Scammer reverse proxy clone of our website - what we did about it

Sharing in case it’s helpful for anyone who may find themselves in the same situation - a fraudster made a clone/mirror of our website and published it to another address. I have zero technical background, but we think they used a reverse proxy to create a live mirror of our website.

Our official site is www.charleychau.com and we’ve been trading on that domain since 2010. The scam site was at www [dot] pawio [dot] us.

(note I’ve had to edit this post and remove all links as I canat post more than 2 links as a new user to this community - hence all the weird formatting on web addresses below).

BACKGROUND

2 days we received a Google alert, triggered on our brand name “Charley Chau” – the link in the alert took us to a website at pawio[dot]us

The www[dot]pawio[dot]us site was a virtually identical clone of our Charley Chau site: site design, nav structure, products, pages, blogs, etc. Every single page from our website was copied. There were some changes:

  • They switched out our logo to their logo for ‘Pawio’.
  • They replaced all mentions of our email address [email removed] and swapped charleychau[dot]com for pawio[dot]us
  • They replaced all mentions of our web address from www[dot]charleychau[dot]com to www[dot]pawio[dot]us
  • The product prices had been altered to be cheaper than on our website – the clone site was showing effectively our price minus UK sales tax.
  • The checkout on the cloned site was different – it was not a clone of our Shopify checkout, and there was a message on their checkout page telling people to email them on hello[at]pawio[dot]us before making a payment.

Given the above, it looked to us like a site set up to start phisihing for either personal & finaincial data, or to go all out to defraud people out of money.

The cloned site was pulling content from our live site and publishing to the cloned site in real time – if we made a change on our own site, it appeared on pawio[dot]us instantly. However there was some kind of automation that replaced our email address and domain name when displayed in page copy.

Screenshot of the fake site:

WHAT WE DID ABOUT IT

The following summarises what we did. Not necessarily in a linear order as much of it was happening in parallel.

  1. Assessed and identified the scale of the cloning
  • We ripped a full list of URLs for our own live website
  • We ripped a list of all of the URLs on the pawio[dot]us site and compared them – every single URL matched like for like.
  1. We documented the cloning
  • Screenshotting every page cloned
  • Made a screen video whilst browsing the cloned site
  • Wrote a detailed summary of the cloning with focus on the intellectual infringements
  1. We tried to identify who was behind the domain, starting with a who.is look up for the domain. It gave us:
  • The admin and tech admin contact for the domain: Gustav Grahnkom; address 108 MOFFETT BLV, MOUNTAIN VIEW, California, 94043, US; Phone +1.3057079010; Email grahnkomgustav[at]gmail[dot]com
  • The registrar for the domain: Porkbun
  • It showed that the nameservers were fronted by Cloudflare

  1. We emailed the admin contact for the domain of the cloned site even though we did not expect to hear back, and stated:
  • Who we are
  • That we were contacting them because they were listed by who.is as the admin for pawio[dot]us
  • The reason we were contacting them – we used the summary of the IP infringements.
  • That the cloning and infringements were unacceptable.
  • A list of things that they must do: take everything down within 48 hours, and confirm by email once done.
  • We would escalate to our lawyers and law enforcement if they did not comply and cease the infringements.
  1. We started reporting the clone site to:
  • Shopify DMCA take down - we did not know whether the pawio[dot]us site was on Shopify itself but we started here just in case.
  • The domain registrar Porkbun through their abuse report form
  • Cloudflare as the CDN through their abuse form. We ticked the boxes that asked if we wanted to report this also to the hosting company and the owner of the domain – we got an auto reply giving us the hosting company name
  • Hosting company rashost [dot] com (in China) using Perplexity to write an appropriate infringement notice in Chinese and English
  • Google in relation to IP infringements to try to get the page URLs de-listed from – we made two reports, one for IP infringements not related to our TM and one for I{P infringement involving our TM.
  • Google for phishing
  • The UK Police through Report Fraud

Sorry I tried to inlcude links to all of these but as I am a new user on here, it won;t let me post them.

  1. We put up a warning on our live website
  • We published an announcement bar on our website, and as expected it was published immediately on the mirror site. the screen shot below is the cloned/mirror site showing our warning.

  • We went through key pages on our site where our contact details are published and replaced our email address which is normally just displayed as [email removed] to say instead: [email removed] ( hello[at]charleychau[dot]com – replace [ ] with [email removed] and ‘.’ ).” As expected, this change also then went into the mirror site BUT their automatic replace of our email address ended up looking like this: [email removed] ( hello[at]charleychau[dot]com – replace [ ] with [email removed] and ‘.’ )” - we thought that was weird enough to make most unsuspecting visitors to the mirror site to think something dodgy might be going on.

  1. We informed our customers
  • We posted a blog explaining what was happening and told them what we were doing about it
  • We posted on social and said we’d keep everyone updated
  • We were about to send an email out to our customer base too …

And then, within 36 hours of us discovering the mirror site for the first time, the mirror site was taken down.

We have no idea who took action – whether it was the fraudsters themselves, Shopify, Cloudflare, Porkbun or Rashost.

Now we know about this kind of scamming we will be very vigilant in looking out for these clones/mirrors.

I have zero technical knowledge but if anyone knows of how to stop this from happening with a technical solution then please do let us know. Thanks in advance!

An update - Shopify responded to our DMCA takedown request and confirmed that the Pawio site is not hosted on Shopify so they could not do anything about it. It’s odd because that site is now showing a Shopify log in - maybe they’re just cloning another unsustpecting site right now.

Wow! What a saga and great thinking from all of you!!

I loved the idea (in a horrific way) that your warning about their site also appeared on their site. Too good!!

Anyways, thanks for sharing and creating awareness of this, especially with advice on how to tackle the problem. It helps everyone to stay safer online.

I hope your problems are over and I wish you all the best,

Nathan

Hi @charleychau

Thank you for sharing your case, very detailed, and it should help a lot of users who land on this topic.

And Shopify, Domain registar are first to report but you mention a few others. I would also add some from this older video that helped us in a similar situation.

In the description there are some links to report. Just to be safe.

HAve a good day.

it was .us domain, so you got personal data. For other domains, it is redacted. though contacting domain registrar, hosting company (cloudlflare if proxied), google and other methods you mentioned are way to go

Thanks for sharing this video :+1:

Hi @charleychau, thanks for writing this up so clearly. This is one of the better practical playbooks I’ve seen for handling a live mirror / reverse-proxy clone.

Disclosure up front: I’m behind ShadowShield, a tool focused specifically on protecting Shopify landing pages from cloning. It does not protect ads or Shopify checkout, so in your case the fake checkout and payment-fraud side still needs the registrar/host/DMCA/law-enforcement route you already followed.

For the technical prevention side, I’d think about this in layers:

  1. Keep doing the operational response you described: screenshots, URL inventory, WHOIS/registrar/host/CDN abuse reports, Google phishing reports, and customer-facing warnings. That’s still the fastest path to takedown.

  2. Add clone detection and alerting, so you know quickly when a suspicious domain is mirroring your pages.

  3. Add storefront-side protection for landing/product pages, especially against simple HTML scraping and live proxy-style copying. It won’t make public web pages impossible to copy, but it can make cloned pages break, lose key functionality, or become much easier to detect.

  4. Keep checkout risk separate. If the attacker swaps in their own checkout, that part has to be handled through takedowns, customer warnings, reporting, and payment/fraud channels.

One thing I would avoid is relying only on “disable right click” or basic copy/paste blockers. Those can slow down casual copying, but they don’t really address automated mirroring.

Again, really useful write-up. The warning banner idea was smart because it used the clone’s own mirroring behavior against it.