Reset all of your authentication details with all financial institutions, ideally in person after showing them your state ID and let them know to block anything related to that domain. Have them treat your debit cards as stolen and issue new ones with entirely new numbers. Consider temporarily freezing your credit with the 3 credit agencies.
If the attackers are causing financial harm consult with an attorney and also with the FBI cybercrime division if you are in the US. [1] Log all details that you can including dates, times, events. Just the facts. Keep records of your communication with lawyers and the FBI so that you can show you were performing due diligence in for future related incidents.
[1] - https://www.ic3.gov/
ckrapu•7h ago
I totally forgot that it has a readable (I.e. guessable domain name) because AWS’ equivalent service doesn’t. I also had a company subdomain pointing to it so someone got to put up a malicious page on our domain for a day :(