The first you hear of it is usually a customer. Not a nice one. Someone who paid $89 for your best-selling product on a site that looked exactly like yours, got nothing, and is now in your Instagram DMs calling you a thief.
What’s in This Article
You did not sell them anything. A criminal did, wearing your logo, your product photos and your About page, on a domain that is one letter off yours. But the customer does not know that, Google does not know that, and by the time you work out what is happening the same ad has been running to your exact audience for a fortnight.
Most founders treat a clone store as a one-off crisis. They panic, fire off an angry email to whoever they can find, post a warning story, and hope it goes away. The brands that come out clean treat it as a process they have already built: the assets are pre-registered, the detection net is running, the takedown ladder is written down, and the customer script is ready before the first DM lands. This is the 5-step system we use inside eCommerce Circle to get a fake site off the internet in days instead of weeks, and to make sure your customers blame the scammer, not you.
Why Clone Stores Are Coming for Brands Your Size
Five years ago a scammer needed a designer, a copywriter and a week to fake a store convincingly. Today one person with a $1 Shopify trial, a page scraper and an image generator can clone yours in an afternoon and run it at volume. The ACCC said as much in August 2026: consumers “can no longer rely on appearance alone” to tell a real business from a fake, because AI has collapsed the cost of looking legitimate.
The numbers explain why it keeps happening. Shopping scams were the most reported scam type involving a financial loss in Australia across January to September 2025, with 9,628 loss reports to Scamwatch and $8.6 million lost, up 19 per cent on the year before. Online content, meaning fake websites, ads and social posts, was the number one first-contact method for every scam type and drove $122 million, or 47 per cent, of all reported losses in that window. The National Anti-Scam Centre’s March 2026 Targeting Scams report put total Australian scam losses at $2.18 billion for 2025, and reported that online-based scams with a loss rose 31.8 per cent in a single year.
Clones of Aldi, Myer and JB Hi-Fi get picked up fast because those companies have legal teams and the media notices. A clone of a $3 million-a-year candle brand in Geelong can run for months, because nobody is looking except your customers. The ACCC counted at least 360 reports about roughly 60 “ghost stores” in the first half of 2025 alone, and said the real number was clearly higher.
The Three Fakes You Are Actually Fighting
Founders lump every fake into one bucket, which is why they use the wrong takedown route. There are three species, each with a different weak point.
- The mirror clone. A pixel-for-pixel copy of your store on a lookalike domain (yourbrand-au.com, yourbrandoutlet.com, yourbrand.shop). It uses your photos, your copy and often your ABN. It exists to take card details and ship nothing. This is the one the National Anti-Scam Centre calls a “clone website”, and it is what hit Gorman, Peter Alexander, Rip Curl and Witchery. Weak point: it is a straight trade mark and copyright breach, so the host, the registrar and the platforms all have a policy that obliges them to act.
- The ghost store. Not a copy of you, but a fake “local boutique” that borrows a name close to yours and a suburb near you. Everly Melbourne next to the real Everly Collective. Willow and Grace Adelaide next to the real Grace & Willow in Williamstown. It runs “closing down, ends tonight” ads on Facebook, drop-ships rubbish from overseas, and your inbox fills with refund demands from people who think they bought from you. Weak point: it makes false representations under the Australian Consumer Law, which is why the ACCC issued Public Warning Notices against four of them in July 2025 and a further 10 shut down after the regulator leaned on Meta and Shopify in December 2025.
- The hijacked account. No website at all. A compromised Facebook or Instagram account, sometimes a customer’s, sometimes a creator you have gifted, posting a “fire sale” of your products with a payment link. The ACCC flagged this as a growing pattern in November 2025. Weak point: it is an account-security problem, so the fix is a platform report plus the account owner recovering access, not a domain takedown.
Identify which one you are dealing with in the first ten minutes. Everything after that depends on it.

Step 1: Pre-Register the Assets That Make Takedowns Fast
The speed of every takedown is decided months before the fake appears. Platforms move quickly for rights holders who can prove ownership in one screenshot, and slowly for everyone else. Do these four things this month, while nothing is on fire.
