Skip to content

Reporting Service Abuse or Malicious Content

If you observe abusive activity on one of the WSO2-owned domains listed below, report it to report-abuse@wso2.com. Include as much detail as possible: the specific domain, IP address, or URL involved; a description of the activity; the date and time of observation; and any relevant screenshots or logs. Reports are reviewed promptly and acted on by WSO2.

In-scope domains

Choreo: choreo.dev · choreoapps.dev · choreoapis.dev · choreoapis.io

WSO2 Identity Platform: asgardeo.dev · asgardeo.io

Ballerina: ballerina.io · ballerina.org

WSO2: wso2.com · wso2.org · wso2con.com

What counts as abuse

Activities that warrant a report include, but are not limited to:

  • Phishing. Fake websites or emails impersonating WSO2 to steal personal information or business data.
  • Malware distribution. Hosting or distributing malicious software through any of the listed domains.
  • Spamming. Unsolicited bulk email or messaging that disrupts services or annoys users.
  • Unauthorized access. Attempts to access systems, data, or accounts without authorization.
  • Impersonation. Pretending to be WSO2, a WSO2 employee, or another organisation, to deceive or defraud.
  • Fraud. Activities intended to deceive others for financial or personal gain.
  • Content violations. Hosting or sharing content that is illegal, harmful, or in violation of WSO2's terms of service.