To try to be more efficient, we have to go after these two domains:
xchange[.]cx
stealthex[.]co
They are the new element of the scheme, and for that they have to be overthrown.
We now have to put out the dirty laundry for companies that haven't even shown interest in this fight or don't know what's happening to their brand out there

Besides, considering these phishing sites removed eXch from their phishing farm, the only possible case we can pin them down for is
xchange[.]cx or stealthex[.]co . The reporting method has to change going forward as exch being phished is out of the equation.