Skip to main content
brand protection /

Someone Cloned Your Shopify Store. Here's What to Do

Recon Team · clone detectiondmcatakedowns

You found a site using your logo, product photos, and descriptions on another domain. First, preserve what you can see. Then report the right issue to the companies that control the site, domain, and search listing.

This guide covers the practical sequence from verification to reporting. It is general information, not legal advice.

Step 1: Confirm and Document the Clone

Before you do anything else, you need solid evidence. Screenshots disappear when sites go down, so document everything now.

Take timestamped screenshots of the cloned site. Capture the homepage, product pages, about page, and any pages using your content. Also try the Wayback Machine to save an independent snapshot.

Save the page source. Right-click the cloned site’s homepage and select “View Page Source.” Save the HTML file. It may contain references to your original domain, store name, or asset URLs.

Compare side by side. Take screenshots of your own store’s matching pages. You’ll need these for your takedown requests to show the original vs. the copy.

Check the domain registration. Run a WHOIS lookup at who.is or whois.com. Note the registrar name, the registration date, and the nameservers. You’ll need the registrar info for Step 4, and the registration date proves the domain was created after your store launched.

Recon monitors for lookalike domains and copied storefronts, but keep collecting evidence if you found the site manually.

Step 2: File a DMCA Takedown with the Hosting Provider

The Digital Millennium Copyright Act (DMCA) is your primary legal tool here. A DMCA takedown notice tells the hosting provider that the site is using your copyrighted content without permission and demands they remove it.

Find the hosting provider. The WHOIS lookup from Step 1 shows the nameservers. The URL after “Name Server” usually indicates where the site is hosted. If the nameservers point to Cloudflare (which is a CDN, not a host), use a tool like WhoisHostingThis.com to find the actual hosting provider behind it.

Locate their DMCA/abuse contact. Visit the hosting provider’s website and look for “Report Abuse,” “DMCA,” or “Legal” — usually in the footer. If you can’t find one, try emailing abuse@[hostingprovider].com.

Send a valid DMCA takedown notice. Under U.S. law (17 U.S.C. § 512), your notice must include:

  1. Your full legal name and contact information (address, phone, email)
  2. Identification of the copyrighted work being infringed (your store URL, specific page URLs)
  3. Identification of the infringing material and its location (the clone’s URL, specific page URLs)
  4. A statement that you have a good faith belief the use is not authorized by the copyright owner
  5. A statement, under penalty of perjury, that the information in the notice is accurate and you are the copyright owner or authorized to act on the owner’s behalf
  6. Your physical or electronic signature

Use our DMCA takedown letter template as a starting point. Response times vary by provider and by the completeness of the notice.

Step 3: Report to Shopify

If the cloned site is also hosted on Shopify (some are), you can report it directly through Shopify’s enforcement process.

Use Shopify’s Report a merchant page and choose copyright infringement, trademark infringement, phishing, or fraud based on what you observed.

Provide direct links to the reported content, links to your original material, and the requested contact and ownership information. File other relevant reports in parallel rather than waiting on one recipient.

Step 4: Report to the Domain Registrar

The domain registrar is the company where the scammer purchased their domain name (GoDaddy, Namecheap, Google Domains, etc.). You found this in your WHOIS lookup in Step 1.

Visit the registrar’s abuse page. Most registrars have a dedicated abuse reporting form. For example:

Include the same evidence package: screenshots, registration data, your notice, and links to both the original and reported content. Be precise about what policy or right you believe the site violates.

Step 5: Report to Google Safe Browsing

If the site is collecting credentials or payment information under false pretenses, report the specific URL to Google Safe Browsing. Google evaluates reports and may show warnings for pages it classifies as dangerous.

Submit the report here: safebrowsing.google.com/safebrowsing/report_phish/

Provide the URL and describe exactly what the page asks visitors to do. Do not describe a copyright dispute as phishing unless the page is actually deceiving visitors for sensitive information or payment.

Also submit a spam report through Google Search Console if the cloned site is ranking in search results for your brand name: developers.google.com/search/help/report-quality-issues

Recon keeps the domain, redirect, and supporting evidence together so you can prepare the appropriate report.

Step 6: Notify Your Customers

If the clone site has been live for any amount of time, some of your customers may have encountered it. A brief, honest communication protects them and protects your brand’s reputation.

Post a notice on your store. A banner or blog post: “We’ve been made aware of a fraudulent website impersonating [Your Brand]. Our only official store is [yourstore.com]. If you’ve made a purchase from a different domain, please contact your bank immediately.”

Email your customer list. Keep it short and direct. Acknowledge the site, confirm your official domain, and tell affected customers where to get help.

Report on social media. Post about it. Your customers will appreciate the transparency, and it spreads awareness quickly.

Step 7: Set Up Ongoing Monitoring

One report does not monitor what happens next. Keep watching lookalike domains, copied storefronts, redirects, and browser warnings after the first case closes.

Recon continuously monitors for lookalike domains and copied storefronts, then keeps the evidence and recommended next step attached to the finding.

Install Recon free →


Quick Reference: Where to Report

WhatWhereLink
Hosting provider DMCAHosting provider’s abuse pageVaries (check WHOIS)
Shopify copyright or trademark claimShopify report flowshopify.com/legal/tools/report-an-issue/report-a-merchant
Domain registrar abuseRegistrar’s abuse formVaries (check WHOIS)
Google Safe BrowsingPhishing report formsafebrowsing.google.com
Google Search spamSearch quality reportdevelopers.google.com

Further Reading


Recon is a free Shopify app that monitors for cloned stores, lookalike domains, and phishing sites targeting your brand. Install it at recon.bot.

Recon detects this automatically. Install free on Shopify →

← All posts