One kit, ~90 fake .shop storefronts: inside the clone operation copying real brands
If you searched your own brand name and found a .shop version of your store selling your products at 65–70% off, you are almost certainly looking at one instance of a mass-produced kit. We traced it. Here is the evidence, the tell you can check yourself in ten seconds, and the one thing that actually gets a clone removed.
Published 28 July 2026 by Scam Detective · Every domain below resolved HTTP 200 with cache bypassed on 27 July 2026. A domain's status can change any day — re-check before relying on it.
What we found
Our case work started with one cloned US small business. Searching the verbatim fabricated testimonial strings on that clone surfaced roughly 90 further storefrontssharing the same template. Every one we probed was the same build: a real brand's name, a copy of that brand's catalogue, invented reviews, a boilerplate “10,000+ Happy Customers / 500+ Products / 50+ Countries” block, discounts of 65–70%, and a .shop domain. This is not a handful of opportunistic copycats. It is one production line, pointed at many brands at once.
An important limit on our own evidence. These storefronts share a generated social-image signature (443c03a007878a5d) and an asset-path scheme of the form /images/<clone-domain>/images/product/…. We do not treat that signature as proof of impersonation, and neither should you: two sites we checked that are not clones of anyone — kunuze.com and livingandesstore.com— return the same signature, and one exposes the underlying template as a commercially sold “DBH Next.js Starter Template”. The signature identifies a template, not an intent.
The combination we do treat as probative, and which every domain in the table below exhibits, is: reproduction of a real brand's name + a copied catalogue or product names + fabricated customer reviews + fake 65–70% discounts, together.
The four artefacts that give the kit away
1. The operator left their placeholder in the page title — and inside a fake review
johnderian.shop serves a page whose HTML title reads “Home | apiSanitizer”. The same string appears inside one of the page's own invented testimonials: “Shopping at apiSanitizer was seamless.”The template's internal name is sitting inside its own fabricated social proof.
2. Storefronts that serve their artwork from the real brand's own CDN
philipparoberts.shop hotlinks images — including the February 2026 homepage banner and the favicon — directly from the genuine philipparoberts.com. The real brand's own server is delivering the copy's artwork, and was still doing so on 27 July 2026.
Captured 4 August 2026, re-confirmed through 15 September 2026. Re-checking saboskirt.shop with cache fully bypassed, we found it doing the same thing across three classes of asset: it served the genuine brand's own hosted files — the hero image, the favicon and a category image — directly from the real brand's CDN. The hero image is saboskirt.com/cdn/shop/files/preview_images/bc5e3d8eeb774391be00ec34c4adedb8.thumbnail.0000000000_3840x.jpg, the favicon is saboskirt.com/cdn/shop/files/Sabo-Favicon-32x32-01.png, and a category image comes from cdn.shopify.com/s/files/1/0108/8959/2898/— the real brand's own Shopify asset path. That is file-level copying, which is the strongest class of evidence in this case file: the files were taken, not the look imitated. On 6 October 2026 this hostname did not resolve, so everything in this paragraph is a dated record of what it was serving on the dates named — not a statement about today. Its full reportcarries the detail. A hostname still observed serving the genuine brand's own files — read on 22 September 2026, and observed live, HTTP 200 again on 6 October 2026 — is philipparoberts.shop.
3. Copied files, not imitated designs
Where a brand runs on a platform that generates unique asset IDs, these storefronts reuse those exact IDs — which means a file was taken, not a look imitated. Two confirmed instances: The Winfield Collection's logo asset ID, and Kimirica's (KR_logo_244199d5-5473-42c5-9305-ca61537bb7bf). Two go further and ship logo files the operator named …-copy: tillmans-meats---copy-32x32.png and logo-copy.png. Product pages also reproduce internal part numbers verbatim — #BHNG1, #EYE3, #FMH, #CARB and paint codes 2030/2057/2505/2506 in the Winfield case.
