Reporting Service Abuse or Malicious Content¶
If you observe abusive activity on one of the WSO2-owned domains listed below, report it to report-abuse@wso2.com. Include as much detail as possible: the specific domain, IP address, or URL involved; a description of the activity; the date and time of observation; and any relevant screenshots or logs. Reports are reviewed promptly and acted on by WSO2.
In-scope domains¶
Choreo: choreo.dev · choreoapps.dev · choreoapis.dev · choreoapis.io
WSO2 Identity Platform: asgardeo.dev · asgardeo.io
Ballerina: ballerina.io · ballerina.org
WSO2: wso2.com · wso2.org · wso2con.com
What counts as abuse¶
Activities that warrant a report include, but are not limited to:
- Phishing. Fake websites or emails impersonating WSO2 to steal personal information or business data.
- Malware distribution. Hosting or distributing malicious software through any of the listed domains.
- Spamming. Unsolicited bulk email or messaging that disrupts services or annoys users.
- Unauthorized access. Attempts to access systems, data, or accounts without authorization.
- Impersonation. Pretending to be WSO2, a WSO2 employee, or another organisation, to deceive or defraud.
- Fraud. Activities intended to deceive others for financial or personal gain.
- Content violations. Hosting or sharing content that is illegal, harmful, or in violation of WSO2's terms of service.