How It Works
Scammers create pixel-perfect clones of popular shopping websites — same logo, layout, and design — but hosted on a slightly different domain name. Ads for "mega sales" drive traffic to the clone site, where shoppers enter card details that go straight to fraudsters instead of a real checkout system.
Real Example
A website with a layout and logo identical to a major online retailer, but hosted at a misspelled domain, runs a "festive mega sale," collecting card payments for orders that never ship.
Red Flags 🚩
- Domain name is slightly misspelled or has unusual extensions (.xyz, .shop, .in instead of .com)
- Came across the link via an ad or forwarded message, not a direct search
- No HTTPS padlock or inconsistent site security indicators
- Prices significantly below the same product on the genuine site
Protection Steps 🛡️
- Always double-check the URL spelling character by character before entering payment details.
- Navigate to retailers by typing their name into a search engine, not clicking ads.
- Use a payment method with fraud protection, such as a credit card, where possible.
- If a deal feels too good, verify the same product's price on the official site first.