I once got a phish E-mail to my ISP E-mail account with Comcast stating I needed to log into their site and accept the new TOS. I knew it smelled phishy so I opened the link in a VPN and sure enough the whole website was crafted to look just like a real Comcast website with login. The hacker (or would be hacker since I nailed his ass) even add a nice touch of a captcha. Well, you could enter anything for the captcha and the login still worked. But what I did for a week was enter bullshit usernames and passwords. Like, you_have_been_pwned, etc. Then I went to GoDaddy, where the website was hosted and told them about it. Also reported him to spam cop and the E-mail server Admin he was using. He messed with the wrong dude because the site is no longer in existence.