Removing a website built to attack you means taking down a single purpose domain created to rank for your name or brand, such as “scambrandname.co” or “yournameexposed.com”. These sites are removable more often than people expect, because they are built quickly and almost always break rules the operator never considered.
Key facts
- An attack website is normally a single purpose domain with no publisher behind it, so the operator and the infrastructure are the only parties who can act on it.
- Almost every attack site reuses your logo, photography or sales copy, which is why these domains are more vulnerable than their operators assume.
- Hosting providers can and do act on these sites, because the safe harbour in DMCA 512 depends on them responding once properly notified.
- ICANN’s registrar accreditation obligations require registrars to keep registrant records and to operate an abuse contact, so an anonymous operator is not beyond reach.
- In England and Wales the Defamation Act 2013 requires serious harm to reputation, and Australia added a comparable serious harm element in 2021.
- Google’s legal removal process can take specific URLs out of search results even while the domain itself stays online.
What is an attack website?
An attack website is a domain registered for one reason: to sit on page one of your name. It usually has a handful of pages, no real publisher behind it, and a domain that contains your brand plus a loaded word. The content is often a mix of lifted material from your own site, screenshots of comments, a timeline of accusations, and an invitation to contact the operator.
They are not the same problem as a review page on an established site or a press article. There is no editor to negotiate with, no policy team, and no advertiser relationship to lean on. The operator is the publisher, the site exists only to hurt you, and that is both the difficulty and the opening.
Why does a small attack site outrank my company?
Because search still reads a domain name as a strong signal of what a page is about. A domain that literally contains your brand and the word “scam” is treated as an exact match for people typing that phrase, and almost nobody else has written a page targeting it. Add a few paragraphs of your own copy, your logo, your photos, and the site looks topically relevant to a crawler that cannot tell malice from journalism.
Two other things push it up. Attack sites get clicked, because the headline is dramatic, and click behaviour on a query reinforces the result. They get linked from forums and comment sections where the operator seeds them.
Who is behind it, and how do we find out?
Almost every attack domain sits behind WHOIS privacy, so the public record shows a proxy service rather than a person. That is a starting point rather than a wall. In most matters we can establish who is operating the site, or at least establish enough about the operation to make the infrastructure act, and we do that quietly before anything is filed.
Operators of these sites are rarely working alone and rarely working once. The same person usually runs a small network of near identical domains, and the connections between them tend to be visible to someone who knows where to look. Where a matter is heading toward litigation, your counsel can also compel disclosure from the companies holding the records.
We build that picture first, because a filing sent to the wrong party is a filing the operator gets to read.
Which grounds actually get an attack site removed?
More than most people expect. Attack sites are built quickly and almost always overreach: they lift your logo, your photography and your sales copy, they present themselves as something official, and they state as fact things that are demonstrably false. Each of those is a separate lever, and the strongest matters use several at once rather than betting on one.
Copyright and false statements of fact are the two that carry the most weight, and opinion is not removable, which is why the assessment matters before anything is sent. Even where a domain stays online, the URLs can often be taken out of search results for your name, and that is usually the outcome a client actually feels. See copyright infringement removal and legal content removal.
Timelines depend on the route and the platform, and are set out in writing after the free Exposure Scan.
Get a Free, Confidential Exposure Scan
How we take an attack domain down
We establish who is behind it, then act on every ground that applies at the same time rather than trying one and waiting. The aim is not a single takedown but a domain that stops resolving, pages that stop existing in caches, and a clean first page for your name, your brand and the loaded variants people actually type. You see the evidence, not the paperwork.
Where the operator is identifiable and reachable, counsel corresponds directly, and we work alongside your lawyers rather than around them. We also expect the mirror. Operators re-register the same content on a new extension within days, so the file stays open and a second domain is handled far faster than the first. The work is verified, evidenced to you, and monitored afterwards.
What if the operator wants money, or sits overseas?
Many of these sites end with an offer: pay, and it comes down. Paying is the one move we ask clients not to make. It funds the next site, it identifies you as someone who pays, and the second domain arrives faster than the first.
An overseas operator changes the tools, not the outcome. The host, the registrar, the CDN and the payment processor are frequently in the United States or the European Union even when the person is not, and each of those has policies that bind them regardless of where the operator sits. In practice, infrastructure is the pressure point, not the person.
For an anonymised example of how this runs end to end, see our supplement brand attack site case study and the trading educator case study. Educators facing a coordinated version of this can also read what we do for trading educators.
What the law and the registrar rules say
There is a route here, and it does not depend on the operator agreeing to anything.
Copyright is the fastest of the systems that apply, because a host’s own protection from liability turns on acting once it has been properly notified. That is the principle behind DMCA 512 in the United States and behind the comparable notice and action duties that apply to hosts inside the European Union. It is why an anonymous operator overseas is much less of an obstacle than it looks.
