A victim can know exactly which website stole their money and still have no single obvious place to report it.
The scam may have arrived through an advertisement, used a domain registered by one company, passed through a security or CDN provider, taken payment through another service, and impersonated a seller on a platform operated by somebody else.
Each company sees a different slice of the event.
The victim sees the whole mess.
The Federal Trade Commission asks consumers to report fraud through ReportFraud.ftc.gov and explains that those reports can help investigators identify patterns and build cases. The FBI separately directs online fraud victims to the Internet Crime Complaint Center at IC3.gov.
See the FTC’s explanation of why fraud reports matter and the FBI’s fraud-reporting guidance.
Infrastructure reports go somewhere else
Law-enforcement reporting does not automatically remove the web page.
A browser-security service may need a phishing report. An ad network may have a separate advertiser-abuse process. A hosting or infrastructure company may require URLs and evidence through its own abuse form.
Cloudflare’s abuse documentation makes the fragmentation unusually visible. Its response depends on which Cloudflare service is involved: pass-through CDN and security service, registrar, or content actually hosted on its platform.
See Cloudflare’s abuse-reporting documentation.
That distinction is technically reasonable. It is also a lot to ask from somebody who just got robbed by a fake store.
Better reports need both evidence and ownership
A useful report should preserve the exact URL, screenshots, timestamps, transaction records, messages, advertiser information when visible, and the method used to pay.
But good evidence is only half of the problem.
Someone also needs to own the next step.
Reporting systems are more effective when they make clear what the receiving organization can actually do, whether the report was accepted, and where to send the complaint if the organization is merely an intermediary.
The web’s anti-fraud machinery is distributed because the web itself is distributed.
That is not automatically a failure.
The failure comes when every participant has a report form and nobody appears responsible for making the harmful thing disappear.
