In simple terms — A clone website copies the appearance and identity of a real firm, but sends logins, payments, or approvals to a fraudster. It is like a door painted to match the original that leads somewhere else.
A clone may reproduce a broker or exchange's logo, wording, address, and even a genuine registration number. The meaningful difference is often hidden in the domain, email address, phone number, or payment beneficiary. Real facts shown on the page therefore do not prove who operates it.
How it works and where to look
A victim may reach the copy through an advert, sponsored result, phishing message, or fake support profile. The domain may change one character, use another extension, or add reassuring words. After login, the page can capture credentials and security codes, display an attacker-controlled deposit address, or request a digital signature.
A website is a clone when it impersonates a specific real entity. An invented, opaque, or unauthorised operator is not automatically a clone. A padlock and HTTPS do not certify that the operator is honest either: they protect the connection to the open domain, which may still be the wrong one.
Verify and respond without following the clone
Open a known bookmark or type the competent authority's address yourself. Compare the domain character by character, then check the legal name, phone, email, authorised services, and payment account holder. Call the number published in the register, not the one displayed on the suspicious page. If one element does not match, stop the login or transfer until identity is confirmed through an independent channel.
If you entered a password, use the genuine service from a trusted device to change it, close active sessions, and enable multi-factor authentication. Notify the impersonated provider and preserve the URL, screenshots, messages, and receipts. If you sent money or authorised an operation, contact the payment provider and relevant authority promptly as well. Speed may limit further harm, but it cannot guarantee recovery.
Sources
- FCA — Clone firms and individuals — Explains how fraudsters reuse real firm details while changing contacts and how to verify a firm through the official register.
- FINRA — Imposter websites — Documents imposter sites that copy genuine firms to obtain money or sensitive information.
- CNMV — Financial scams and fraud — Describes cloned firms and URLs that are identical or very similar to those of authorised entities.
- FBI IC3 — NFT developer impersonation — Shows how a cloned page can request a wallet connection and trigger a malicious contract.