Infrastructure
A Fake Website Impersonating Your Business Can Be Online by Lunchtime

The little padlock in your browser bar does not prove a website is who it claims to be. It never did.
Somewhere between the day SSL certificates became free and the day anyone with a laptop could copy a full website in an afternoon, that padlock stopped meaning "trustworthy" and started meaning "encrypted". Those are not the same thing. A scammer can lift every page of your business website, register a domain one letter off yours, fit the copy with a free SSL certificate, and have a convincing fake live before you have finished lunch. The padlock will sit on the fake, green and reassuring, exactly as it does on the real one.
I have spent 20-plus years in Irish hosting, and I am a dot.IE accredited registrar. An email landed in my inbox on Monday morning that started the way these always do: "A customer rang to say they ordered from us, but we never got the order." That sentence is usually the moment an owner discovers a copy of their site exists.
What impersonation actually looks like for a small business
Forget the hoodie-in-a-basement picture. Modern impersonation is mostly copy and paste. There are three moves, and they tend to run together.
The clone. Your website is public by design. Every image, every line of copy, every product description can be saved by anyone with a browser. Attackers pull the lot and rebuild it on their own server. To a customer glancing at it on a phone, it is your site.
The lookalike domain. They register something a glance away from yours: a .com when you are a .ie, a hyphen where you have none, "yourbusiness-ie.com" in place of "yourbusiness.ie". In the trade it is called typosquatting, and it works because nobody reads a URL character by character.
The traffic. A cloned site with no visitors is harmless, so they buy it an audience. Fake social profiles and paid ads point people at the copy. Meta has taken legal action against advertisers doing exactly this, impersonating real brands to funnel people toward fraudulent sites, and it documents those cases on its own newsroom. The Banking and Payments Federation Ireland, through its FraudSMART programme, has flagged a surge in AI-generated online adverts pushing shoppers to counterfeit websites.
Now put it together for a real trader. Consider a Roscommon farm shop that ships Christmas hampers nationwide. A cloned site appears on a near-identical domain, running Facebook ads for "20% off hampers". Customers order. They pay. Nothing arrives. The complaints come to the real owner, because the real owner is the one whose name is on the shop. She did not lose a single order through her own website, and she is still the one fielding the angry calls, issuing apologies for money she never took, and watching a reputation she spent years building take the hit. That is the cruelty of it. The damage lands on the genuine business.

Why the padlock lies to your customers
This is the part that catches people out, including sensible ones. The padlock and the "https" were sold to the public for years as the mark of a safe site. That advice was never quite right, and it is now actively misleading.
An SSL certificate proves one thing: the connection between the browser and the server is encrypted, so nobody can snoop on it in transit. It proves nothing about who is on the other end or whether they are honest. The certificate authorities that hand out free certificates check that you control a domain. They do not check that you are a legitimate business, and they were never meant to. If you want the longer version of why the padlock does not mean what people assume, we pulled apart a related myth about SSL and PCI compliance that is worth your time.
The numbers make the point bluntly. Anti-phishing researchers, including the Anti-Phishing Working Group that tracks this quarter by quarter, have put the share of phishing sites carrying a valid SSL certificate somewhere in the region of 80 to 90 percent in recent years, and rising. The exact figure moves around depending on who is measuring and how, but the direction is not in doubt. The padlock is now background noise. A scammer gets one in minutes, for nothing.
So what does that mean for the person buying a hamper? It means the single visual cue most people were taught to trust is worthless as a test of legitimacy. They see the padlock on the fake, feel reassured, and hand over a card number.
The one structural defence Irish businesses have
There is a genuine advantage sitting in Irish businesses' laps, and most do not know they have it.
The .ie namespace is a managed one. As the IE Domain Registry sets out in its registration rules, every application for a .ie domain is checked to confirm the applicant has a real, provable connection to Ireland: an Irish company number, a VAT registration, proof of residence, that class of thing. You cannot sit in another country and casually grab the .ie version of an Irish business's name the way you can grab a throwaway .com. It is not impossible to abuse, and I will not pretend it is a force field. But it raises the cost and the friction of impersonation in a way the open .com free-for-all does not.
In practice, that means the domain you actually want to own for your business is the .ie. It is harder to clone, it signals to Irish customers that you are the real, verified operator, and it puts a barrier in front of the laziest impersonation attempts. This matters more than it used to. FraudSMART reports that more than three quarters of Irish adults, around 78 percent, are now targeted by scam texts, emails, calls or online content at least once a month, and that Irish SMEs lost over 17 million euro to email-related fraud across a recent two-year window. The Global Anti-Scam Alliance put it in even starker global terms in its 2025 State of Scams study of 46,000 people across 42 markets: roughly seven in ten adults had hit a scam in the previous year. Your customers are being softened up daily. A verified, obviously-genuine home for your business is not a nicety anymore.
I will own a mistake here. A few years back an owner showed me a lookalike domain of theirs that was registered but not yet doing anything, and I told them not to waste energy on a dormant domain. It went live as a phishing page about five weeks later. Would not give that advice again. A registered lookalike is a loaded gun sitting on a table. Treat it as intent.
What you can actually control
You cannot stop your public pages being copied. Anyone can view-source, anyone can save an image. Selling you a tool that "prevents cloning" would be selling you a fairy tale, and I would rather you trusted me on the things that are true. Accept that copying is possible, and change the question. The question is not "how do I make my site uncopyable". It is "how do I make my real site the obvious, authoritative, hard-to-beat original, and how fast can I respond when a fake shows up".