4. The template-mismatch tell — the ten-second check anyone can run
The kit pours generic category copy into brands it does not understand, so the pages refute themselves. Read the reviews on a suspected copy and ask whether they describe products the brand actually sells. We found this on 12 of 33 storefronts:
stixyarnstudio.shop— a yarn shop whose reviews praise a floor lamp and dining chairskeywaydesigns.shop— phone cases, with an FAQ answering questions about mechanical keyboards and USB-C dockshighcountrygardensco.shop— a plant nursery whose page body sells “rugged mountain style apparel”michaelangeloskitchen.shop— a coffee seller reviewed for pasta saucemyredneckblinds.shop— deer blinds, reviews praising hoodiestheappointed.shop— paper goods, reviews praising ceramic vases and linen beddingmuhouse.shop— copy reading “handcrafted alongside artisans throughout ,” — an unfilled template variableshopkimirica.shop— offers free worldwide shipping; the real brand's own FAQ says it ships within India only
Two more, captured on a 4 August 2026 re-check with cache fully bypassed:
saboskirt.shop— a women's clothing label carrying a testimonial from “Marcus T.” praising “my SABO blazer”thewinfieldcollectionco.shop— a store selling woodworking patterns, with testimonials praising a “coffee table”, “linen curtains” that “filter light perfectly”, and generic “home decor”. Its meta description also claims a “trusted resource for hobbyists for more than 40 years” — on a domain that is not the real brand's
36 brands, 38 lookalike storefronts — all live on 27 July 2026
These are the domains we resolved ourselves, uncached, on 27 July 2026. We have not added, guessed or extrapolated a single one. We describe what each page serves; we make no assertion about any registrant's intent or criminality, and nothing here is legal advice.
Status updates since publication.The table is the record as captured on 27 July 2026 and is not rewritten. Where a later re-check found a hostname's state has changed, the row carries a dated marker in the same fixed vocabulary we use everywhere: live, HTTP 200, does not resolve, or resolves but not serving — HTTP nnn. On 6 October 2026 we re-checked every documented hostname with cache fully bypassed: 31 were live, HTTP 200, 19 did not resolve, 2 resolved without serving, and 8 could not be checked because our own fetch failed — those keep their earlier findings and their earlier dates rather than being re-stamped. Every hostname we could not read still resolves; the failure was at our own egress, so none of them is recorded as dead, and none of their dates moved.
A hostname's state moves in both directions. noguhq.shopreturned HTTP 404 with a “domain has not been configured” body on two separate cache-bypassed checks on 31 July 2026; on the last check of it we completed, on 22 September 2026, the observed state was live, HTTP 200 again, serving the full clone-kit storefront. We attempted a further check on 6 October 2026 and our own fetch failed before it observed anything, so there is no later reading of this hostname and its date has not moved — nothing here is a statement about what it is serving today. Its full report carries every observation, in date order. Nothing here is described as removed, suspended or taken down: that would mean a registry status code (clientHold or serverHold) read back off the record. Where we have now read one — on 22 September 2026, 29 September 2026 and 6 October 2026, for the hostnames that do not resolve — it is recorded on that hostname's own page as a separate, dated observation, it does not change the observed state, and it is not a claim that anyone acted, still less that anything we published caused it.
Added 17 August 2026.The “own-CDN” tell is not confined to the .shop kit. On 17 August 2026 we re-checked foursigtics.com — a lookalike of Four Sigmatic, built on WordPress/WooCommerce rather than the Next.js kit above — and found it serving four homepage images directly from us.foursigmatic.com, the genuine brand's own store domain. Different build, same artefact. The ten-second check is written up here.
Every hostname we have documented, in one place. The domains named above each have their own dated page, and so do the lookalikes we have found since on other platforms. They are listed together, under the brand each one copies, in the documented fake-store index— the fastest way for a brand's own team to find their entry.
Three further candidates were excluded rather than softened, because they did not resolve cleanly on 27 July 2026: doughgirlonline.shop (DNS failure), getkomodo.shop and shopwinnerscircle.shop (both HTTP 504). A timeout is not evidence of life.
