Website Clone Scams: How One Shopify Store Fought Back Against a Reverse Proxy Attack
Hey there, fellow store owners! Navigating the digital landscape can feel like a wild west sometimes, and unfortunately, that means dealing with some pretty sneaky characters. I recently came across a really eye-opening discussion in the Shopify community that I just had to share with you all. It's a fantastic, albeit alarming, example of how one store owner, charleychau of Charley Chau, faced a sophisticated website cloning scam head-on and came out on top. Their story is a masterclass in vigilance and quick action, and it offers invaluable lessons for all of us.
The Alarming Discovery: A Reverse Proxy Clone
Imagine waking up to a Google alert for your brand name, only to find it linking to a website that's a near-perfect mirror image of your own – but it's not yours! That's exactly what happened to charleychau. A scammer had created a clone of their legitimate store, www.charleychau.com, at a different domain, www.pawio.us. This wasn't just a static copy; it was a "reverse proxy" clone, meaning it was pulling content from their live site in real-time. If Charley Chau made a change on their official site, it instantly appeared on the scammer's clone.
But there were tell-tale signs: the scam site had swapped out Charley Chau's logo for 'Pawio,' replaced their email address (which was originally hello@charleychau.com) and domain name in the copy, and, most crucially, altered product prices to be cheaper. The checkout process was also different, instructing customers to email them on hello@pawio.us before making a payment – a huge red flag for phishing or outright fraud.
Here's a glimpse of the fake site that charleychau shared, showing just how convincing these clones can be:

CharleyChau's Battle Plan: A Step-by-Step Approach
What charleychau and their team did next is truly inspiring and provides a fantastic roadmap for any of us who might find ourselves in a similar situation. They had "zero technical background" but still managed to execute a comprehensive plan. As NKCreativeSoulutions aptly put it in the thread, "Wow! What a saga and great thinking from all of you!!"
1. Document Everything
- They immediately ripped lists of URLs from both their live site and the cloned site to confirm the extent of the cloning.
- Screenshots of every cloned page and a screen video of browsing the fake site were taken.
- A detailed summary of the intellectual property infringements was written. This documentation is crucial evidence for any reports you file.
2. The "Whois" Investigation
This was a critical first step. A "whois" lookup for the scam domain (pawio.us) revealed key information: the admin contact (Gustav Grahnkom), the domain registrar (Porkbun), and that Cloudflare was fronting the nameservers. As ajaycodewiz pointed out, "it was .us domain, so you got personal data. For other domains, it is redacted." This is a good reminder that information availability can vary.
Here's the whois listing charleychau shared:

3. Multi-pronged Reporting Strategy
This is where charleychau really cast a wide net, reporting the clone to every relevant authority:
- The Scammer's Admin Contact: They sent a direct email to Gustav Grahnkom (grahnkomgustav@gmail.com), outlining the infringements and demanding a takedown within 48 hours, threatening legal action.
- Shopify: Even though the cloned site wasn't hosted on Shopify, they filed a DMCA takedown request. As charleychau later updated, Shopify confirmed they couldn't act directly since the site wasn't on their platform. This highlights an important point: always report to Shopify, but understand their limitations if the scam isn't hosted by them.
- Domain Registrar (Porkbun): Filed an abuse report through their abuse report form.
- CDN (Cloudflare): Filed an abuse report through their abuse form, which also helped identify the actual hosting company.
- Hosting Company (rashost.com in China): Used Perplexity to draft an infringement notice in both English and Chinese.
- Google: Filed reports for IP infringements (both trademark-related and general) and for phishing, aiming to get the scam URLs delisted from search results.
- Law Enforcement: Reported to the UK Police through Report Fraud.
Laza_Binaery also chimed in, thanking charleychau for their detailed case and pointing to an older video with additional links for reporting scam websites. It's clear that hitting every possible avenue is the way to go.
4. Smart Counter-Measures on Their Own Site
This was perhaps the most ingenious move! Knowing the scam site was a real-time mirror, charleychau:
- Published an announcement bar on their own website warning customers about the scam. Sure enough, it immediately appeared on the fake site! NKCreativeSoulutions loved this, saying, "I loved the idea (in a horrific way) that your warning about their site also appeared on their site. Too good!!"
- They cleverly altered their email address display on key pages from a simple "hello@charleychau.com" to something like "hello[at]charleychau[dot]com – replace [ ] with @ and '.'". The scam site's automatic replacement mechanism then produced a garbled, suspicious-looking email, further alerting potential victims.
Here's the warning appearing on the cloned site:

5. Inform Your Customers
Transparency is key. Charley Chau posted a blog, shared on social media, and was preparing an email campaign to inform their customer base about the scam and the actions they were taking. This builds trust and helps prevent your customers from falling victim.
The Swift Resolution and Lingering Questions
The amazing news? Within just 36 hours of discovering the mirror site, it was taken down! Charley Chau isn't sure which of their many reports finally tipped the scales, but the coordinated effort clearly paid off. This really underscores the importance of being proactive and hitting every possible angle.
One question charleychau posed at the end of their original post was about technical solutions to prevent this from happening again. Unfortunately, direct technical prevention for a reverse proxy outside your control is tricky. Since these scammers are essentially just displaying your content through their domain, stopping them outright often involves legal and reporting channels rather than a technical "fix" on your own site. However, maintaining a secure Shopify store, keeping your software updated, and regularly monitoring your brand online are your best defenses. Always ensure your customers are directed to your official domain, perhaps by linking to your authentic store here on Shopify.
The update from charleychau also mentioned something interesting: the pawio.us site later showed a Shopify login, suggesting it might have moved on to clone another unsuspecting site. This highlights the persistent nature of these threats, and it's a good reminder that these bad actors don't just disappear:

So, what's the takeaway? While it's frustrating to deal with these kinds of scams, charleychau's story gives us a powerful playbook. Be vigilant, document everything, report far and wide, use clever counter-measures, and communicate openly with your customers. Your quick action and community support can make all the difference in protecting your brand and your customers online. Let's keep sharing these experiences to make the eCommerce world a safer place for everyone!