If you are reading this, you're probably already aware that your site is being impersonated. Maybe a customer wants to know where their order is, and you have no record of it. Someone in your finance team takes a call from a supplier asking why your bank details have changed. Or somebody raises a support request with a link, and there is your website: your logo, your product photos, your wording, on a web address/domain name you have never owned.
TL;DR
- Capture the evidence before the copy changes.
- Work out what the copy is built to do.
- Warn your staff and your customers, starting with finance.
- Get it in front of the people who can take it offline.
- Chase every report until the copy is actually offline.
- Assume there will be another one, and start watching for it.
Steps 4 and 5 are the slow part. Tell us what you have found and we will run them for you.
A cloned website can be taken down, and you can do every step below yourself. Expect a separate report to each provider, each with its own queue, then days of chasing and checking, and the same again for every new copy. That is the work DefendDomain takes off your hands. After the steps comes the part that matters most for next time: how to find a copy before your customers do.
First, check it is a clone
Websites borrow from each other all the time, and a rival reusing your product descriptions is irritating but a different problem. The test is whether the site pretends to be you to people who trust you. If it uses your name and branding, and it takes orders, collects logins, lists contact details or sends email as you, treat it as an attack on your business. It will be used against your customers, your staff or both.
Clones turn up in three kinds of place: a web address close to yours (a misspelling, or your exact name with a different ending), an unrelated address with your pages on it, or a subdomain on a free hosting platform with your brand as the project name. That last kind has no domain registration behind it, which matters later.
If the fake products are listed on a marketplace or promoted from a social media account, rather than sold from a copy of your own site, report them through that platform's own brand reporting process. That is where the power to remove them sits. This guide is about copies of your website.
Step 1: Capture the evidence before the copy changes
Once the people running a clone realise they've been spotted, they can change the pages, take the site down, or rebuild it on a different address. The evidence you collect in the first hour may be the only evidence you get.
Capture:
- A screenshot of every page, with the full web address and the date and time visible.
- The full address of each page, copied as text.
- Your own genuine pages alongside, so anyone reviewing a report can compare the two at a glance.
- Whatever sent people there: emails, text messages, adverts, social posts, and the reports from customers or staff, with their dates.
- What the site asks visitors for: its forms, and what its checkout or login pages collect.
Do not type real details into the clone's forms, and do not contact whoever runs it. Both tell them they have been found.
Step 2: Work out what the copy is built to do
Nobody copies a website for the look of it. A clone is built for a purpose as part of an attack, and the purpose tells you who is about to be hurt and how.
- Taking orders or payments. Your customers pay for goods that never arrive, and then they contact you.
- Collecting logins. If your site has a customer portal or a staff sign-in page, the copy is there to collect passwords.
- Collecting enquiries. The clone's contact forms and email addresses put your prospects and suppliers in touch with the attacker instead of you.
- Making invoice fraud look legitimate. A fake invoice, or an email saying your bank details have changed, is more convincing when a customer can check and find a working copy of your website behind it. The payment goes to the attacker, and your finance team is left chasing an invoice the customer believes is paid.
- Advertising jobs. A copied careers page can front an employment scam aimed at people who want to work for you.
If the clone sits on a lookalike of your domain, check one more thing: whether that domain is set up to send email. A lookalike with email configured can write to your customers, staff and suppliers as you, whether or not anyone ever visits the site. Our free domain threat analysis shows which lookalikes of your domain are registered and which of them can send email.
Step 3: Warn your staff and your customers
By the time you find a clone, the cost is already impacting you: the refunds and complaints, the passwords to reset, the payment that went to the wrong account. Warning people quickly limits how much more of it there is.
Tell your staff first, and finance before anyone else. If a supplier or customer has already asked about new bank details, do not wait for step 1 to finish. Anyone who pays suppliers or updates bank details should confirm every change by phone, on a number they already hold, until this is closed. Support and sales teams need two or three sentences they can give a customer who asks.
