Skip to content

Clone website: how to spot one

A clone website impersonates a real service to steal credentials, redirect payments, or induce the user to authorise harmful transactions.

In simple terms — A clone website copies the appearance and identity of a real firm, but sends logins, payments, or approvals to a fraudster. It is like a door painted to match the original that leads somewhere else.

A clone may reproduce a broker or exchange's logo, wording, address, and even a genuine registration number. The meaningful difference is often hidden in the domain, email address, phone number, or payment beneficiary. Real facts shown on the page therefore do not prove who operates it.

How it works and where to look

A victim may reach the copy through an advert, sponsored result, phishing message, or fake support profile. The domain may change one character, use another extension, or add reassuring words. After login, the page can capture credentials and security codes, display an attacker-controlled deposit address, or request a digital signature.

A website is a clone when it impersonates a specific real entity. An invented, opaque, or unauthorised operator is not automatically a clone. A padlock and HTTPS do not certify that the operator is honest either: they protect the connection to the open domain, which may still be the wrong one.

Clone website: credible copy, different destination Follow the flow, identify the decisive action, verify through a known channel. Unexpected link, Credible copy, Altered detail, Official route. OPERATIONAL MAP Clone website: credible copy, different destination Follow the flow, identify the decisive action, verify through a known channel Unexpected link: The route to a clone often starts with a contact or result that you did not open through the official channel. 1 Unexpected link Advert, email, or fake support Credible copy: Wording, branding, and a registration number may be genuine even when the domain belongs to a fraudster. 2 Credible copy Real logo and details on an altered domain Altered detail: A small variation redirects credentials, communication, or money to a destination controlled by the attacker. 3 Altered detail Login, contact, or payee changed Official route: Open the register and genuine site independently, then compare the domain, phone, email, and payment beneficiary. 4 Official route Find the register and contacts afresh Tab or tap: explore the four stages Cyclepedia diagram · Emiciclo
The decisive comparison happens outside the received page, using a register and contact details found independently.
Select the highlighted points to explore the detail

Verify and respond without following the clone

Open a known bookmark or type the competent authority's address yourself. Compare the domain character by character, then check the legal name, phone, email, authorised services, and payment account holder. Call the number published in the register, not the one displayed on the suspicious page. If one element does not match, stop the login or transfer until identity is confirmed through an independent channel.

If you entered a password, use the genuine service from a trusted device to change it, close active sessions, and enable multi-factor authentication. Notify the impersonated provider and preserve the URL, screenshots, messages, and receipts. If you sent money or authorised an operation, contact the payment provider and relevant authority promptly as well. Speed may limit further harm, but it cannot guarantee recovery.

Sources

Anti-scam · Red flags · Fake broker · Fake exchange