- Register your trade mark with IP Australia. Not “pending”. Registered. Meta’s Brand Rights Protection tool, Shopify’s trade mark infringement form and Google’s trade mark complaint process all ask for a registration number, and a pending application gets you the slow lane. If you have not done this yet, the Brand Protection Playbook walks through what to register first and what it costs.
- Enrol in Meta Brand Rights Protection. It is free, but you have to apply through Business Manager, and Meta requires an active registered trade mark, a verified business and no history of IP violations on your own account. Once approved you can search Facebook, Instagram and Marketplace for your brand name and images in one place and file bulk takedowns that Meta typically reviews within a day. Apply now so the approval is sitting there when you need it.
- Own the domains a scammer would buy. Your .com.au and .au are a start. Add the .com, the obvious hyphenated version, and yourbrand-au, yourbrandaustralia and yourbrandoutlet across .com and .shop. At $15 to $30 a year each this is the cheapest insurance in ecommerce. Set them all to redirect to your real store.
- Put your official URL in writing everywhere. Your Instagram bio, email footer, packing slip and FAQ should all carry the same sentence: “Our only website is yourbrand.com.au. We never sell through any other domain.” Aldi’s version, “DoorDash is the only platform that sells ALDI supermarket products online in Australia”, is exactly this move. It turns every customer into a detector.
Step 2: Build a Detection Net That Costs 15 Minutes a Week
You will never out-monitor a criminal syndicate, but you do not have to. You only need to find the fake before your customers do in volume, and most clones announce themselves in four predictable places.
- Google Alerts on your brand name plus modifiers. Set alerts for “yourbrand”, “yourbrand sale”, “yourbrand 80% off”, “yourbrand closing down” and “yourbrand scam”. Clones need to be indexed to rank in Shopping results, so they show up here within days of launch. Free, five minutes to set up.
- A weekly brand-search check in an incognito window. Search your brand name and your top three product names, and look at the sponsored results, not just organic. The ABC found that half the sponsored tumble dryer results on Google in September 2025 pointed to fraudulent Aldi clones. If a stranger is bidding on your brand with your images, you will see it here. The Brand Search Defence Playbook covers how to hold that real estate yourself.
- Meta Ad Library search. Go to facebook.com/ads/library, set the country to Australia, search your brand name and your hero product name. Ghost stores and clones run paid ads, and every active ad on Meta is public here, including the advertiser page and the destination URL. Screenshot anything that is not you.
- Reverse image search on your hero product photo. Once a month, drop your three most-used product images into Google Lens. Clones scrape images, and this is the fastest way to find a site you have never heard of using yours.
Then build the fifth channel, which is your customers. Add a “Report a fake site” link to your footer and FAQ that goes to a short form (URL, screenshot, where they saw the ad). Scamwatch’s June 2026 guidance for impersonated businesses says exactly this: create a clear process for customers to report impersonations to you, because it lets you act in hours instead of weeks.

Step 3: Run the 48-Hour Takedown Ladder
When you find a fake, the temptation is to send one furious email and wait. Do not. File on every rung of the ladder on day one, in parallel, because you do not know which one will move first and each report strengthens the next. Before you start, build a two-page evidence pack: full-page screenshots of the fake with the URL and date visible, side-by-side shots of your original product pages, a copy of your trade mark registration, and a WHOIS lookup of the fake domain. Every form below asks for the same evidence, so build it once.
- Rung 1: The host and the registrar. Run the domain through a “who hosts this website” lookup (Scamwatch recommends exactly this). If it is on Shopify, use the Report a Merchant form and choose trade mark infringement, with your registration number and direct links to the infringing pages. Shopify takedowns backed by a registered mark usually resolve in days. If it is elsewhere, email the host’s abuse address (abuse@ works for almost every provider) and file separately with the registrar (GoDaddy, Namecheap, Cloudflare and the rest all have an abuse form). Registrar action kills the domain even if the host is slow.
- Rung 2: The platforms carrying the ads. Report the ad in Meta Brand Rights Protection if you are enrolled, or through the “Report ad” link and the trade mark report form if you are not. For Google, file a trade mark complaint against the Shopping and Search ads and, separately, report the site to Google Safe Browsing (safebrowsing.google.com) as a phishing page. Safe Browsing is the sleeper move: once the URL is flagged, Chrome and Safari show a full-screen red warning to every visitor, which kills the clone’s conversion rate even before the site comes down.
