All articles

Knowledge

The Fake Store Ranked Above the Real One.

Criminals don't need to hack your store to steal your customers — they build a convincing copy and buy an ad to place it above you in search. This is a case we followed closely, and what we'd do to catch it fast.

August 19, 2026 · Confidanti · 4 min read

  • brand-impersonation
  • fake-store
  • phishing
  • google-ads
  • monitoring

Every article in this series so far has been about protecting you from being the victim. This one is different. In a fake-store scam, you aren't the target. You're the bait. Nothing of yours gets hacked. Criminals copy what's already public: your name, your logo, your product photos, the look of your payment page, and aim it at your customers. Because nothing of yours is breached, nothing of yours raises an alarm. You typically find out when the messages start: "I paid three days ago. Where's my order?", from people who never bought from you.

A case we followed closely

Earlier this year we watched one of these play out against a large consumer-finance company — the kind of brand whose customers log in every month to download a payment slip.

The attackers didn't clone the whole website. They faked the one page that mattered: the customer portal where payment slips are downloaded. They built it on Google Sites — free, legitimate Google hosting, valid HTTPS padlock, nothing for a browser to flag. Then they bought a search ad on the company's own name. For at least ten days, anyone who googled the brand saw the fake portal in the top position, above the real one. Customers who clicked, logged in with their real credentials, and downloaded a "payment slip" were handing their money and their login to criminals. By the time the page disappeared, complaints from defrauded customers were already accumulating on public review sites.

Three details from that case matter more than the rest, because they're the pattern:

  1. Everything the attackers used was legitimate and free. A Google Sites page anyone can publish, an ad account anyone can open. There was no exploit, no malware, no break-in. Nothing a firewall or antivirus would ever see.
  2. The fake outranked the real brand on its own name. Paid search placed the scam above the genuine result for the exact query customers type. Trust in the search engine did the rest.
  3. Customers knew before it was over. The complaints were public while the fake stayed live. The detection signal existed; it just wasn't being acted on quickly enough.

What this looks like for your store

The target there was a payment slip. For an online store, it's whatever page the money flows through. The scam wears different clothes but it's the same animal:

  • A cloned storefront at a lookalike address — yourstore-offers.com, or your name with an rn where the m should be — selling your products at 40% off, collecting card numbers or instant payments, and shipping nothing.
  • A fake "second copy of your payment slip" or "order tracking — confirm your card" page, advertised to people searching your brand.
  • A copy of your Instagram or WhatsApp business profile, announcing a "flash sale" and taking payment in DMs.

In every version, the victim is your customer and the collateral damage is you: angry messages, chargebacks, refund demands for orders you never received, one-star reviews, and a name that, for a while, means "the store that took my money."

What we'd do

As the security team you don't have to hire, this is one of the few threats where we'd tell you up front: you cannot prevent it. Everything a criminal needs to clone you is public by design: that's what a storefront is. This isn't a close-the-door problem. It's a find-it-fast-and-take-it-down problem, and the cost of finding it slowly can escalate. So here's where we'd put the effort:

  • Watch for copies. Lookalike domains being registered, certificates issued for names resembling yours, your product photos and page layouts appearing on sites that aren't yours. This is what we watch for when we look at a store's exposure, because this scam is invisible from inside your own systems.
  • Search your own brand periodically, including the ads. Type your store's name into Google the way a customer would, and look at what ranks above you. That single habit can catch the fake on day one.
  • Watch the complaint channels. Review sites, your social mentions, your support inbox. A sudden cluster of "where's my order?" from people you can't find in your system is the earliest signal to watch.
  • Register the obvious lookalikes yourself. The two or three most plausible misspellings and variants of your domain cost less than one chargeback — and help route mistyping customers to your real store.
  • Make your real channel unambiguous. One official domain, stated everywhere — site, social bios, order emails, WhatsApp profile — and a standing line to customers: we never ask for payment outside it.
  • Have a takedown playbook ready. When a fake appears: report the ad to Google's brand-impersonation process, report the site to the hosting provider and registrar, report the profile to Meta, submit the URL to Google Safe Browsing and tell your customers, loudly and immediately, that a fake is live. Takedowns work; speed is the whole game. Having the list written down before you need it is what turns ten days into one.

The honest limit

Your brand is public. That's not a vulnerability to patch; it's the thing that makes you a business. The only defense against someone wearing your name is noticing fast and responding faster. Don't be the one with a fake collecting from your customers, under your logo, above your own site, running for several days.

For your IT team. Certificate-transparency log monitoring for lookalike hostnames, permutation scans of your domain, reverse-image or favicon-hash searches for your assets, and alerting on brand-term ad placements. We keep the technical version of this playbook for whoever owns that side of your stack. See what we'd check →


Wondering whether anyone is already wearing your store's name? Looking for fake copies of your site is part of how Confidanti assesses a store's exposure. Talk to us.