# Fraudalant site using letsencrypt cert - appleid.icloud-lock.info

**URL:** <https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395>\
**Category:** Site Feedback\
**Created:** [February 8, 2017, 11:53am UTC](https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395 "2017-02-08T11:53:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darius](https://avatars.discourse-cdn.com/v4/letter/d/58956e/32.png) [@Darius](https://community.letsencrypt.org/u/Darius)\
**Post date:** [February 8, 2017, 11:53am UTC](https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395/1 "2017-02-08T11:53:19Z")

</div>

Hi guys,

I have received phishing email pointing me into [https://appleid.icloud-lock.info/](https://appleid.icloud-lock.info/)

This site us using your cert. I have already notified apple as well.

Is there any official way to report such misuse of your certs?

Kind Regards

Dariusz

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [February 8, 2017, 11:58am UTC](https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395/2 "2017-02-08T11:58:16Z")

</div>

You may report certificate misuse to the email address mentioned at the bottom of [https://letsencrypt.org/repository/](https://letsencrypt.org/repository/).

I went ahead and reported the site to [Google’s Safe Browsing](https://safebrowsing.google.com/safebrowsing/report_phish/); this is generally more effective than certificate revocation (which many browser don’t actively check). Let’s Encrypt uses data from Safe Browsing for newly-issued certificates as well (meaning if the domain is listed, it cannot obtain any new certificates).

---

<div class="post-metadata">

**Author:** ![Darius](https://avatars.discourse-cdn.com/v4/letter/d/58956e/32.png) [@Darius](https://community.letsencrypt.org/u/Darius)\
**Post date:** [February 8, 2017, 12:01pm UTC](https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395/3 "2017-02-08T12:01:55Z")

</div>

Thx. Next time will follow suggested path.

---

<div class="post-metadata">

**Author:** ![Weird](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/weird/32/15857_2.png) [@Weird](https://community.letsencrypt.org/u/Weird)\
**Post date:** [February 13, 2017, 9:10pm UTC](https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395/4 "2017-02-13T21:10:46Z")

</div>

I don’t think there’s anything LE can do for this.  
An LE certificate simply confirms that the site your browser has connected is indeed that site. Unless the certificate there is an EV certificate, crooks can purchase the certificate from pretty much any CA.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 15, 2017, 9:11pm UTC](https://community.letsencrypt.org/t/fraudalant-site-using-letsencrypt-cert-appleid-icloud-lock-info/27395/5 "2017-03-15T21:11:13Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