Taking it down isn't the hard part. Filing correctly is.
The single most useful thing we have learned across this case file is that registrars and hosts do act — but only on a request that arrives in the shape they require. In one case a registrar set clientHold on a clone the same day the brand went public about it. And across three separate brands we found the same asymmetry with zero counter-examples: every domain a brand named publicly and filed against is gone; every unnamed sibling domain is still trading. The Winfield storefront above was first documented live on 27 May 2026 and was last confirmed “live, HTTP 200” on 15 September 2026 — 111 days. On 6 October 2026 its observed state was “does not resolve”. Through 15 September 2026 the only status on its registry record was the routine transfer lock that was there from the start — nobody had filed against that particular one so far as the record showed, and we hold no filing of our own for it. Reading GMO Registry, the .shop registry’s own RDAP record for thewinfieldcollectionco.shop on 22 September 2026, the record carried the status codes “client hold”, “client transfer prohibited” and “inactive”, last changed 17 September 2026 (2026-09-17T06:55:38Z). The registration itself is intact: created 12 May 2026, running to 12 May 2027, and not deleted. That is consistent with the “does not resolve” state we observed ourselves on 6 October 2026. clientTransferProhibited on its own is the routine lock carried by nearly every registered domain and shows nothing by itself. What we record here is the combination, read together: a hold on the registry record, no answer in the DNS on our own checks, and a registration that has neither expired nor been deleted — the name is still registered, it is simply not in the zone. We hold no filing, no correspondence and no reference number for this domain. We do not know who asked for this, or why. A registrar or registry acting after we published is not a registrar or registry acting because we published, and we claim no part in it.
Two other practical notes for anyone doing this themselves. First, Cloudflare name servers do not mean the operator is hidden — in our case work the real origin server resolved to a DNS-only A record outside all Cloudflare ranges, which is the party you actually file with. Second, verify the contact address before you write to it: one “brand” contact address we checked was published on the fake site itself, so emailing it would have contacted the impersonator rather than the business.
Is your brand on this list — or think it should be?
We ran the research above ourselves — the verified re-checks, the hotlinked assets, the dated readings. The $29 Brand Impersonation Audit does the equivalent for your brand specifically: every lookalike and typosquat name our generator produces from your own domain, resolved, and everything that answers fetched live with cache bypassed and graded against your own page — each confirmed-resolving hostname named with its dated readings, the copying evidence where we find it (your own hosted files being served, your image filenames, your catalogue handles or your title wording reproduced), a risk rating derived in code, our own published finding quoted verbatim wherever we already document a hostname, and a takedown request drafted with your details in square brackets. You send it.
For comparison, a single attorney-drafted cease-and-desist letter averages around $860 — before anyone has found the domains or captured the evidence.
We're not a law firm and this isn't legal representation. We don't file on your behalf, we don't contact whoever registered a domain, and no outcome or timeline is guaranteed — each suspension is the provider's decision alone. One-time payment, no subscription.
You can also read one complete $29 audit in full first — a real report, start to finish, nothing withheld. No email required.
Journalists and researchers
The underlying dataset behind this teardown — the full domain list, the discovery queries, the per-domain resolution log and the artefact captures — is available on request. Email scam-detective8@mail.acoco.ai. We will also tell you plainly which of our findings we consider inconclusive.
Scam Detective — pay-per-use scam intelligence. One-off checks, no subscription, no account.
Every finding here is an assessment of publicly available information at the time of the check, and is not legal advice. We do not execute takedowns, monitor continuously, or contact registrars on a customer's behalf; we produce the evidence and the correctly addressed request. Confirm your own trademark position before sending anything adversarial. Domain statuses were captured on 6 October 2026 and may have changed since.
Find out what's trading on your name.
Same research, pointed at your brand: the lookalike domains, the evidence, the registrar and true upstream host per domain, a risk rating, and the takedown request drafted to the format abuse desks accept. One payment, delivered in minutes.
Questions? scam-detective8@mail.acoco.ai