I wanted to share a new discovery of ours that lead us to disabling Shop Pay and Shop Pay Installments (temporarily for Shop Pay, and permanently for Shop Pay Installments due to the outrageous cost to us).
Several fake websites are using our company name in the URL that ends in .shop (i.e. https://thewinfield.shop (fake don’t use it!)). In searching our company name on Google several different .shop copycat websites appear within the first and second page results. What entices our customers to these sites are unrealistic discounts (i.e. 70% off).
Our customers are confusing this as an official Shop checkout (they use the same purple and everything), providing their personal information and credit card info in which the scammers use this information for fraudulent monetary gain.
Because of not seeing any search results in the community regarding this topic, I wanted to share this discovery with fellow Shopify stores.
Our customer base is older and less tech savvy. We had one angry customer yesterday call us because we would not give her the 70% off discount after she tried entering her credit card information five times and it wouldn’t go through. We were confused and she was upset that we had this sale and we were not honoring it. We have never ever ever had this type of sale. Still we didn’t put it all together until another customer called us today letting us know what he has discovered. Gave us the link and everything. For his kindness in letting us know, we gave him a $10 store credit. Thank goodness for faithful customers!
We have reported all the sites we have found so far to their registrars as their WHOIS is of course private. Who’s idea was that to privatize this information??
Anyway, wanted to share and hopefully spread the word.
Sincerely,
Jamie
Customer Service
The Winfield Collection
Hi @Winfield,
This is absolutely infuriating, and you did the exact right thing by prioritizing your customers’ safety. It is terrifying how easy to scam to trick less tech-savvy buyers. Disabling those payment options to break that visual association in their minds is a very smart and protective move.
Beyond reporting them to the domain registrars, I recommend you consider filing a DMCA copyright takedown request directly with Google. This will remove those fake .shop links from the search results entirely, which cuts off their main supply of victims. It is also a great idea to put a temporary, highly visible banner at the top of your real homepage warning your older customers that you only operate under your official domain and never offer 70 percent off sales.
Thank you so much for taking the time to warn the community about this issue.
Hope this helps!
I think you should try Google Ads targeting your own shop’s brand keyword. The cost-per-click (CPC) should be very low since you likely won’t have any competitors bidding on your exact domain name. This gives you a significant advantage, as your ad will appear at the top of the results first.
Report them to Google and file a DMCA complaint. You can also add a banner on your website clarifying that you don’t operate any other shop domains or affiliated stores. Over time, this strategy will help you reclaim and dominate your brand’s search presence.
Thank you for the advice everyone! I will be reporting to Google, but I have also reported to the registrar of the domain names in question as that information is not privatized. Most registrars do not want to be associated with fraud, so I believe they will take down the domain in its entirety (since some registrars also host, this could be a double whammy).
I wear many hats so this has definitely filled in my hours in between customer service duties.
~Jamie
Hi Jamie! @Winfield
This is a big problem and you are right to point it out.
A practical first step, then, is to protect your brand footprint: grab the key misspellings of your domain name, as well as your .shop name, before someone else does. You can place a distinct “official store” label or banner, and have a verification page on your web explaining that your is the only legitimate checkout domain.
And for customer protection, add a fraud alert on your product pages and your email footer, and let your customers know that you are not partnered with any other .shop domain that is not your own. Finally, keep an eye on search ads for your brand name, and quickly report any impersonators.
Hi Jamie, thanks for posting this. The “looks like Shop / Shopify checkout” confusion is especially dangerous for less technical customers, so the warning is useful for other merchants.
Disclosure up front: I’m behind ShadowShield, which focuses on protecting Shopify landing pages from cloning. It does not protect ads or Shopify checkout, so for this specific issue I’d keep checkout/payment fraud in a separate bucket from storefront cloning.
A few practical things I’d prioritize:
-
Create one obvious “official store / known scam domains” page on your real domain, then link it from your announcement bar, footer, order emails, and support replies. That gives confused customers and Google a canonical page to find.
-
Keep reporting each fake domain to the registrar, host, Google Safe Browsing, and Google Search. If you can document customers being tricked into entering payment details, include that evidence.
-
Monitor for new lookalike domains and copied landing/product pages. These campaigns often rotate domains, so the faster you spot the next copy, the faster you can warn customers and start takedown reports.
-
For the real Shopify storefront, consider adding protection specifically around high-traffic landing and product pages. It will not stop a scammer from creating a separate fake checkout, but it can make copied pages less useful and easier to detect.
I’d avoid framing this as a Shop Pay problem alone. The confusing checkout styling is part of the scam, but the broader issue is brand impersonation plus copied storefront content.