OpenAdLibraryOpenAdLibrary
Ad Transparency & Supply Chain

Website Cloned by Scammers? A Step-by-Step Response Plan

Evidence first, traffic second, takedowns third. The exact order of operations when scammers clone your site, with the levers that actually move fast.

Editorial illustration: Website Cloned by Scammers? A Step-by-Step Response Plan

If scammers have cloned your website, work through five moves in order: capture evidence immediately (screenshots, saved pages, WHOIS records, archive copies); find the traffic source feeding the clone — it is almost always paid ads or phishing; file abuse reports with the clone's hosting provider and registrar; report the URL to Google Safe Browsing so major browsers warn visitors away; and notify your customers before the first chargeback arrives, not after. The clone site itself is cheap and disposable. The leverage points are the infrastructure it rents and the traffic it buys.

Here is the full response plan, in the order that minimizes damage.

First hour: capture evidence before you touch anything#

The instinct is to fire off angry abuse reports immediately. Resist it for one hour, because every takedown you win destroys the evidence you will need for the next steps — the domain dispute, the payment-processor complaint, the trademark filing, and the inevitable reappearance on a fresh domain.

Capture, at minimum:

  • Full-page screenshots and saved HTML of the clone's home page, product pages, checkout, and contact page.
  • The exact URLs and the date and time of each capture.
  • The checkout flow itself, if it is live: which payment methods it offers and any merchant name that appears — payment-rail complaints need this.
  • The domain's WHOIS record (registrar, registration date, registrant details if visible) and its hosting provider via an IP lookup.
  • An archive snapshot (archive.org or similar) as third-party corroboration that the clone existed at that URL on that date.

Keep it all in one dated folder. Clones reappear on fresh domains, and being able to show a pattern — same template, same assets, same payment processor across five domains — is what turns the third takedown from a fresh investigation into a same-day action.

Find out how people are reaching the clone#

A cloned site with no traffic is a harmless artifact. Clones don't rank organically — they buy visitors, and the channel they buy on determines who can cut the traffic off. Check, in order:

  • Ad transparency libraries for your brand terms: the Meta Ad Library and the Google Ads Transparency Center.
  • The native ad networks, which run no official libraries and are a favorite clone-traffic source. OpenAdLibrary's index traces native ads through their redirect chains to the final landing domain — 1.3 million+ landing captures across 49 networks as of June 2026 — so you can search your brand and product names in the ad intelligence library and see which ads resolve to domains that are not yours. Our guides on identifying the ad network behind an ad and finding out who is buying ads on a website cover the manual version of this trace.
  • Phishing channels — email and social DMs — if no ads turn up. Ask affected customers how they found the site; their answers are evidence too.

Finding the ad matters because an ad-network abuse report is usually the fastest lever you have: it can cut the clone's oxygen within a business day, while hosting takedowns grind through queues. Report the ad together with its click URL and redirect chain, packaged the way our scam-ad reporting guide describes.

Takedown routes, fastest levers first#

Route What it does Typical speed
Ad network abuse report Cuts the paid traffic feeding the clone Often the fastest lever — hours to days
Hosting provider abuse desk Takes the site offline Days; varies by host and jurisdiction
Registrar abuse desk Suspends the domain Days to weeks; strongest for clear phishing
Google Safe Browsing report Browsers warn visitors before the page loads Typically days
Search engine removal (DMCA) De-indexes the clone from results Days to weeks
CDN / reverse-proxy abuse desk Identifies or notifies the real host A forwarding step, not a removal

Practical notes on each:

  • Hosting. Find the host with an IP or ASN lookup on the clone's domain. Most hosts run an abuse inbox or form; attach the evidence pack and state plainly that the site is a fraudulent clone of your business, with your original URLs for comparison.
  • Registrar. Listed in the WHOIS record. Registrars act decisively on phishing — fake login or checkout pages — while pure content copying is more often bounced to the DMCA route.
  • Safe Browsing. Report at safebrowsing.google.com. A listing puts a full-screen warning in front of Chrome users, and Firefox and Safari consume the same list. It does not remove the site, but it collapses its conversion rate.
  • DMCA. A clone is a wholesale copy of your copyrighted text, images, and code, so takedown notices to search engines and the host stand on solid ground.
  • Bulletproof hosting. Some clones sit on abuse-tolerant hosts that ignore everything. Don't burn weeks there — double down on the traffic side (ad networks, Safe Browsing, payment rails), which the host cannot protect.

