When we started BotBye, the focus was bot detection and fraud prevention. But talking to users, we kept hearing the same thing: stolen credentials from phishing lead to account takeovers, brute force attacks, and fraud. Bots and phishing are two parts of the same attack chain.
So we built phishing protection into BotBye.
Here's what it does:
- Detects phishing sites impersonating your brand — HTML clones, reverse proxies (like Evilginx), and custom-built fakes
- Responds with automated takedowns and counter-attacks on phishing pages
- Flags users whose credentials were compromised through phishing
The idea is simple: if someone clones your site and steals your users' passwords, those passwords will be used by bots to take over accounts. We now cover both sides — detect the phishing site and block the bots that come after.
This is currently available in beta on all plans, including Free.
Would love feedback from anyone who's dealt with phishing attacks on their product. How do you handle it today?
What stood out to me is that you're treating phishing and bot attacks as one continuous problem instead of two separate security products.
Most tools defend one stage of the attack. You're following the attack chain from credential theft to account takeover. That feels like a much stronger way to think about the problem than adding another standalone security feature.