The cybersecurity refrain when encountering phishing emails invariably advises: “don’t click on that link” and “report that email”—but new research from Drexel University and Arizona State University has revealed a problematic reality: Most major companies do little to support reporting and few take action to shut down phishing sites disguised as their own after they have been reported.