Clone Site Detection & Takedown

A cloned login or checkout page collects your customers' passwords and payments under your name, and they'll blame you rather than the attacker. Every day a clone stays up, more people type their details into it.

Price
$300–600 CAD
Turnaround
3–7 business days per batch

What's included

Finds fake copies of your site set up to steal your customers' logins or payments, then files to get every one taken down.

  • Look-alike and typo domain scanning, certificate transparency log search, reverse image search on your brand assets and copied-content matching
  • Checks against PhishTank, OpenPhish and Google Safe Browsing
  • Evidence package for each confirmed clone: screenshots, hosting and registrar details, side-by-side comparison
  • Takedown reports filed in parallel with the host, registrar, Google Safe Browsing, CDN and threat-intel feeds
  • Active password-stealing clones filed first
  • Report with takedown status per site and realistic timelines

Scales with the number of confirmed clones. Formal domain disputes (UDRP) against repeat offenders need a lawyer; those are flagged for you, not filed.

How it runs

  1. Start with what's public

    A free finding or a Security Snapshot. It only looks at what anyone on the internet can already see, so no access or passwords are needed.

  2. Talk it through

    A short call in plain English: what each finding means for your business, and which ones actually matter this month.

  3. Get the fix, not just the finding

    Deeper testing only happens under a written scope agreement. Fixes arrive as pull requests your developer can review, DNS records ready to paste, or takedown reports already filed.

  4. Keep watching

    Look-alike sites come back under new domains and new email senders appear. A retainer keeps someone watching after the report is done.

Often requested by

  • Law and accounting firms

    Wire-fraud and impersonation usually start in the inbox. If your domain has no email authentication, anyone can send a convincing "change of payment details" email as you.

  • Self-hosted online stores

    On WooCommerce, Magento and custom builds, an outdated plugin is a common way card-skimming code ends up in your checkout without you noticing.

  • Property management and real estate

    Tenant records, deposit payments and look-alike domains make you a target for payment redirection scams aimed at your clients.

Other services

Ask about Clone Site Detection & Takedown

Say what you run and when you need it. You'll get a fixed quote within the published range before any work starts.

Connect on LinkedInSee the code on GitHub

Opens your email app with this filled in.