A deceptive website is rarely just a website.
It may use one company for the domain, another for hosting or security, a third for advertising, a fourth for payment, and a fifth platform to find victims. The browser may maintain its own phishing blocklist. The victim’s bank may control a dispute process. Law enforcement controls none of those systems directly but may investigate the people behind them.
That makes the obvious question — Who is responsible for taking this down? — harder than it sounds.
Different companies control different levers
An ad network can stop buying traffic for the scam.
Google’s advertising policies prohibit phishing, malicious software, and ads that impersonate trusted entities. Enforcement can therefore remove an advertiser or destination from the ad system even if Google does not host the underlying site.
See Google’s phishing policy and malicious-software advertising policy.
A hosting provider can potentially remove content it actually hosts. A registrar controls the domain registration relationship. A security or CDN provider may only sit between the visitor and an origin server.
Cloudflare’s abuse documentation explicitly notes that what it can do depends on which Cloudflare service the reported site uses. A site merely passing through Cloudflare’s network is a different situation from content hosted on Cloudflare infrastructure or a domain registered through its registrar.
See Cloudflare’s abuse-reporting documentation.
A payment provider or card issuer controls another layer. It may be able to stop a merchant relationship, investigate a transaction, or process a dispute. The FTC advises marketplace buyers who paid by credit or debit card to dispute fraudulent transactions with the card company while also reporting dishonest sellers to the marketplace and regulators.
See the FTC’s online marketplace guidance.
The gaps appear at the handoffs
Each participant can truthfully say it does not control the entire fraud.
That can still leave the victim with a live scam.
The ad network may remove the ad while the site remains online. The host may act while a replacement domain appears. The payment path may close while the scammer switches processors. A marketplace may remove an account while the same operator continues through search ads or social media.
No single intervention is guaranteed to erase the operation.
But that does not mean nobody has meaningful power.
Practical ability is not the same as legal duty
It is useful to separate two questions.
What can this company technically or contractually do?
And what is this company legally required to do?
The first can often be answered from the provider’s service role and published policies. The second depends on jurisdiction, facts, contracts, regulatory rules, and sometimes litigation. It should not be guessed from a company’s ability to press a button.
The distributed web creates distributed responsibility.
That architecture is resilient when no single company can control everything.
It is maddening when a victim discovers that the same decentralization also means the scam can exist in the spaces between companies that each control only one piece.
The practical answer is not to search for one universal sheriff of the internet.
It is to identify every lever the operation depends on — visibility, domain, hosting, account, payment, browser trust, and law enforcement — and make sure the report reaches the party that can actually move that lever.