One more efficiency note: write the abuse-report template once and reuse it. A tight report contains your identity and rights (who you are, your official domain, proof you own the original content), the clone's URL and capture dates, a two-line statement of what it is ("a fraudulent copy of our website collecting payments under our name"), and two or three side-by-side screenshots. Every route in the table above accepts essentially this same package, so the second and third filings should take minutes, not an afternoon.

Protect your customers while the takedowns run#

Takedowns take days; your customers are being defrauded now.

  • Post a short notice on your site, order-confirmation emails, and social channels: your only official domain, a warning that a fake exists, and a reminder that you never ask for payment anywhere else. Describe the lookalike pattern rather than hyperlinking the clone — there is no reason to hand it more visitors.
  • Brief your support team with a canned response and a place to log every customer report. Sightings are evidence, and support is usually the first place a clone becomes visible.
  • Watch chargebacks and payment disputes for the clone's fingerprints. If the clone phishes logins rather than payments, force password resets for any affected accounts.

The escalations that move slower but hit harder#

  • Trademark. If the domain embeds your mark, a UDRP domain dispute can transfer the domain to you permanently — the only remedy that prevents the same domain from coming back. Ground the ad-side complaints in the same rights; see Trademark Infringement in Ads.
  • Payment rails. Report the clone's checkout to the payment processors it uses. Scammers can replace a domain in an hour; replacing a merchant account is much harder, which is why this complaint hurts them the most.
  • FTC. US businesses and consumers can file at ReportFraud.ftc.gov. It will not take the site down, but it builds the law-enforcement record that matters when the same operation resurfaces for the third time.

Expect it to come back — build the monitoring loop#

A domain costs a few dollars and the cloning itself is automated, so a profitable clone operation treats takedowns as churn, not defeat. The pattern is thoroughly documented in native advertising specifically — see how scammers clone brands in native ads and the copycat landing page glossary entry.

The durable fix is detection speed:

  • A weekly sweep of the ad libraries and the native index for your brand and product terms.
  • Watchlist alerts on new ads whose landing pages match your brand, so a relaunched campaign surfaces in days rather than weeks.
  • Similarity monitoring against your own funnel pages, which catches clones that never mention your brand in the ad at all — the approach described in Brand Protection in Native Advertising.

The response plan, compressed: evidence, traffic, infrastructure, customers, escalation — in that order. The teams that struggle are the ones that start in the middle, win one hosting takedown, and declare victory while the ads keep running to a fresh copy.

Frequently asked questions

Who should I contact first when my website is cloned?
The ad network delivering its traffic, if you can find the ads — that is usually the fastest lever, since clones live on paid traffic. In parallel, file abuse reports with the clone's hosting provider and registrar, and report the URL to Google Safe Browsing so browsers warn visitors. Capture evidence before filing anything, because takedowns destroy it.
Is cloning a website illegal?
Yes, on multiple grounds: wholesale copying of your text, images, and code is copyright infringement; using your brand name or logo to sell is trademark infringement; and harvesting payments or logins under your identity is fraud. That stack of violations is useful in practice — it gives you DMCA, trademark, and fraud channels to run in parallel.
How do I find out who is hosting a cloned website?
Run an IP or ASN lookup on the clone's domain to identify the hosting provider, and pull the WHOIS record for the registrar and registration date. If the site sits behind a CDN or reverse proxy, file the abuse report with the proxy service — it forwards the complaint to the real host, and phishing reports get priority handling.
Can I get a cloned website removed from Google?
Yes, in two ways. A DMCA removal request de-indexes the clone from search results, since it copies your copyrighted content. Separately, reporting it to Google Safe Browsing puts a full-screen warning in front of Chrome users — and Firefox and Safari consume the same list. Neither takes the server offline, but together they cut most of its traffic.
How do scammers get visitors to a cloned website?
Almost always paid ads or phishing — clones don't rank organically. Paid campaigns typically run brand-style creative on channels with weak transparency, especially native ad networks, where no official ad library exists. That is the good news: traffic that is bought can be cut off with an abuse report to the network, often faster than any hosting takedown.
The OpenAdLibrary Team
Written byThe OpenAdLibrary Team
Ad intelligence & native advertising research

We build OpenAdLibrary, the open ad-transparency platform. Every day our systems capture live native ads across Taboola, Outbrain, MGID, Revcontent, Teads, Yahoo and MSN, identify the real advertiser behind each one, and follow the click to its landing page. These guides distill what we see in that data so you can research the market faster.