- Rung 3: The regulators. Report to Scamwatch as a business impersonation and to ReportCyber (cyber.gov.au). In 2025 the National Anti-Scam Centre sent more than 8,400 websites for assessment and had over 7,500 scam URLs removed, referred more than 7,000 suspected Facebook scam URLs to Meta and 2,098 ads to Google. Your report feeds a takedown service that has more pull with the platforms than you do.
- Rung 4: The payment rails. Place a test order on the fake site for the cheapest item, then cancel or dispute it. The order confirmation tells you which payment processor and which merchant name is behind the store, and processors shut down fraudulent merchants fast when a rights holder reports them with evidence. A clone with no way to take money is worthless.
Log every report with a timestamp and reference number, and chase anything that has not moved in 72 hours. Expect the clone to come back under a new domain within a week; the ACCC noted ghost stores routinely close and rebrand with a different suburb in the name.
Step 4: Protect the Customer Before They Blame You
A takedown protects your brand tomorrow. This step protects it today, because the people who have already paid the clone are about to decide whether you are the victim or the villain. LegalVision’s disputes lead put it bluntly to SmartCompany: the businesses that get hurt are the ones “ignoring known impersonation activity, or delaying warnings after it becomes aware customers are being targeted”.
- Publish a warning within 24 hours, on every owned channel. Instagram story and pinned post, Facebook, a banner on your homepage, and an email to your list. Name the fake domain. Say plainly that it is not you, that you have reported it, and what customers should do. Gorman’s August 2023 post (“deeply heartbroken to hear some of our customers have unknowingly fallen victim to a scam website masquerading as our company”) is a good template: honest, specific, and clearly on the customer’s side.
- Give victims the one action that actually gets money back. Tell them to contact their bank or card issuer immediately and dispute the transaction as fraud. Card-not-present fraud on a site that never shipped is the cleanest chargeback there is, and speed matters. Point them to Scamwatch to report it and to IDCARE (1800 595 160) if they entered ID documents. Do not offer refunds for orders you never received; you will bleed cash and you will teach the scammer that cloning you pays twice.
- Arm your support team with a macro. One saved reply that explains what happened, confirms your only official domain, gives the bank and Scamwatch steps, and offers a genuine gesture (a discount code on a real order is fair). Scamwatch’s guidance is to make sure customer service staff know how to talk about impersonation and where to send people. A confused first reply is how a scam victim becomes a public one-star review about you.
- Tell people how you will and will not contact them. If your emails and SMS never carry payment links, say so on your site. Scamwatch’s advice to impersonated businesses is literally “don’t use links”, because it makes every fake message easier to spot. At minimum, commit that you will never ask for payment by bank transfer, gift card or crypto, and that discounts over a stated ceiling are never real.
Keep the warning up for at least 30 days and preserve every piece of evidence; if the ACCC ever pursues the operation, your file of reports and screenshots is what turns an investigation into enforcement.

Step 5: Make Your Real Store Harder to Fake and Easier to Trust
You cannot stop a criminal buying a domain, but you can widen the gap between what they can fake and what your customers have learned to look for. The ACCC’s own list of ghost-store tells is a design brief for a trustworthy Australian store; make sure you pass every one of them.
- Trade on a .com.au or .au and say why. A .com.au requires an Australian ABN to register, which is precisely why most clones sit on .com. Put a line in your footer explaining it. It costs nothing and it teaches your audience the single easiest check.
- Show the things a ghost store cannot. ABN, a real street address, a phone number that rings, an Australian returns address, and terms that reference Australian law. Every one of these is on the ACCC’s list of missing items on fake sites. Put them in the footer of every page, not buried on a contact page.
- Lock down your own accounts. The hijacked-account variant only works if an account gets taken over. Two-factor authentication on every staff Meta login, a review of who has admin on your Page, and a rule that creators you gift must have 2FA on. The Store Lockdown Playbook covers the full checklist.
- Get verified where it is offered. Meta Verified for business, the Google Business Profile with your real domain, and a claimed Trustpilot or Google reviews profile. Clones cannot show a blue tick or a two-year review history, and the ACCC specifically tells consumers to check independent review sites before buying. Give them something to find.
What It Looks Like When Brands Get This Right (and Wrong)
Gorman was cloned repeatedly through 2023, with fake sites advertising its prints at 80 per cent off on Facebook and Instagram. The brand went public fast, named the problem, said what it was doing, and got several offending sites shut down. Its statement that it would “continue to take urgent action where required to protect our valued customers” is the posture you want: visible, specific and ongoing rather than a single apology.
Everly Collective is the cautionary version. When the ACCC issued a Public Warning Notice against the ghost store “Everly Melbourne” in July 2025, the real Australian label found itself fielding “numerous inquiries from concerned customers who have mistaken our business with theirs”, and had to publish a statement that it was “a completely separate entity registered in Australia”. Nothing Everly Collective did was wrong. But a pre-written “our only website” line, a footer with ABN and address, and a support macro would have turned a week of confused DMs into a two-line reply.
Aldi shows the enterprise version: one standing line on the only legitimate channel, active engagement with the National Anti-Scam Centre, and direct escalation to Google, which pulled the fraudulent Shopping ads and actioned the advertiser accounts. You do not need Aldi’s legal budget to copy the structure. You need Step 1 and Step 3.
The Compound Effect (and Why 31 March 2027 Matters)
Each step on its own is modest. Together they change the economics for the person cloning you. The pre-registered assets in Step 1 mean your takedown requests land in the fast lane. The detection net in Step 2 means you find the fake in week one, when it has taken twenty orders, not week six, when it has taken four hundred. The parallel ladder in Step 3 means the host, the registrar, the ad platform, the regulator and the payment processor are all moving at once, so the clone loses traffic, then money, then the domain. Step 4 means the customers it did catch walk away angry at a criminal rather than at you. Step 5 means the next clone converts worse, because your audience has learned what real looks like.
Scammers are running a numbers game across thousands of brands. A brand that costs them a domain every week and converts poorly gets dropped for one that does not fight back. That is the whole aim: not to win a war, but to be the store that is not worth cloning.
There is also a legal clock running in your favour. Australia’s Scams Prevention Framework formally designated banks, telcos and digital platforms (including social media and paid search advertising) as regulated sectors on 28 May 2026, and the bulk of their obligations to prevent, detect, disrupt and report scams commence on 31 March 2027. From that date, a platform that keeps running a fake ad wearing your brand after you have reported it is exposed to civil penalties, and scam victims can take complaints to AFCA. Your evidence pack and your report log are about to become much more powerful than they are today. The brands that already have the process built will be the ones that can use it.
The Clone Store Response Kit (Steal This Checklist)
Build this in a shared doc now. When the first DM lands, you open it and work top to bottom.
- Before anything happens: trade mark registered; Meta Brand Rights Protection approved; lookalike domains owned and redirected; “our only website” line live in bio, footer, emails and packing slips; Google Alerts running; “Report a fake site” form in the footer; support macro written; 2FA on every social login.
- Hour 0 to 1: classify the fake (mirror clone, ghost store, hijacked account); capture full-page screenshots with URL and date; WHOIS and host lookup; place a test order to identify the payment processor.
- Hour 1 to 4: file with host and registrar; file with Shopify if applicable; report ads through Meta Brand Rights Protection and Google trade mark complaint; submit the URL to Google Safe Browsing; report to Scamwatch and ReportCyber; report the merchant to the payment processor.
- Hour 4 to 24: publish the customer warning on every owned channel, naming the domain; email the list; switch on the support macro; brief anyone who answers the phone.
- Day 3: chase every report with no movement; check the Ad Library and brand search for a rebranded clone; add any new domain to the same evidence pack.
- Day 30: review what got the fastest result and update this kit; keep the warning live until the last report has gone quiet.
Inside eCommerce Circle, Protection is one of the 10 P’s we work through with every member, and brand impersonation is now a standing item on it because it is no longer a big-brand problem. If you want to see exactly where your store is exposed, and which of the 10 P’s is capping your orders right now, take the free More Orders Scorecard. It takes two minutes and shows you which P to fix first.