A proper defensive setup for a small business looks like this. You own the right domain, ideally the .ie, and you register the obvious close variants so the cheapest typosquats are already yours. Your real site carries a valid, auto-renewing certificate so it never throws a scary warning that pushes a confused customer toward a fake that looks cleaner. You have real monitoring and a real human to escalate to when something is wrong, rather than a support ticket into a void. And your platform keeps your actual site fast, patched and demonstrably yours, so it out-ranks and out-performs any hasty copy. If you want the full groundwork, our complete guide to WordPress security and backups for Irish sites is the pillar to start from.
This is the standard Web60 was built to meet. Every Web60 site runs on the enterprise-grade Irish infrastructure behind the whole platform, with SSL provisioned and renewed automatically, your data kept on Irish soil, and an Irish support team of actual people to escalate to when you spot something wrong at nine on a Tuesday morning. You get your own .ie domain, full WordPress control, and a real, fast, canonical site that makes a scrappy clone look like exactly what it is.
If you find a clone of your site, do this in order
Speed beats perfection. A takedown that happens today is worth more than a perfect legal case next month.
Document. Screenshot the fake site, the domain, and any ads pointing to it before they vanish. You are gathering evidence for the takedown requests, and fake sites disappear the moment they sense heat.
Report to the registrar and host. Every domain has a registrar and every site has a hosting provider. A WHOIS lookup or a quick abuse-address search surfaces them. Send them the evidence and cite impersonation and fraud. This is usually the fastest kill switch.
Report to the ad platforms. If fake ads are driving the traffic, report them to Meta, Google or wherever they run. Removing the ads chokes the fake's oxygen even while the site itself is still up.
Warn your customers. Post on your real channels that a fake exists, name the correct domain, and tell people how to reach you directly. Owning the message protects the customers you have not lost yet.
Reinforce the real site. Make sure your genuine site is fast, indexed and unmistakably you, so it stays the top result when someone searches your name. In Ireland, report the fraud to your bank's fraud team and to An Garda Síochána as well.
Where a lighter touch is fine
Let me be honest about scale, because I do not want to frighten a one-person operation into buying things they do not need. If you are a sole trader with no online payments, a handful of local customers, and a simple brochure site, the enterprise brand-protection platforms that monitor thousands of counterfeit listings are genuine overkill. Those tools earn their keep for large consumer brands drowning in fakes, not for the plumber in Ennis with a five-page site. For most owner-operators, owning your .ie, registering the obvious variants, keeping your real site fast and legitimate, and knowing the takedown steps above is a proportionate defence. Match the effort to the exposure.
The real lesson
The padlock was a good idea that got oversold, and a generation of customers learned to trust a symbol that no longer earns it. You cannot un-teach them overnight, and you cannot stop your public site being copied. What you can do is make your genuine business the loud, verified, fast, findable original, so that when a customer lands on a copy, something feels off, and the real you is one search away.
Impersonation is a bet that you are slow to notice and slower to react. The businesses that come through it well are simply the ones that decided, before anything went wrong, that they would be neither.
Frequently Asked Questions
Does an SSL certificate or padlock mean a website is safe?
No. The padlock confirms the connection between the browser and the server is encrypted. It says nothing about who owns the site or whether they are honest. Because SSL certificates are now free and quick to obtain, the large majority of phishing and clone sites carry a padlock too, so it is not a signal of legitimacy on its own.
How can someone legally copy my business website?
They cannot do it legally. Anything public on your site can be saved by anyone with a browser, but rebuilding it to pass their site off as yours is impersonation and, where money changes hands, fraud. The technical ease of copying is a separate matter from the legality of doing it, which is why your response is takedowns and reporting rather than trying to make your site uncopyable.
Can I stop someone registering a domain similar to mine?
You cannot pre-block every possible variation, and trying to buy them all is a losing game. You can register the obvious close matches yourself, register your business name as a trademark so you have firm grounds for a takedown, and use a namespace like .ie where registration requires proof of a genuine connection to Ireland.
What should I do first if I find a fake version of my site?
Document it with screenshots and the exact URL before it disappears, then report it to the registrar and hosting provider behind the fake, to any platform running fake ads, and to your own customers so they are not caught out. In Ireland, tell your bank's fraud team and report it to An Garda Síochána as well. Speed matters more than a perfect case.
Is a .ie domain safer than a .com for an Irish business?
For impersonation specifically, yes, in one respect. The IE Domain Registry requires every applicant to prove a real connection to Ireland, which makes casually registering a lookalike .ie of your business much harder than grabbing a throwaway .com. It is not a complete shield, but it raises the bar for the laziest attempts.
Sources
IE Domain Registry, how to register a .ie domain and the proof-of-connection requirement
FraudSMART, Banking and Payments Federation Ireland, scam awareness alerts and SME fraud figures
Global Anti-Scam Alliance, Global State of Scams Report 2025
Meta Newsroom, legal action against scam advertisers impersonating brands
Anti-Phishing Working Group, Phishing Activity Trends Reports
Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.
More by Graeme Conkie →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
WordPress Just Patched a Critical Flaw. 'It Updates Itself' Is Not the Same as 'I Am Protected.'
A pre-authentication WordPress core flaw let anyone break in without a password. Here's what 'automatic updates' actually covers, and what still needs checking.
Accessibility Overlay Widgets Do Not Make Your Website Compliant
An accessibility widget promises EU compliance for one line of code. The FTC fined the largest vendor $1m for that exact claim. See what genuinely works.
