{
  "id": "WEB-135",
  "slug": "web-135",
  "title": "No site impersonating another service to collect credentials",
  "statement": "The brand website must not host or promote impersonation of a legitimate service in order to capture credentials, identity numbers or other sensitive data.",
  "rationale": "This is the phishing pattern the whole landing-page review exists to catch: a page that looks like a bank, a carrier or a delivery service, reached from a text message, collecting whatever the real one would ask for. It is judged from design and form fields together, because the copy alone is by construction indistinguishable from the genuine article.",
  "layer": "WEBSITE",
  "layerSlug": "website",
  "object": "crawled website content",
  "severity": "BLOCKING",
  "detectability": [
    "CRAWL"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "Twilio",
    "CTIA"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30960",
      "remediable": false,
      "generation": "gen2"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "This cannot be registered. Where the brand is an authorised partner using another company's marks legitimately, state the relationship in visible page content and expect the registration to be reviewed by a person.",
  "notes": "CTIA A65-03 extends the same prohibition to brand impersonation on any message landing page or download, and A65-04 to promotion of illegal activity. Both are discharged here.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/website/web-135/",
  "markdown": "https://ekas.io/rules/10dlc/website/web-135.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
