How to tell if your website has been cloned
· 7 min read
A cloned website is not an exotic attack. Copying a site is a right-click; making the copy take deposits is an afternoon. Hotels are a favourite target because the payoff is direct — a guest who believes they have booked a room hands over card details willingly, and neither the guest nor the hotel learns anything until check-in day. By then the money is gone and the argument about whose fault it was happens at the front desk.
The signals that reach you late
- A guest arrives with a confirmation you never issued — the classic, and the worst, because the fraud is already complete
- Chargebacks referencing stays nobody booked through you
- A drop in direct bookings while your traffic looks unchanged
- Search results for your hotel's name showing a domain that is almost, but not quite, yours
Everything on that list is discovered after the harm. The useful work is moving discovery earlier, and there are two honest ways to do it.
Watch certificate transparency
Every TLS certificate issued anywhere is published to public logs within hours. A domain registered to impersonate you — your name with a hyphen inserted, the word booking bolted on, a different suffix — almost always requests a certificate before it does anything else, because a padlock is part of the disguise. Watching those logs for names that resemble yours surfaces the infrastructure days before it is pointed at a victim. A watch list is not an accusation: a similar name has done nothing wrong until it serves your content. But you want it on the list.
Make the copy phone home
A copied page copies everything — including any small script the page loads. If that script, on your real site, quietly reports which domain it is being served from, then the clone reports its own address the moment somebody opens it. That turns detection from a search problem into a tripwire: you are not scanning the internet for copies, the copy is telling you where it lives.
The check that matters comes after: fetch the reported domain and confirm it actually serves your content before alerting anyone. A beacon report alone can be noise — a developer's staging box, a translation proxy. Independent confirmation is the difference between an alert and an accusation.
The day you find one
- Save evidence first: screenshots, the URL, the registrar, the certificate — takedowns need it and the page may vanish
- Report to the registrar and the host; most clones die at abuse@ within days
- Submit the URL to Google Safe Browsing and Microsoft SmartScreen — this poisons the clone for most browsers immediately
- Warn your guests through channels you control, without linking the clone
- If deposits were taken, tell your payment provider and the police report goes in writing
PharosHub automates the early half of this: the beacon that makes a copy report itself, the certificate-transparency watch, and the independent confirmation before you are told anything. What it will not do is pretend the takedown itself can be automated — that half is letters and patience, and anyone selling you a button that does it is selling the button.