Defamation is slower and jurisdictional. In England and Wales the Defamation Act 2013 requires serious harm to reputation, and a trading company must show serious financial loss. Australia introduced a comparable serious harm element in 2021. In the United States the pressure runs through the operator and the courts rather than through a notice to the host. Underneath both sits the domain itself, where registrars carry accreditation obligations and their own terms prohibiting fraud and impersonation. Which of these is worth using in your matter is the question the Exposure Scan answers.
What we need from you to start
Very little, and none of it is hard to assemble.
- The domain or domains, plus any variants that have already been sent to you.
- Proof of ownership of anything of yours on the site: original files, or the original publication dates for your logo, photographs, video and written copy.
- Trademark registration numbers and jurisdictions if you have them. They help, but they are not required.
- A short list of the statements you say are false, with whatever contradicts each one: bank records, court outcomes, regulator correspondence, contracts, or a signed statement of fact.
- Any contact the operator has already made with you, with the full email headers rather than a screenshot.
- Written authorisation for us to file on your behalf, and confirmation of who signs where counsel is involved.
Timelines and what usually happens first
None of this is a commitment, because these outcomes sit with hosts, registrars and courts rather than with us. The first day or two is evidence and identification, and work normally begins inside the first week.
Some routes produce a visible result in days. Others run on a legal timetable and are measured in weeks or months. You get the realistic range for your matter in writing after the scan, before you commit to anything.
Common mistakes that make it harder
- Paying the operator. It funds the next domain and marks you as someone who pays.
- Replying publicly. A post on X or LinkedIn gives the site traffic, links and a second news cycle, and the operator will screenshot it.
- Filing a copyright notice on material that is arguably commentary. A counter notice puts the content back and weakens every later filing you make.
- Sending a legal letter before the infrastructure is mapped. It warns the operator to change host, harden privacy and mirror the content somewhere you have not looked.
How this works alongside your lawyer, PR team or security team
Most of these matters already have at least one of those in the room, and the work divides cleanly.
Your counsel owns anything on legal letterhead, any pre action correspondence, and any application for disclosure against a registrar or host. We give them the evidence pack and the infrastructure map and file the rights and platform routes that do not need a lawyer, which keeps legal spend on the parts that do.
Your PR team owns the external narrative and the decision to say nothing, which is usually the right one. We tell them what is coming down and roughly when, so nobody publishes a statement that revives a story a week before it disappears.
Your security team, or the family office equivalent, owns the physical and account side. Where a site publishes home addresses, travel patterns or family details, that is their matter as much as ours and we share what we find immediately.
Who usually makes first contact and what the 15 minute call covers
About half the time it is the principal, the night they find the site. The rest of the time it is a chief of staff, a general counsel, an agency or a family office acting for them. We are used to reporting into a team rather than to one person.
Before the call we look at the domain: the host, the registrar, what of yours is on it, and whether it is already ranking on your name. The call itself is fifteen minutes and mostly us listening, then telling you which routes are real, which are not, and what order they run in. Confidentiality and an NDA are standard, nothing is filed without your sign off, and the written assessment is yours to keep whether you engage us or not.
Frequently asked questions
Can a whole website be taken down, or only pages?
Both happen. A site that infringes copyright across most of its pages often disappears entirely because the host suspends the account. A site with one defamatory page and otherwise original content usually loses that page. We tell you which one your matter looks like before you commit to anything.
Should my lawyer send a letter first?
Sometimes, and sometimes not first. A letter to an anonymous operator can warn them to move and mirror the content before anything else is in place, which makes the matter longer and more expensive. We work alongside your counsel and tell you plainly where a letter helps and where it costs you.
The site says it is protected free speech. Is it?
Opinion generally is. Falsely stating that a company is under criminal investigation, that a founder was charged, or that money was stolen is a statement of fact, and false statements of fact are actionable in most jurisdictions. The distinction is the whole substance of the filing.
What happens if it comes back on a new domain?
We expect it to, at least once. The evidence pack, the ownership proofs and the host relationships are already built, so a mirror is handled in a fraction of the time the first one took. Monitoring for new registrations containing your brand is part of the work.
Who normally makes first contact with you?
Often the founder, late at night, the day they find it. Just as often it is a chief of staff, a general counsel, or the brand’s agency acting on their behalf. Any of those is fine, and everything is handled under NDA.
What happens on the call?
Fifteen minutes, and mostly us listening. You send the domain, we look at it before we speak, and on the call we tell you what is removable, what is not, and what a realistic outcome looks like. The written report is yours to keep whether or not you engage us.
Can we find out who registered the domain?
Often, and rarely from the public record alone. Privacy services hide the registrant, not the operation, and these sites are usually part of a pattern rather than a one off. Where a matter is going legal, your counsel can also seek disclosure. We look first and tell you plainly whether it leads anywhere.
How much does removing an attack site cost?
It is quoted in writing after the free Exposure Scan, once we have seen the domain and know which routes are genuinely available. Nothing is charged before you have that in writing, and the assessment report is yours to keep either way. See success based pricing.
Send us the domain and we will look at it properly. Start with a free, confidential Exposure Scan, or read how we work first. We work quietly alongside counsel, PR and security teams, and we will tell you when the honest answer is that a route does not exist.


