Skip to content
A hand holds a credit card toward a computer screen showing a fake online bicycle shop checkout, while the card data streams away into darkness

Yep, Somebody Cloned Our Website. Four Times.

How to Spot a Fake

How we found out

A customer went looking for one of our bikes and landed on a website he did not recognize. He put a few things in the cart. Then something felt off, and instead of checking out he sent us the link and asked if it was actually us.

It was not.

Sitting in that cart was a Factor Aluto, Raptor Blue, 56cm. Ours is $6,995. Theirs was $2,448.25. That is exactly 65 percent off, to the cent.

Then we went looking and found three more.

What they took

Our logo. Not a redraw, not a lookalike. The same file, run through a converter and put back on the internet.

A single real bicycle in a workshop in front of rows of flat grey cutouts of the same bicycle
A copy is cheap to make and cheap to spot. What they built was neither a redraw nor a lookalike, it was our own file handed back to us.
The Dialed Cycling Lab logo file we host, exported once and served from our own domain
Ours

The file we host. Exported once at 3104 by 1015 and served from our own domain ever since. We have been using this mark for over a decade and it has not changed.

The same Dialed Cycling Lab logo file re-uploaded to a fraudulent website
Stolen

The same file, on a fake site. Identical dimensions, 3104 by 1015. Just over 93 percent of the pixels match exactly, and the ones that do not are off by an average of 5 shades out of 255. That is the fingerprint of a lossy re-encode, not a recreation.

Nobody redraws a logo and lands on the same 3,104 pixel width by accident.

Then they took everything else. Big chunks of our product database, photos included. The copy off our pages. The blurb that shows up under our name in search results, word for word, brand list and all. There is a file on their homepage named bike-art-at-dialed-600.jpg. We named it that. Nobody else would.

They even grabbed pieces of our layout their build could not handle. Those just sat there broken.

Then they wrote a privacy policy under our business name that we have never seen. And a terms of service to match.

The support address on their site was at our domain. It was not a real mailbox.

So a customer with a problem wrote to something that looked like us, and got a bounce.

We sent one from the lab to be sure. Straight back, undeliverable. Nothing from any of this had ever landed in our actual inboxes.

So somebody who got taken had nowhere to go. They would have to work out on their own that there is a real lab in Vancouver, that it is not the one that charged them, and then come find us the long way around.

We have since pointed that address back at us, so it is a dead end no longer. If you wrote to it and heard nothing, that is why.

They could not be bothered to finish it

Here is where it stops being sinister and starts being sad. Every one of these is a real string we pulled off the live sites.

A warmly lit bicycle shop storefront at dusk revealed from the side to be a propped up flat facade with nothing behind it but an empty lot
Convincing from the one angle a customer ever sees it from, and nothing at all from any other.
{storeName}

Their signup page asks you to create your {storeName} member profile. Nobody filled in the blank. It is sitting there, live, in front of everyone who visits.

john@example.com

Left in the code from whatever kit they built the thing out of. Nobody went back for it.

$$35.00

A shipping price with two dollar signs. Either a typo, or the most honest thing on the entire site.

my go-to for cycling essentials

One of exactly three reviews on the site. All five stars. All describing a long relationship with a shop that was four days old.

The homepage claims 10,000 happy customers across 50 countries. Same four day old domain.

We have been at this since 2015 and we have not sold to 50 countries. They pulled it off over a long weekend.

They are not hackers. They are employees.

Researchers at Security Research Labs in Germany got inside one of these operations and named it BogusBazaar. What they found was not a basement. It was an office.

75,000fake storefronts run by one network
850,000people taken since 2021
$50Min attempted charges

They pulled out employment contracts. Monthly salaries. Training documents. There are people who clock in, spend the day loading stolen catalogs into fake stores, and clock out.

Somebody in there has a manager. Somebody sat through a performance review about how many businesses they copied last quarter.

The whole thing runs like a franchise. A small core team writes the software and keeps the servers up, then rents the kit to operators who each run their own batch of stores. The people who built it barely run any stores themselves. They sell shovels.

Which is why there were four of us. Not four decisions. One machine, running.

The victims were almost entirely in the United States and Western Europe. Almost none were in China, where the operation is based.

They know exactly what they are doing. They just make sure they are not doing it to their neighbors.

How they actually get paid

This is the part that stumped us. Taking card payments is not easy. Anyone who has opened a merchant account remembers the paperwork, the verification, the waiting around. So how does a store that ships nothing survive contact with a bank?

Turns out there are two businesses running at once.

