closed without review.

What verification looked like

Every claim in this matter was tied to a dated screenshot. The founder had retained two other vendors on the same target and initially credited them for the outcome; we showed him, with dated evidence, that the removal followed our submission and matched the reply we had received.

That is not a point about credit. It is a point about what happens when several parties work the same target at once, which is common for founders under sustained attack. Without dated before-and-after records tied to specific URLs and specific replies, nobody can tell which route worked, and the next matter is planned on a guess. The record is what lets a founder decide where to spend effort the second time.

Checks were run logged out and repeated after the confirmation, because a de-indexing result propagates unevenly and a founder searching from his own machine sees a personalised version of the page. The reconfirmation a week later existed for exactly that reason.

What to do first if a site exists to attack you, and what to avoid

Preserve everything immediately, and preserve more than you think you need. Full-page dated screenshots of every page, the source of the pages, the image files and their addresses, any advertising you can see pointing at the site, and copies of anything the site has taken from you. Attack sites are edited constantly, and evidence collected today is the file every route will be built on.

Identify what is legally distinctive rather than what is most upsetting. Stolen photographs, health claims, criminal allegations, financial identifiers and appeals for readers to supply material are the elements that engage host policies and data-protection rules. The general accusation that you are dishonest, which is usually what the target fixates on, is the weakest part of the page from a removal point of view.

Do not contact the operator, do not respond to an anonymous mailbox and do not pay anyone who offers to make it go away. Contact confirms the target is reading, which is the feedback an operator wants, and payment marks you as someone who pays. Do not publish a rebuttal, since a public response gives the site a new hook and a fresh reason to be linked.

Do not run several vendors on the same target without a single evidence record, and do not file scattershot do-it-yourself reports on grounds that do not fit. Both make the sequence unreadable afterwards, and refusals recorded against a URL make the properly built application that follows harder to get reviewed.

Who makes first contact and what the 15-minute call covers

Founders in this position often make contact themselves, and often after weeks of deciding whether to act at all. Sometimes it is their lawyer, their chief of staff or their head of security, particularly where the site publishes financial identifiers or personal movements and the matter has become a safety question as much as a reputational one.

The 15-minute call covers what the site publishes, what of it is verifiably yours, who is hosting it, what is being paid to promote it, what you know about who is behind it, and what has already been tried. We say which grounds we would use and which we would not, and we say plainly when defamation is the wrong instrument even though it feels like the right one.

The free Exposure Scan afterwards maps the site, its copies, the search and advertising footprint around it and the related properties that usually accompany a single-purpose attack. It is written down and it is yours to keep. Confidentiality and an NDA are standard, and the work sits alongside your counsel, your public relations advisers and your security team rather than replacing any of them.

What this shows founders

A hostile host in a jurisdiction chosen for hostility was routed around by attacking its own published rules and its data-protection obligations rather than the content's truth. The site left Google inside three weeks of instruction. The objection every founder raises, that one head becomes two, is answered by acting while the grounds are fresh and the evidence is intact.

Two other vendors had been retained on the same target without achieving removal, which is worth reading as a comment on strategy rather than on effort. Against a host that has publicly committed to refusing takedown requests, the argument you choose decides the outcome, and the argument most firms reach for first is the one that host is built to reject.

The last point is about layers. Removal from search stopped the harm that was actually being done, because a site nobody can find on the founder's name reaches almost nobody. Source removal continued afterwards, and it should, because a page that still exists can still be linked, screenshotted and rediscovered.

If a site exists to attack you, read our attack website page or book the free Exposure Scan.

OutcomeDetail
ContentAn anonymous single-purpose "scam" site naming the founder and associates: stolen photographs, fraud and money-laundering allegations, published crypto wallet addresses tracing personal finances, allegations about health and rehab, an appeal for readers to send more material and report him to law enforcement
AmplificationA marketing agency buying search ads against the founder's name plus "reviews"
HostAn offshore host chosen for its resistance; refused outright, demanded a local court order and called the decision final
ArgumentDeliberately not defamation: the host's own doxxing and phishing clauses, plus GDPR Articles 6, 9 and 10 on special-category and criminal-offence data
GoogleLegal de-indexing request on the same personal-data grounds, supported by identity verification; removal confirmed 3 weeks after instruction and reconfirmed a week later
OthersTwo other vendors retained on the same target had not achieved removal
★★★★★

"The attacker is active and tech savvy, if we remove this website now he will most likely create another one."

— The founder, before instructing us

Facing something similar?

This case was handled through our Attack website removal service.

Attack website removal →

← All case studies

Start with a free, confidential Exposure Scan

We'll scan your digital footprint, show you exactly what's exposed, and recommend the fastest path to remove it, or tell you honestly if you don't need us.

Book Your Assessment
Free · Confidential · 15 minutes