Then tell customers what they can check for themselves: your one genuine web address, how you do and do not ask for payment, and where to report anything suspicious. Keep it factual, and do not publish the clone's address. Naming it sends it visitors.
Step 4: Get it in front of the people who can take it offline
A clone comes down when someone with control over it acts, and for a single clone that can be several different companies:
- The hosting provider serving the pages.
- The registrar the domain was bought through, which can suspend the address itself.
- The DNS provider the domain's records are hosted with, which can stop the address resolving even if the host and registrar are slow.
- The email provider the domain sends through, if the lookalike is set up for email. Suspending the mailboxes stops the invoices and password resets going out in your name while the site is still being dealt with.
- The platform operator, for a clone on a free hosting platform. It hosts the pages and controls the name, so it is the whole route. In one case we have written up, a single evidence-backed report to that operator had the copy offline about a day after it was confirmed.
- The warning services built into the major web browsers, which can put a warning in front of visitors while removal is under way. Search engines can also drop the pages from their results.
What decides the speed is the report. The person reading it has never heard of your company, so it has to make the impersonation obvious within a minute: the copy and the original side by side, dated, with what the site is being used for. Vague complaints wait in a queue.
By hand, you write that report several times over, because each of those companies has its own abuse form, its own evidence requirements and its own queue.
Submit the domain to threat intelligence feeds as well. Email security products, corporate web filters and browser warning services draw on shared blocklists, so a listing there protects people who have never heard of your company, and it keeps working while the removal requests are still in someone's queue.
Report it to the authorities as well. In the UK, report the site to the National Cyber Security Centre, and if anyone has lost money, to Report Fraud in England, Wales and Northern Ireland or to Police Scotland on 101. In the US, fraud losses are reported to the FBI's Internet Crime Complaint Center. A report gives you a record and adds to what the authorities can act on. It does not replace a direct request to the people who control the site.
Step 5: Chase it until it is actually offline
Sending the reports starts the takedown. Getting the copy offline often takes days, sometimes longer, while each one sits in a queue and the clone keeps taking your customers' payments and your staff's passwords.
So someone has to follow up: phoning registrar and hosting help desks, replying to tickets that were closed or passed to another provider, re-sending the same evidence, and pushing for an escalation when nothing moves. It also means checking every day whether the address still works and the pages still load, because a closed ticket can still mean a live site, and a copy that comes down can reappear on the same host.
That work often lands on the head of IT or an operations lead: phone queues and ticket threads spread across days, while the work they would otherwise be doing waits.
If you have a live copy of your site right now, this is the part we run for you. Tell us what you have found, and the reports, the chasing and the checks are ours until the copy is offline.
Step 6: Assume there will be another one
Copying a website takes minutes. A takedown costs whoever made it that one copy, and nothing stops them making another. In the free hosting case above, the project name on the platform had been built from a lookalike domain that was already taken down once before for the same brand. By hand, every new copy sends you back to step 1.
So the useful question after the first takedown is how you will hear about the second. This time, the clock ran from the day the copy went live to the day someone told you. That gap is where the refunds, the reset passwords and the misdirected payments came from, and it is the part you can change.
How to find the next copy before your customers do
A clone has one weakness built in. To fool anyone, it has to carry your brand with it: your name, your words and your images. Everything it carries is something you can watch for. How much watching is worth doing depends on what a copy would cost you, and there are two sensible answers.
If you run a small business, a side project or an early-stage startup, the free/cheapest approach. Run our free domain threat analysis once a week. It shows which lookalikes of your domain have been registered and which of them can send email, so a misspelling or your name on a different ending gets noticed while it is still empty. Then set up Google Alerts for your brand name and two or three distinctive phrases from your site, so you hear when your words are published somewhere new. Neither catches everything. A clone that is only ever sent to people as a direct link may never be indexed, and a copy on a free hosting subdomain has no registration to spot. Together, though, they turn “a customer told us” into “we noticed” for a good share of copies, for the cost of a reminder in your calendar.