The one that needs no bank at all

A fake checkout page takes your card details and processes nothing. You get an error. There is no merchant account because there was never a transaction. The card number is the product, and it gets sold on.

The second business takes real payments through PayPal, Stripe or a card processor. You get charged. Nothing ships.

The worst version is both, back to back. They grab your card on a page that does not work, show you an error, then hand you to a gateway that does. They get the number and the money.

We know which one came for us

We read the checkout code on all four sites. There is no merchant account behind any of them.

The card form is not a payment company. It is a window onto their own server, and the word Stripe printed on it is a label they typed in themselves. Your card number, the expiry date, the security code and the address you filled in two screens earlier all leave together over a live connection, while you sit there watching a spinner.

The address form matters too. It reads what you type before you ever reach payment. Fill in your name, email, phone and address, think better of it, close the tab, and they already have every bit of that.

Which means a charge that never shows up is not good news. It is the expected outcome.

How the merchant accounts get through the vetting

Three ways, and none of them need the account to last.

Some get opened knowing they will be lost. Process hard for a few weeks, pull the money out, walk away. Getting shut down is the plan, not the failure.

Some traffic runs through somebody else's legitimate account. It is called transaction laundering, and the bank sees a flower shop. Estimates put it north of 350 billion dollars a year in the United States alone.

And identity checks confirm a real person exists. They cannot confirm that person is the one filling out the form. Stolen and made up identities clear the same paperwork the rest of us had to file.

Our catalog was not stolen to fool customers. It was stolen to pass underwriting.

A blank storefront gets a merchant application declined. One with a full catalog, real photography, real copy and real policies gets it approved.

That took a while to sink in. Somebody at a payment processor reviews these applications by pulling up the website and looking at it. Eleven years of product pages, written one at a time, turned into somebody's credentials.

Then it is just a gap in the calendar

Card payments land in the merchant account in two to four business days. Chargebacks show up thirty to a hundred and twenty days later.

That gap is the whole business. Process, withdraw, disappear before the disputes arrive. By the time the bank comes looking, the balance is zero and the company does not exist.

Who actually eats it

Picture our guy going through with it. A Factor at 65 percent off, paid for, then three weeks of watching for a box that is not coming. The support address bounces. Eventually he calls his bank.

The bank refunds him and goes after the merchant to get it back. Except the merchant is a shell with an empty account, so the bank eats it. If the money ran through somebody else's account, that business eats it instead, loses its processing, and lands on a list that makes getting another account very hard.

So most cardholders come out whole eventually. Not everyone, though. Debit and bank transfer usually cannot be recovered. Harvested card numbers turn into fraud months later that nobody ever traces back to a bike website. And anyone who notices past their dispute window is just out.

We are not out any money. We are out the time, and the trust of anybody who ordered from a site with our name on it.

The uncomfortable math

Why a lab in Vancouver

Because the model assumes we are easier than Nike.

Big brands have legal teams whose whole job is finding this and shutting it down. The bet is that a business our size has nobody watching. Same catalog, same photos, same trust built up over years, and in theory a fraction of the defense. Plus there are a lot more of us to choose from.

It works because it costs them almost nothing. A domain costs a few dollars. The site builds itself from a script. No inventory, no warehouse, no shipping, nobody on payroll except whoever is doing the data entry. The entire cost of a fake storefront is the domain name. At that price they do not need to fool many people. They need to fool a few, thousands of times over.

Here is where the bet fell apart.

Our customer flagged the first one. We found the other three ourselves that same afternoon, by fingerprinting that first site and then going hunting for anything stamped out of the same machine. Identical code, identical server software, same host across three different addresses. Once you know what the press looks like, the rest are not hard to find.

1afternoon from first sighting to all four identified
4sites archived with timestamps and file hashes
6channels the reports went out to

By the end of that day every page was captured and hashed, reports were in with the registrar, three payment processors, the network provider and Google, and our email was locked down so nobody can send messages wearing our name.

Small is not the same as easy. We would rather burn an afternoon on forensics than a month on damage control.

What actually bothers us is that plenty of shops have none of this, and they have done nothing to deserve it. They are busy building wheels and taking care of people. A clone can run for months before somebody happens to mention it, and by then it has taken every order it was ever going to take.

That is who this post is really for.

Who actually gets caught by this

Here is the part that surprised us. You probably picture the victim as somebody's grandmother. For this particular scam, it is the other way around.

86%more likely to lose money if you are under 60
2xthe rate for millennials versus over 40
40%of losses at ages 18 to 29 start on social

Those are Federal Trade Commission numbers. For people in their twenties and thirties, fake online stores are the single most common fraud they report. Older adults lose more per incident when it happens, but they are better at spotting it and walking away.

