- AI, E-commerce
Cloned in just a few hours: the number of AI-generated copies of online stores is growing
A customer calls your customer service because her order still hasn’t arrived after three weeks. She’s angry—and rightly so. But she never actually ordered from you. She ordered from an online store that looked exactly like yours—with your logo, your product photos, and your descriptions—but with prices that were 30 to 80 percent lower.
This scenario is becoming increasingly common. Dutch online stores are being copied on a large scale by scammers who use AI tools to create a convincing look-alike in just a few hours.
They then advertise on Facebook and Instagram, often literally under your brand name. Well-known brands such as Kwantum, Shoeby, Leen Bakker, and Douglas have already been imitated, but smaller online stores are also increasingly becoming targets.
Before you start to panic: this is annoying, but it’s manageable. There’s a clear path to taking down such a site, and it works. Below, we explain exactly what happens, how to spot it in time, and what steps to take.
Why is this suddenly happening so often?
Until recently, cloning an online store involved a lot of manual work. Someone had to copy the layout, download images, rewrite text, and list products online. That took days and usually resulted in a sloppy product that an observant consumer could see through pretty quickly.
That hurdle is gone. With AI, you simply enter the URL of your existing website, and it generates a visually nearly identical copy.
Product descriptions are automatically rewritten. Ad copy and even customer reviews are generated. The result looks professional—precisely because it’s modeled after your professional site.
The scammers then run ads on Meta platforms, where targeting Dutch consumers is inexpensive and effective. The offers are aggressive: discounts of fifty, seventy, or eighty-five percent, often linked to a “going-out-of-business sale” or “last few days.” What the buyer usually gets is nothing. Within a few weeks of “cashing in,” the cloned online store goes offline.
"The difference between reporting it within a day and reporting it a week later is the difference between ten and a hundred affected customers mentioning your name."
The tricky thing about this type of fraud is that you end up bearing the brunt of the damage, even though the problem lies outside your systems. Your online store hasn’t been hacked, your data hasn’t been leaked, and your platform is working just fine.
That’s why early detection is valuable. There are a few warning signs that almost always appear before the issue reaches your customer service team:
- Customers who contact you about orders or order confirmations that aren’t in your system. This is the clearest sign—and usually the first one.
- Brand mentions in places where you don’t advertise yourself. Set up a Google Alert for your brand name and common variations that include hyphens, additional words like “outlet” or “sale,” and alternative domain extensions such as .shop, .store, or .online.
- Ads featuring your name or logo in Meta’s ad library. That library is public and searchable by brand name. A weekly check is all it takes.
Notice and takedown: the approach that works
There is a standardized procedure for taking down a fraudulent online store: “notice and takedown.” The idea behind this is that you don’t have to go to court right away, but instead contact the parties that provide the technical infrastructure for the site. These parties also have a vested interest in preventing fraud and, in practice, often cooperate.
The procedure follows a fixed escalation process. Anyone who goes straight to the final party will be sent back to the first step.
For .nl domains, the process looks like this: first the website administrator, then the domain holder via the administrative contact, next the hosting provider or reseller, followed by the registrar via the abuse email address, and only as a last resort, SIDN, the administrator of the .nl domain. For foreign domain extensions, the process goes through the relevant registry, but the principle is the same.
What you’ll need:
- Evidence, recorded on [date]
Take screenshots of every relevant page of the fake site, including the URL and a visible date. Sites are often modified or moved within days, and without documentation, you’ll be left empty-handed. Also document the ads. - WHOIS data
Search to find out who registered the domain, with which registrar, and which hosting provider the site is hosted by. This information will help you determine who to contact. - A legal basis
In most cases, this involves trademark infringement, along with copyright infringement regarding your product photos and text. A registered trademark significantly strengthens your position, because web hosts and registrars can then verify a specific right rather than having to weigh a claim. - File a police report at
. This isn’t just for criminal proceedings. A case number lends your report demonstrable weight when dealing with intermediaries. Additionally, report the incident to the Fraud Help Desk and, if your company’s personal data is being misused, to the Central Identity Fraud Reporting Center. - Reporting to advertising platforms
This is a separate track that runs parallel to the domain route and often yields faster results. Meta and Google have their own procedures for brand infringement in ads.
If the amicable approach doesn’t work, the next step is a cease-and-desist letter from a lawyer, and in extreme cases, summary proceedings. In practice, it rarely comes to that with this type of fraud, because web hosts of clearly fraudulent sites have little reason to be uncooperative.
Speed matters. Every day a fake site remains online means more victims who associate your name with scams.
Conclusion and Support
It’s important to realize that this isn’t an attack specifically targeting your company and that the problem is well-known and manageable.
Retailers are equipped to handle these types of reports; in fact, legislation has become stricter toward platforms in recent years, and a well-substantiated takedown notice has a real chance of success. Moreover, being copied is, in a sense, a sign that your brand has value. What matters is that you spot it quickly and know exactly what steps to take.
If you’re facing this issue and would like to discuss the best approach, need help setting up monitoring, or require support in carrying out a notice-and-takedown procedure, we’d be happy to assist you with our experience and expertise.
Related articles
Digital Product Passport (DPP): What Does This Mean for Your Product Data and PIM?
One year after the EAA: not a single major online store is fully accessible