Saltar al contenido
06 · Especializados06 · Specialised

Anti-Phishing y Brand ProtectionAnti-Phishing and Brand Protection

Dominios fraudulentos, suplantación en redes, takedowns.Fraudulent domains, impersonation on social media and takedowns.

Brand ProtectionBrand Protection Servicios verticales para riesgos específicosVertical services for specific risks

¿Qué es este servicio?What is this service?

Es la detección y retirada de todo lo que usa la marca de la organización para engañar a terceros: dominios parecidos al legítimo, sitios que copian el portal de banca o la intranet, perfiles falsos en redes sociales, aplicaciones móviles clonadas y campañas de correo que se hacen pasar por la entidad.

Detection and takedown of anything using the brand of the organisation to deceive third parties: lookalike domains, sites cloning the banking portal or the intranet, fake social media profiles, cloned mobile apps and email campaigns impersonating the entity.

¿Para qué se usa?What is it used for?

El daño de este fraude lo sufre el cliente final, pero la reputación que se resiente es la de la entidad suplantada. Un dominio parecido se registra en minutos y cuesta menos de veinte dólares. Lo que marca la diferencia no es evitar el registro, cosa imposible, sino cuánto tarda en detectarse y bajarse: de días a horas.

The damage from this fraud lands on the end customer, but the reputation that suffers is that of the impersonated entity. A lookalike domain is registered in minutes and costs under twenty dollars. What makes the difference is not preventing the registration, which is impossible, but how long detection and removal take: days versus hours.

Qué beneficios traeBenefits it delivers

  • Acorta la vida útil del sitio fraudulento, que es la única métrica que de verdad reduce víctimas.
  • Vigila el registro de dominios parecidos y detecta muchos antes de que se usen, cuando todavía están vacíos.
  • Cubre lo que la seguridad perimetral no ve: perfiles falsos, anuncios pagados y tiendas de aplicaciones.
  • Deja rastro documental de cada suplantación, útil si el caso termina en denuncia.
  • Shortens the lifespan of the fraudulent site, the only metric that genuinely reduces victims.
  • Watches lookalike domain registrations and catches many before they are used, while still empty.
  • Covers what perimeter security cannot see: fake profiles, paid ads and app stores.
  • Leaves a documented trail of each impersonation, useful if the case ends in a complaint.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal de contratar protección de marca en Costa Rica.
  • Las entidades financieras supervisadas responden ante su regulador por el fraude que afecta a sus clientes, y el Acuerdo CONASSIF 5-24 les exige gestionar el riesgo tecnológico asociado a sus canales.
  • La denuncia penal por suplantación es una vía aparte y más lenta: el takedown no la sustituye ni la impide.
  • There is no legal obligation to contract brand protection in Costa Rica.
  • Supervised financial entities answer to their regulator for fraud affecting their customers, and CONASSIF Agreement 5-24 requires them to manage the technology risk of their channels.
  • A criminal complaint for impersonation is a separate and slower route: a takedown neither replaces nor blocks it.

InternacionalInternational

  • Ningún marco lo exige por nombre.
  • PCI-DSS empuja controles antisuplantación en el correo para las entidades que procesan pagos.
  • En banca y seguros los reguladores esperan medidas activas contra el fraude a clientes, y esto entra en esa categoría.
  • No framework requires it by name.
  • PCI-DSS pushes anti-spoofing email controls for entities processing payments.
  • In banking and insurance, regulators expect active measures against customer fraud, and this falls into that category.

Requisitos mínimosMinimum requirements

  • Titularidad demostrable de la marca y de los dominios legítimos: sin eso el registrador no atiende el reclamo.
  • Un inventario de los dominios, perfiles y aplicaciones oficiales, para distinguir lo propio de lo falso.
  • Correo bien configurado con SPF, DKIM y DMARC: sin eso, suplantar a la entidad por correo es trivial y ningún takedown lo arregla.
  • Un contacto interno con autoridad para autorizar la solicitud de retirada y su seguimiento.
  • Demonstrable ownership of the brand and the legitimate domains: without it registrars ignore the complaint.
  • An inventory of the official domains, profiles and applications, to tell the genuine from the fake.
  • Email properly configured with SPF, DKIM and DMARC: without it, impersonating the entity by email is trivial and no takedown fixes that.
  • An internal contact with authority to approve takedown requests and follow them up.

Plazo típico de entregaTypical delivery time

Servicio continuo Ongoing service rango habitual del mercado usual market range

Es un servicio continuo. La configuración inicial toma de una a dos semanas. Cada takedown depende de terceros que nadie controla: un proveedor de hosting cooperativo baja el sitio en horas, un registrador en una jurisdicción hostil puede tardar semanas o no responder nunca. Cualquiera que prometa un plazo fijo de retirada está vendiendo algo que no depende de él.

A continuous service. Initial setup takes one to two weeks. Each takedown depends on third parties nobody controls: a cooperative hosting provider removes the site within hours, a registrar in an uncooperative jurisdiction may take weeks or never answer. Anyone promising a fixed removal deadline is selling something outside their control.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

TakedownTakedown
La gestión ante hosting, registrador o plataforma para que retiren el contenido fraudulento. The request to a host, registrar or platform to remove the fraudulent content.
TyposquattingTyposquatting
Registrar dominios con errores de tecleo o letras parecidas a los legítimos para capturar visitas y credenciales. Registering domains with typos or lookalike letters to capture visits and credentials.
DMARCDMARC
Política publicada en el dominio propio que indica al correo receptor qué hacer con los mensajes que dicen venir de la organización sin hacerlo. A policy published on the domain telling receiving mail servers what to do with messages claiming to come from the organisation without doing so.
SPF · DKIMSPF · DKIM
Los dos mecanismos que autentican el correo de la organización: uno autoriza servidores emisores y el otro firma el mensaje. The two mechanisms authenticating the email of the organisation: one authorises sending servers, the other signs the message.
Kit de phishingPhishing kit
Paquete listo para usar que clona un sitio legítimo y recolecta las credenciales que la víctima escribe. A ready-made package cloning a legitimate site and harvesting the credentials the victim types.