How to report a cloned website, from a real clone-store case

Someone copied your website or your online store. Who can take which part of it down (registrar, host, Google, browser blocklists), what to save before you report, whether you need a trademark, and what happened when we reported five copies of one store in September 2026.

To report a cloned website, send the evidence to every party that controls a piece of it: the registrar can suspend the domain, the hosting provider can remove the server, Google can drop copied pages from search results on a copyright notice, and the browser blocklists can put a warning in front of visitors. Save the evidence with a third party while the copy is still live, because a report nobody can verify is easy to close. If the copy takes card numbers or passwords, it is fraud, and you do not need a trademark to report it.

That is the short answer. The rest of this page is what it looked like in practice: in September 2026 we reported five copies of one US retailer's online store. Some of the copies came down within a day and the machinery behind them did not, and we made one mistake we describe below. The full hour-by-hour record is in a store cloned five times.

First: is the copy just a copy, or a trap?

Find out what the copy does before you decide who to report it to. A copied site that only steals your text and photos is a copyright problem. A copied store that collects card details is phishing, and registrars are contractually required to act on phishing (more on that below).

You usually cannot tell from the homepage. In our case, the retailer found the first copy and reported it to us on 11 September. Our own classifier scored its homepage as legitimate (0.93), and Google's Web Risk returned no threat. Of 30 product pages we sampled, all 30 descriptions matched the retailer's own word for word, under the retailer's logo. The theft only showed at checkout. The card field was an iframe served from a separate domain, and during checkout no request went to any payment provider. Nothing a shopper typed there would buy anything.

If you walk through a copy's checkout yourself, use made-up details and stop before paying.

Who can take down which part

Each party can remove one layer, and none of them removes all of it.

WhoWhat they can removeWhat they act on
Registrar (the company the domain was registered through)The domain itself: suspended domains stop resolving until the operator registers a new oneEvidence of phishing or fraud they can check themselves
Hosting providerThe server or account serving the pagesThe same evidence; the operator can move to another host
Google SearchThe copied pages in its resultsA copyright notice from the owner of the copied content, or someone authorised to act for them
Browser blocklists (Google Safe Browsing, Microsoft SmartScreen)Nothing. They show a red warning page in the browserA URL that is doing phishing when they check it
The platform, if the copy runs on one (a site builder or store platform)The store accountIts own abuse or intellectual-property form
The payment provider, if the copy takes real paymentsThe merchant accountOrder details from someone who paid

Registrars have a contractual duty here. Under section 3.18 of ICANN's Registrar Accreditation Agreement, every accredited registrar must publish an abuse contact and "take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse". Amendments that took effect in April 2024 require registrars to act on well-evidenced phishing. ICANN's enforcement report for the first six months counts 154 resolved cases, more than 2,700 suspended domain names and more than 350 disabled phishing websites. Google states that it complies with copyright notices under the DMCA (Google Legal Help).

One detail matters for store owners: none of the five copies ran on the real store's platform. The real store was on Shopify. The copies were on .shop domains bought through one registrar and hosted on one network, so reporting them to Shopify would not have removed anything. Find out where a copy actually lives before you report it; how to look up the registrar and the host is in how to report a phishing domain to its registrar.

What to save before you report

A copy can vanish for you and stay up for everyone else, so save proof that someone else can check.

  • A third-party archive of the live page, such as urlscan.io or the Wayback Machine. An abuse desk can open it after the site stops answering them.
  • Screenshots of the parts that matter: your logo on their page, the copied product text next to yours, and the checkout form if there is one.
  • Every domain involved. Copies often come in batches. Our retailer's first report named one; five days later it sent us four more.

Do you need a registered trademark?

Not to report fraud. A store that collects card numbers is an abuse case for the registrar and the host, whether or not the brand holds a trademark. A trademark matters for the slower routes that decide who owns a domain name: UDRP and URS, and platforms' trademark complaint forms. Copied product text and photos are covered by copyright, which you have without registering anything.

What if the fake site only uses your business name?

If it takes no payments and asks for no passwords, it is usually not an abuse case, and registrars treat it as a dispute over the name. That points to the trademark routes above, or to a copyright notice if it also copies your content. These take weeks or months, not hours. If it does take payments, see the first section: it is fraud, however it is dressed.

What happened when we reported five copies

We sent the first reports on 16 September at 09:35 UTC. By the next morning, all five storefront domains had disappeared from DNS:

ResultCount
Storefront domains suspended by the registrar3 of 5
Storefront domains whose DNS records were emptied (by whom, we cannot tell from outside)2 of 5
Card-collection domains still live three days later3 of 4
Written confirmations from any party we reported to0

The storefronts were disposable. The domains that collected the card numbers were shared between them, and a new storefront can be attached to one the day it is registered. Taking down the copies is one round, not the end of the case.

Our mistake: within three hours of the first reports, the first copy stopped answering our checks, and we told the retailer it was offline. It was still serving visitors in other countries and had only stopped answering us. Third-party scans from other countries showed it, and we sent the retailer a written correction. How that happened, and what we changed so it cannot repeat, is in the case record.

Warn your customers while you report

Reports take hours to days to act on, and your customers are on the copy in the meantime. Post a short notice where they will see it: which address is really yours, what the copy looks like (with its domain written so it cannot be clicked, like example[.]shop), and what to do if they already paid. The whole first-response sequence is in the first 48 hours of a phishing incident.

Copying is not only a US problem. In its August 2026 monthly report, Japan's Council of Anti-Phishing Japan says reports are increasing from companies whose website photos, brand names and operator details were copied and used for fake sites and fraudulent online stores.

If you want someone to do this for you

This is the work OpenBait does. On the Business plan ($299 a month), a person works one hard case a month, such as a copied store, through to the end: the registrar and host reports, DMCA notices for copied product pages, and a case page that records what was sent to whom and what came back. Five cloned stores and the card-collection domains behind them count as one incident, not nine. If none of the sites we take on in your first month is removed, that month is refunded.

If you only want a place for customers to report copies of your site, the report page is free for one brand. How it works explains what happens after a report comes in.

A fake site using your name?

Give customers one link to report it. Each report is checked in seconds and phishing sites go to the browser blocklists. Free for one brand; paid plans take them to the host and registrar.

Get your free report page

Related articles

A store cloned five times: what each abuse desk did, hour by hour

A US retailer's online store was cloned five times in September 2026. The hour-by-hour record: the four card-collection domains behind the copies, what the registrar, the hosts and the blocklists each did, and the half day in which we reported a live site as offline.

「偽サイトにご注意ください」注意喚起の例文集

自社をかたる偽サイトを見つけたときに、お客様へ出す注意喚起の例文です。自社サイトのお知らせ、メール、X・SNS の 3 種類をそのままコピーでき、必ず入れる 5 項目と、載せてはいけないものも整理しています。

A .cn phishing site: Tencent took it down in a day

One phishing site on a .cn domain, reported on the same day to Google Safe Browsing and to Tencent's abuse channel. Tencent removed it within 24 hours; Google never responded. What this means for anyone running anti-phishing for a brand exposed to Chinese-hosted infrastructure.