Skip to content

False positive: phishing-risk interstitial ('Our AI model spotted a phishing risk') on jodacreativestudio.com, a legitimate small-business site #57749

Description

@Zaida-3dO

Description

Brave is showing a full-page phishing-risk interstitial for jodacreativestudio.com, a legitimate small business (a calligraphy/creative-services studio) site currently in pre-launch. We believe this is a false positive and would appreciate the classification being reviewed.

Steps to reproduce

  1. Open https://jodacreativestudio.com/ in Brave.
  2. Observe the interstitial before the page loads.

(Reported to us by the site's operator with a screenshot on 2026-07-31 21:53 (Europe/London); the exact Brave version/OS/channel of that report was not captured, so I can't state it with certainty — happy to follow up if that's needed to investigate.)

Actual result

A full-page warning: "Phishing risk detected" / jodacreativestudio.com — "Suspicious URL" with the body text "Our AI model spotted a phishing risk. This website may be trying to steal your data.", a "WHY ARE YOU SEEING THIS ALERT?" expandable section, and "Not a scam" / "Leave website" buttons.

Expected result

The site loads normally — it's a real, currently-in-development business website with no data-collection forms beyond a single password field gating pre-launch access (see context below).

Reproduces how often

Reported as occurring on every visit at the time of the report (single report received so far; not personally re-verified in a live Brave session, since I don't have Brave available in the environment I'm working from).

Context that may be relevant to the classifier

  • The domain is ~109 days old (registered mid-April 2026), hosted on Vercel, DNS via Cloudflare (nameservers only, not proxied — A records resolve straight to Vercel's IPs).
  • Approximately 1h40m before the reported warning, we enabled a site-wide pre-launch "coming soon" gate (a real, intentional password prompt in front of every page, pending the site's public launch) — i.e. the domain went from serving full content to serving a same-URL password-entry page shortly before the flag appeared. We suspect that change in page shape (new domain + a page asking for a password, no prior browsing history in that state) is what the model keyed on, though we can't confirm your model's internals — offered as context only.
  • We independently checked reputation status before filing this: Google Safe Browsing shows the domain as clean (checked via the public transparency-report status endpoint, cross-checked against Google's own known-malicious test domain to confirm we were reading the response correctly), and VirusTotal shows 0/91 security vendors flagging it, including Google Safe Browsing, Netcraft, PhishTank, OpenPhish, and Sucuri SiteCheck, all "Clean" (VirusTotal's last analysis was same-day).
  • We have not changed DNS, added any new third-party scripts, or introduced any credential-harvesting behavior — the password field posts to a same-origin API route and sets a signed, httpOnly cookie server-side; there's no external form action anywhere on the page.

Brave version (brave://version info)

Not captured by the original reporter — can follow up if needed.

Channel information

Unknown (not captured).

Reproducibility

Unknown — not tested with Shields disabled or in Chrome by us; the domain shows clean everywhere we've checked outside of this one Brave warning.

Miscellaneous information

Site owner/operator is available to provide further detail (exact timestamps, additional screenshots, HTTP logs) if that would help investigate. Domain: jodacreativestudio.com. Thanks for looking into it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-more-infoThe report requires more detail before we can decide what to do with this issue.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions