Case studies / An imposter site, dead in days, not months
An Imposter Site, Dead in Days, Not Months
A pixel-for-pixel clone of a pre-IPO mining company's website appeared online, carrying the company's real street address and a working contact form collecting inquiries meant for the real business. It had been live for months before anyone noticed. Once we saw it, taking it off the internet was a matter of days, not months.
The short version
We don't name clients. Here's exactly what happened anyway. Someone cloned a pre-IPO mining company's entire website, pixel for pixel, onto a lookalike domain, kept the company's real street address on it, and left the contact form running, collecting inquiries meant for the real business. It had been live for roughly eight months before anyone noticed. From the day the engagement opened, taking it off the internet was a matter of days, not months: HTTP 200 to 403, verified, and still dead at every check since.
Research: what we found
The clone was not a parody or a fan page. It was the company's own site copied wholesale: verbatim text, the same images with identical filenames, the real corporate address, and a live inquiry form. For a pre-IPO company whose inbound is investors and partners, that form was the threat. Every message it collected was a conversation the real company never knew it was missing, held by someone pretending to be them.
The copying was also sloppy, and that sloppiness became our best evidence. The imposter had run a find-and-replace to swap the company's name for their own and missed spots: the client's real corporate name was still sitting in the clone's own pages, direct proof of copying rather than coincidence. We documented all of it before touching anything: full-page captures of both sites side by side, archived snapshots preserved with a third party, domain records, and the client's corporate registry filings.
One more finding shaped the whole plan: the lookalike domain's registrar and its hosting company were the same business. One pressure point covered both.
Plan: what we told them
We told the client this was winnable without a lawsuit, and faster. Registrars and hosts operate formal infringement processes with statutory teeth, and a copyright takedown notice built exactly to the format the law prescribes is the tool they respond to. The plan: assemble the evidence package first, then put the notice to the registrar-host's abuse channels and work the case thread until the site went dark.
We were straight about what would not help. Emailing the clone's contact form delivers a warning to the imposter and nothing else. And a loosely written demand letter, however forceful, carries no obligation for anyone to act on it. The paperwork discipline was the strategy.
Mid-engagement, that discipline caught our own mistake before it cost us. Verifying the client's identity against the official corporate registry, we found the draft notice cited a wrong corporate registration number, and that the client had legally renamed since the clone appeared. Both were corrected and disclosed in the notice as filed. A takedown that misidentifies the complainant is a takedown that fails.
Execute: what we did
- Apr 24 Engagement opened; evidence built and submitted the same day Side-by-side captures, preserved snapshots, domain records, corporate registry documents. The takedown notice went to the registrar-host the same day, with six supporting exhibits.
- May 20 Registrar blocked the site Written confirmation that the infringing content was blocked. We verified it directly: the clone went from HTTP 200 to HTTP 403.
- May 21 Client sent the dead link Proof delivered as a link that no longer resolves to their stolen website. Engagement closed.
Monitor: what we watch now
A takedown is only as good as its persistence, so the dead clone gets re-checked. It still returns a blocked status, months after the takedown. That checking is not a courtesy. Operators who clone a site once have already shown they will do it, and a blocked domain can come back the moment attention moves elsewhere. We kept watching precisely so they could not quietly return. If that domain started serving content again, we would know, and we would be back in the registrar's case thread within minutes, on an existing file with the evidence already assembled.
The watch is wider than one dead domain. The clone we killed is a known quantity. The real ongoing risk is the next one, so the monitoring also covers new lookalike registrations and copied content that has not surfaced yet. The larger lesson is the reason this study sits next to our monitoring work: the clone operated for roughly eight months before anyone noticed it, and every one of those months had a working form on it. Speed only starts counting from the moment of detection. You cannot move fast on a threat nobody has spotted.
The clone never came back.
Found a site pretending to be you?
Every conversation is confidential. Tell us what shows up when someone searches you, and we will tell you straight what is possible.
Start the conversation →Prefer email? Write to us directly.