If a clone would cost you customers, payments or credentials, the watching has to be continuous and much wider than a weekly check, and the takedown needs someone whose job it is. A brand protection platform like DefendDomain watches continuously for lookalikes of your domain, often catching them before they are used, and for copies of your site, including on addresses that look nothing like yours. When a copy goes live, the evidence is captured with the alert and the takedown runs end to end, including every follow-up, check and escalation until the copy is offline. It is managed by a team who do this every day, and the watching carries on in case the same site comes back. In the second case we have written up, a lookalike of a private-equity-backed software group's domain was flagged when it was registered, confirmed as a clone when the copied site went live, and taken offline before any customer, prospect or employee was known to have used it.
Why this cannot wait
The takedown is the step everyone searches for, and it matters. But the size of the bill is set by how long the copy stays live. Every day it is up is another day of orders paid to someone else, passwords handed over, invoices settled to the wrong account, and customers who now connect your name with being defrauded. The refunds and the password resets can be counted. The customers who quietly stop trusting your emails, and the employees whose details end up in an attacker's spreadsheet, cannot.
A slow response also tells the attacker something. Copying a website is cheap, and they judge the return by how long it stayed up before anyone pushed back. A clone that ran for weeks marks your brand as a soft target: the same people come back with a new address, and others notice too. A copy that is offline within days was a poor investment, and they move on to someone who reacts more slowly.
So act today, not after the next customer call. Capture the evidence, warn your people, get the reports out and chase them, or tell us what you have found and we will start the takedown now. Then decide how you will hear about the next one: run a free domain threat analysis to see what is already registered around your brand, or book a demo to see the full platform.
Frequently asked questions
Can you get a cloned website taken down?
Yes. A cloned website that uses your name, branding or content to impersonate you can be taken offline by the company hosting it, by the registrar that sold the domain or, on a free hosting platform, by the platform operator. Browser warning services can warn visitors in the meantime. Speed depends on clear, dated evidence that shows the copy next to your original, sent to the party that controls the site. Doing it yourself means a report to each provider, then days of chasing until the site is actually offline, and the same again for every new copy. DefendDomain can run all of it for you.
How do I find out if someone has copied my website?
For a quick check, search for a distinctive sentence from your site in quotation marks, which finds copies that search engines have indexed. If you run a small business or an early-stage startup, run a free domain threat analysis each week to see which lookalikes of your domain have been registered and which of them can send email, and set up Google Alerts for your brand name and a few distinctive phrases from your site. If a clone would cost you customers, payments or credentials, use a brand protection platform such as DefendDomain, which watches continuously for lookalikes of your domain and copies of your site, warns you early, and runs the takedown and the follow-up when a copy goes live.
What should a tool that detects fake websites impersonating my brand do?
It should warn you about lookalikes of your domain early, often before they are used, and find copies of your site, including on free hosting platforms and on addresses that look nothing like yours. Then check what happens after detection: whether the evidence is captured for you, whether takedown is included, whether the follow-up is run for you until the copy is offline, and whether it keeps watching for the same site to return.
Where do I report a cloned website?
In the UK, report the site to the National Cyber Security Centre and any financial loss to Report Fraud, or to Police Scotland on 101. In the US, report it to the FBI's Internet Crime Complaint Center and to the Federal Trade Commission. In Canada, report to the Canadian Anti-Fraud Centre and the Canadian Centre for Cyber Security. In Australia, report through ReportCyber, run by the Australian Signals Directorate, and to Scamwatch. The EU has no single reporting point: report to the police or national cyber security agency in your member state, and Europol keeps a list of each country's reporting sites. A report creates a record, but removing the site still depends on the host, registrar or platform acting on your evidence, so send your evidence to them directly as well.
Will a cloned website come back after it is taken down?
It often does, and the odds rise the longer the first copy was allowed to run, because a clone that stayed up for weeks tells the attacker your brand is worth another attempt. It will almost always appear on a different domain, since the one that was taken down is unusable to them. That is why the watching has to continue after the first takedown: a new lookalike of your domain, or a copy of your site on another address, is the earliest sign of the second attempt.