Your Store Cloned? How a Shopify Merchant Fought Back Against a Reverse Proxy Scam

Hey everyone, your friendly Shopify expert here, diving into a really critical discussion that popped up in the community recently. We all pour our hearts and souls into building our Shopify stores, right? So, the thought of someone cloning your entire website to scam customers is, frankly, terrifying. But it happens. And when it does, knowing what to do can make all the difference. That's why I wanted to shine a spotlight on a fantastic, albeit alarming, thread started by charleychau, who shared their detailed experience – and for that, a big :+1: from the community (and me!).

The Threat: What is a Reverse Proxy Clone?

Charleychau shared their harrowing experience with a 'reverse proxy clone' of their established store, www.charleychau.com. Imagine waking up to a Google Alert for your brand, only to find a nearly identical version of your website, pawio.us, hosted elsewhere. This wasn't just a static copy; it was a live mirror, pulling content from their actual site in real-time! The scammers had subtly altered the logo, swapped out email addresses, changed product prices to be cheaper (minus UK sales tax, which is a huge red flag!), and used a different, suspicious checkout.

Here's a look at the fake site they discovered:

spot-the-fake-01

Their goal? Likely phishing for personal and financial data, or outright defrauding unsuspecting shoppers. It's truly unsettling to see your hard work used for such malicious purposes.

Detecting the Imposter

The first crucial step, as charleychau found out, is detection. In their case, a Google Alert for their brand name was the hero. This highlights the importance of setting up brand monitoring. Keep an eye on:

  • Google Alerts for your brand name and key product names.
  • Social media mentions.
  • Regular searches for your brand.

Once detected, it's vital to act fast, but methodically.

Your Battle Plan: What CharleyChau Did (and What You Should Too)

When you discover a clone, panic is a natural first reaction. But charleychau's systematic approach is a masterclass in how to respond. Here's a breakdown of their actionable steps, bolstered by community insights:

1. Document Everything

This is non-negotiable. Before you do anything else, gather evidence:

  • Take screenshots of every cloned page.
  • Record a screen video whilst browsing the cloned site.
  • Create a detailed summary of the cloning, highlighting intellectual property infringements (logo, product images, text, brand name).

This documentation will be your ammunition for reporting.

2. Identify the Perpetrators (or their Proxies)

Charleychau started with a WHOIS lookup for the scam domain (pawio.us). Ajaycodewiz from the community pointed out that .us domains often provide personal data, unlike others where it might be redacted. This information is gold! It can reveal:

  • Admin and technical contacts (email, phone, address).
  • The domain registrar (e.g., Porkbun).
  • Name servers, which might point to a CDN like Cloudflare.

Here's what charleychau's WHOIS lookup revealed:

pawio-us-who-is-listing-23-july-2026

Even if the contact details seem fake, you'll get the registrar and CDN info, which are crucial.

3. Launch a Multi-Pronged Reporting Attack

This is where you hit them from all angles. Don't rely on just one report; cast a wide net:

  • Email the Scam Domain's Admin: Send a firm email outlining the infringements, demanding takedown within a specific timeframe (e.g., 48 hours), and threatening legal action.
  • Shopify DMCA Takedown: Even if the scam site isn't hosted on Shopify (as charleychau discovered with the pawio.us site), it's worth filing a DMCA request with Shopify. They might still be able to offer guidance or block access if the scammer somehow leverages Shopify's infrastructure in the future.
  • Domain Registrar Abuse Report: Contact the registrar (e.g., Porkbun) directly through their abuse report form.
  • CDN Abuse Report: If the site uses a CDN like Cloudflare, report it to them. As charleychau noted, Cloudflare's abuse form might even help you identify the actual hosting company.
  • Hosting Company Infringement Notice: Once you identify the hosting provider (e.g., Rashost), send them a detailed infringement notice. If it's an international host, consider using translation tools (like Perplexity, as charleychau did) to send it in their native language as well as English.
  • Google Reports: File reports for:
    • Intellectual Property infringements (for both general IP and trademark-specific issues).
    • Phishing activity.

    This helps get the fraudulent URLs de-listed from search results.

  • Law Enforcement: Report the fraud to your local police or relevant cybercrime authorities (e.g., UK Police through Report Fraud).

4. Turn the Tables: Use Their Own Mirror Against Them

This was a brilliant move by charleychau that garnered praise from NKCreativeSoulutions in the thread. Because the clone was a reverse proxy, changes made on charleychau.com appeared instantly on pawio.us:

  • Warning Banner: They published an announcement bar on their live website, warning customers about the scam. This immediately appeared on the cloned site, effectively turning the scammer's own platform into a warning system for their potential victims!

    pawio-us-unauthorised-cloned-site-with-warning

  • Confuse the Auto-Replacement: They cleverly altered their email address display on key pages. Instead of just "hello@charleychau.com", they changed it to "hello[at]charleychau[dot]com – replace [ ] with @ and ‘.’”. The scammer's automatic email replacement system then struggled, resulting in a garbled address on the clone that looked suspicious to visitors. Genius!

5. Inform Your Customers

Transparency builds trust. Charleychau posted a blog, shared on social media, and prepared an email to their customer base. Keeping your community informed not only protects them but also shows you're proactive and trustworthy.

The good news? Within 36 hours of discovering the clone, the scam site was taken down! Charleychau isn't sure which action was the silver bullet, but the multi-pronged approach clearly worked.

What About Technical Prevention?

Charleychau specifically asked the community if there's a technical solution to stop this from happening. The truth is, preventing someone from creating a reverse proxy clone is incredibly difficult, as they're essentially just mirroring your public-facing website content. However, your best technical defense lies in:

  • Robust Monitoring: As mentioned, Google Alerts, brand monitoring tools, and even simple regular searches are your first line of defense.
  • Staying Updated: Ensure your Shopify store and any third-party apps are always updated to patch potential vulnerabilities, though reverse proxy cloning often doesn't exploit direct vulnerabilities in your store itself.

The community didn't offer a magic bullet for prevention, and that's because there isn't one for this specific type of attack. The focus must be on rapid detection and aggressive, multi-faceted response.

Laza_Binaery also shared a helpful video, "How Anyone Can DESTROY A Scam Website in Minutes 😤 (Scammers Will HATE This)", which often lists additional resources for reporting. It's always great to have more tools in your arsenal!

An interesting update from charleychau showed the scam site (pawio.us) later displaying a Shopify login, suggesting the scammers might have moved on to cloning another unsuspecting Shopify site. This highlights the ever-evolving nature of these scams and the need for continuous vigilance.

image

So, while the digital landscape can be a wild west, stories like charleychau's remind us that with vigilance, a smart strategy, and the power of community, we can fight back and protect our businesses and our customers. Stay safe out there, and keep those eyes peeled for anything suspicious!

Share:

Use cases

Explore use cases

Agencies, store owners, enterprise — find the migration path that fits.

Explore use cases