Someone cloned my Shopify store. Here's the 24-hour playbook.

Someone cloned my Shopify store — the 24-hour takedown playbook

Someone cloned one of our client's stores last month. Same logo, same product photos, same brand name — with one word changed in the domain. Real card details were being collected under her brand at a fake checkout.

We got the site delisted from Google in under 24 hours, the host pulled the server in three days, and the payment processor cut the money layer in between. Below is the exact playbook, in the order you should run it. Speed matters more than getting it perfect.

Table of Contents

Key Takeaways

Question Answer
Who actually gets a copycat site down fastest? Google (via DMCA delist) then the host (via abuse report). Not the registrar.
Should I frame it as copyright or fraud? Both — but not to the same audience. Copyright to Google; fraud to the registrar and the payment processor.
Can Shopify help? No — the fake store is off-platform. Shopify can't do anything about a site that isn't hosted on Shopify.
Can ICANN help? No — they oversee registrar compliance policy, not domain suspensions. Wrong door.
What order should I do this in? Warn customers → DMCA to Google → Contact the host → Fraud report to registrar → Escalate to registry → Report the payment processor. All in the same day.

The 6-step 24-hour playbook

Do these in order. Same-day if possible. Don't wait to figure out who the "right" party is — send all of them.

1. Warn your customers today

A notice on your site and every social channel. Same day. The fake checkout is collecting card details under your brand — every hour it goes unflagged is real money out of real people's accounts. This isn't optional and it isn't a "let me draft something for a week" task.

Sample copy:

Important notice: We're aware of a website impersonating our brand at [do NOT name the domain]. It is not affiliated with us. Do NOT enter payment details. Our only checkout URL is [yourbrand.com/checkout]. If you've already paid there, contact your bank to reverse the charge and monitor the card for further fraud.

Post it on your homepage, your Instagram story, your Facebook page, your email list. Pin the social posts.

2. Report it to Google via DMCA

This was our fastest win. Google delisted the fake store from search in under a day. A scam store with zero search traffic does very little damage even while the actual server is still online.

The correct URL: reportcontent.google.com/forms/dmca_search

Do NOT use Google's general legal troubleshooter. It loops you in circles. The DMCA-for-Search form is the only fast path.

What to include:

Google acknowledges within hours. Delist usually happens within 24-48 hours.

3. Contact the host, not the registrar

This is where most guides get it backwards. The host runs the actual server — they can pull the site down. The registrar just sold the domain — they can't (in practice, won't) remove the site.

Find the host: whoishostingthis.com — paste the fake domain, get the host back in about 3 seconds.

Common answers:

4. When you do email the registrar, call it fraud — not copyright

The registrar is a lower priority than the host, but you should still send them a report. Just frame it right.

Registrars treat copyright as a content dispute. They pass. "We're not a court, this is a matter between the parties."

Registrars act on phishing and financial fraud. Different queue, different response time, different result. Same facts, different word.

Facts to lead with in the fraud report:

Send to the registrar's abuse email. Every registrar has one, usually abuse@[registrar].com. If they don't respond in 48 hours, escalate.

5. Escalate above the registrar to the registry

Almost nobody knows this. Every domain extension has a registry operator sitting above every registrar that sells it. The registrar is retail. The registry is wholesale. The registry has its own anti-abuse policy and can put a domain on hold independently of the registrar.

Registries move slower than Google but faster than registrars for clear fraud cases. And the registrar knows the registry is watching, so a cc'd escalation often unblocks a stuck registrar report.

6. Report the payment processor

Cuts off the money layer even while the site is still up.

Payment processor takedowns are underrated. Once card details won't process, the fake store is a static page with no revenue — and the operator usually abandons it within a week.

The two notice templates you need

Send both. Same facts, different framing.

Template A — DMCA notice (for Google + hosts)

Subject: DMCA Notice of Copyright Infringement — [yourbrand.com]

To whom it may concern,

I am writing on behalf of [Your Company Name], the owner of the copyrighted
material displayed on [yourbrand.com].

The following URLs contain material that has been copied from our site
without permission:

Infringing URLs:
- [fake domain]/product/xxx
- [fake domain]/collections/xxx
- [fake domain]/pages/about
- [additional URLs]

Original URLs (owned by us):
- yourbrand.com/product/xxx
- yourbrand.com/collections/xxx
- yourbrand.com/pages/about
- [additional URLs]

The material copied includes: product images, product descriptions, brand
logo, page layout, and marketing copy.

