I have already submitted this through the online form and received a case acknowledgement, but the impact has escalated since and I would be grateful for any help getting it looked at.
The problem: the entire registrable domain kaizenconsult.es is being blocked as a phishing page by the Antiphishing module, across all subdomains and all paths. I am the owner of this domain.
Blocked URLs (all: module Antiphishing, reason Phishing — confirmed both on Bitdefender Endpoint Security Tools / GravityZone and on the TrafficLight browser extension):
- https://www.kaizenconsult.es/es/proceso
- https://agent.kaizenconsult.es/login
- https://clustermav.kaizenconsult.es/login
Why this is clearly a false positive: the first URL is a page on our public corporate website. It contains no login form, no password field, no payment or card field, and no iframes. It loads no third-party resources other than YouTube and LinkedIn embeds. There is literally nothing on that page that could be used to collect credentials from anyone. I would ask an analyst to simply open it and confirm this directly.
What the domain is: Kaizen Consult is a registered process-automation consultancy based in Barcelona, Spain. This domain has hosted our corporate website since at least December 2021.
What the subdomains are: agent.kaizenconsult.es is a private client dashboard hosted on Netlify. It has no password field — the only input is an email address, and access is by a one-time signed link valid for 15 minutes sent to a pre-authorised address. No payment or financial data is requested or processed. It serves a strict Content-Security-Policy (default-src 'self'; form-action 'self'; frame-ancestors 'none'; object-src 'none'), so it cannot load third-party code or send data to any external destination. It uses HTTPS with HSTS and is marked noindex as a private internal tool. Its login page explicitly names the operating company and states that no password or banking details will ever be requested.
Likely origin: an earlier hostname, clustermav.kaizenconsult.es, combined a client's brand name with our own domain — a naming pattern that can resemble brand impersonation. We have since renamed the service and removed all third-party branding from the public page. The classification appears to have then been escalated to the whole registrable domain.
Impact: our clients cannot access the service we provide them, and any prospective customer using a Bitdefender product cannot reach our corporate website at all. This is ongoing commercial damage.
Screenshots of all three blocks attached. Happy to provide anything else that helps — hosting details, DNS records, or access to the dashboard itself.