After finding the malicious website (phishing, crypto drainer, online seed “backup”) the best would be to report them to following websites:
https://safebrowsing.google.com/safebrowsing/report_phish/
https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site-guest
https://sitereview.bluecoat.com
https://safeweb.norton.com/
https://phish.report/
https://support.metamask.io/
http://PhishDestroy.io
For more advanced users, you could report them directly to domain registrar and hosting provider of the malicious website.
This tool can be used to find e-mail addresses of domain registrar and hosting provider to report abuse:
https://acidtool.com
You can also report scam to authorities on following links:
https://www.europol.europa.eu/report-a-crime/report-cybercrime-online