I have a good-faith belief that use of the material in the manner complained
of is not authorized by the copyright owner, its agent, or the law. The
information in this notice is accurate, and under penalty of perjury, I am
the copyright owner or authorized to act on the copyright owner's behalf.

Full legal name: [Your name]
Company: [Your company]
Address: [Your legal address]
Phone: [Phone]
Email: [Email]
Signature: /s/ [Your name]

Date: [Today]

Template B — Fraud + phishing report (for registrar + registry + payment processor)

Subject: Urgent — Brand Impersonation and Payment Fraud at [fake domain]

To the Abuse Team,

I am reporting active fraud and brand impersonation at [fake domain],
registered through your services on [registration date].

This site is a functional clone of my legitimate business at [yourbrand.com].
It has an active checkout page collecting credit card details under my brand
name. Real customers have already been charged for orders that will never
be fulfilled.

Evidence of fraud (not just copyright):
1. Active checkout collecting payment details under a false brand identity
2. Fake trust badges (SSL, "Secure Payment") implying legitimacy
3. Fake customer reviews impersonating our real reviews
4. Fake contact address that does not exist
5. Domain registered [X days] ago, no business history
6. WHOIS registration data appears to be false / privacy-shielded

My business:
- Registered legal name: [Your company]
- Operating domain: [yourbrand.com] since [creation date — pull from your WHOIS]
- Trademark: [registration # if you have one]
- Legal address: [Your address]

I am requesting immediate suspension of [fake domain] under your Anti-Abuse
Policy, or at minimum escalation to your fraud investigation team.

Customer safety is actively at risk. Every additional hour this site is
online is direct financial harm to real people.

Thank you,
[Your name]
[Your company]
[Contact info]

Send template A to Google DMCA + the host. Send template B to the registrar + registry + payment processor. Same facts, different framing, three different queues.

Why identical facts get different results

The same set of facts — a fake site collecting card details under someone else's brand — moves through three completely different abuse handling systems depending on which word you use to describe it.

Send everything the same day, using the right frame for each recipient's queue. That's the whole game.

How to read a WHOIS result

Every whois lookup returns three fields you care about. Most people confuse them.

Rule: the host controls the site. Everyone else controls something adjacent.

Identifying the platform from URL patterns

Sometimes the fake site is on the same platform as yours (Shopify), sometimes on something entirely different. This changes who to complain to.

Signals in the source code (right-click → View Page Source):

Once you know the platform, add the platform's own IP infringement form to your list.

Abuse forms for the biggest hosts

Bookmark these — you'll want them fast.

Why ICANN can't help

People email ICANN thinking they're the internet police. They're not. ICANN oversees registrar accreditation and policy compliance. They can't suspend a domain. They can't force a takedown. They can (very slowly) investigate a registrar for policy violations, which sometimes matters over months but never within your 24-hour window.

If a registrar is genuinely non-responsive after a valid fraud report + registry escalation, an ICANN complaint at icann.org/en/contact/compliance is worth filing — but it's a long-tail move, not a speed move.

What to do when they reappear under a new domain

Scam operators recycle. When the first fake domain gets taken down, they often re-register a slight variation (yourbrand-store.com → yourbrand-shop.com → yourbrandusa.com).

Set up:

"Do this today" checklist

Print this. Pin it. Hand it to your ops person.

Talk to Branva

If you're mid-incident right now and need a human to walk this playbook with you, book a working session. Free 30 min. We've done this before — we can move faster than you'll figure out solo.

Frequently Asked Questions

How long does the whole takedown usually take?

Google DMCA delist: 24-48 hours. Host takedown of the actual server: 2-7 days. Payment processor cut-off: 2-5 days. Registrar / registry domain suspension: 3-14 days depending on which extension. The whole thing is usually resolved in a week if you send everything on day one.

Can I sue them?

Yes, but slowly and expensively. A cease-and-desist letter from a real trademark attorney is worth having on file, but for a 24-hour takedown it does nothing. The playbook above beats litigation for speed. Save the lawsuit for the second offense.

What if the fake site is offshore and no US law applies?

The playbook still works because the host, registrar, registry, and payment processor almost always have US or EU operations subject to takedown law. You're not suing the operator — you're getting the infrastructure that supports them to disconnect. That works globally.

Should I try to buy the fake domain from the operator?

No. Never negotiate with domain squatters or scam operators. It validates the model and funds the next attempt. Takedown is the only path.

What about the customers who already got scammed?

They're your customers now, functionally. Route them to your support team, tell them how to dispute the charge with their bank/card issuer, offer to send them a real product at cost if it fits your economics. The customer-service goodwill from handling this well often outweighs the cost, and word travels fast in your niche.

Related reading