It is not about being gullible. It is about where the traffic comes from. These sites reach people through social ads, and more money was lost to scams that started on Facebook last year than on any other platform.

So it is not the people who are bad with computers. It is the people who spend the most time on their phones, scrolling past an ad for a frame at a price that seems almost possible.

Which is most of us.

Five checks, ten seconds

How to spot a fake, ours or anybody else's

  1. Check the address bar firstThe only check that works every time. We sell online from dialedcyclinglab.com and dialedcycling.com. That is the whole list.
  2. Get suspicious when everything is on saleReal shops discount some things. Fake shops discount the entire building, usually 50 to 80 percent off, because they are not shipping any of it anyway.
  3. Look for a price that cannot legally existMost of what we carry has a floor the manufacturer sets. The Factor in that cart was listed at exactly 65 percent off. Nobody sells one that way. Not us, not anybody.
  4. Try the contact details before you buyOurs are on every page and somebody picks up. On the fake, the support address bounced. A number that rings and an address you can drive to beat any badge on a checkout page.
  5. See if the story holds upGlowing reviews about years of great service, on a website that is a week old. Thousands of happy customers, at a shop nobody in town has heard of. Read the dates, not just the words.

Habits that protect you before checkout

  1. Pay with a credit card, never a debit cardBest habit on this list. A credit card gives you chargeback rights, and until it is sorted out the money is still the bank's. Debit money is yours, and it is already gone while you argue about getting it back.
  2. Use a virtual card number if your bank offers oneMost major issuers do now. It spins up a single use number, so if the site is harvesting card details instead of selling anything, and ours were, what they walk off with is already dead.
  3. Do not shop from the ad. Shop from the address bar.If something catches your eye in a feed, do not tap through. Open a tab, type the shop's name yourself, go there directly. That one habit defeats most of this.
  4. Check how old the domain isA free whois lookup takes twenty seconds. A store claiming a decade of happy customers on a domain registered last month has told you everything you need.
  5. Reverse image search a product photoIf the same shot turns up on forty stores and one of them looks like a real business, you have found the real business.
The part we keep coming back to

Somebody built this on purpose

Not the person importing catalogs all day. That is data entry with a lunch break. But upstream of them, somebody designed a machine that eats a real website and spits out a working store. Payments wired in. Built from the start to survive getting shut down, because getting shut down was always part of the plan.

That is good work. Genuinely. Put it on a resume and somebody hires you Monday.

Which is the part we keep chewing on. You could build that and just sell it. People pay real money for software. There is an entire industry of people doing fine making tools nobody had to steal first.

They pointed it at a lab in Vancouver instead. And a few thousand small businesses like ours, most of which have nothing to do with bikes. To move a couple grand at a time.

Our best guess is they ran the math, same as they ran everything else. This sort of thing crosses borders, which makes it slow and expensive to chase. What comes off any one person is too small for anybody to bother with. A domain costs less than a bottle of chain lube.

Stealing did not pay better than building would have. It was just easier, and nobody was going to stop them. That turned out to be enough.

We would have preferred a better reason.

Why this does not just go away

We reported all four on July 29, 2026. Some will come down. More will show up, and we expect that. Takedowns alone do not fix it, because the franchise model is built to absorb them. Lose a domain, register another one by lunch.

What actually costs these operations money is being found fast.

Their return on any single store depends entirely on how long it stays up before somebody notices.

Which is where you come in, and we are not being cute about that. The first one got found because a customer thought something looked off and said so. Not software. Not us.

What we did about it

  1. Captured everything. All four sites archived page by page, with timestamps and file hashes, before anything could be pulled down or changed.
  2. Reported to the registrar. Where the domains were bought, and the only party that can actually take one away.
  3. Reported to Stripe, PayPal and Klarna. Cutting off the ability to take a payment matters more than cutting off the website.
  4. Reported to the DNS provider and Google. The company answering for the fake addresses, and the search engine that could otherwise send people to them.
  5. Locked down our email. So nobody can send messages that look like they came from us.
  6. Built a page you can always check. Every website and platform that is genuinely ours, plus the fakes we know about.

If you ever see something with our name on it and it feels off, send us the link. We would rather answer ten of those than have one person lose their money. If you find one impersonating another business, tell that business. Most of them have no idea. Neither did we.

Our official websites

And if you put a card into one of these, call your bank today and have it replaced. Not watched, replaced. If you were charged, dispute that too, and do not wait for the package.

It is not coming. Nothing on that site ever was.

Got something to add?

Please note, comments need to be approved before they are published.