Lookalike domain hosting a clone of your employee sign-in page
acme-sso.example
What we found
A domain registered two days ago behind privacy protection, serving a pixel copy of your employee sign-in page over a valid certificate. The login form posts to an endpoint the attacker controls, then redirects to your real portal so the visitor sees a normal second attempt.
Where we found it
A certificate transparency log entry matched your brand watchlist. We resolved the host, fetched the page, and stored the screenshot, the DOM, the WHOIS record and the TLS chain as evidence before the site could change.
Why it matters
Credentials typed here reach an attacker in seconds. Because the domain and its certificate are hours old, your mail gateway has no reputation signal to block on, and your staff have nothing visual to distinguish it from the real portal.
What we recommend
Block the domain at the mail gateway and egress now. We file the takedown with the registrar and the hosting provider in parallel and chase it to closure. Add the registration pattern to the watchlist so the next variant is caught on the day it appears rather than on the day it is used.
- First seen
- 41 minutes ago
- Registered
- 2 days ago, privacy proxy
- Certificate
- issued 19 hours ago
- Hosting
- shared provider, EU region
- Evidence
- screenshot · DOM · WHOIS · TLS
- Push to Jira
- Notify #soc-alerts
- Assign owner
- File managed takedown