Skip to content
All articlesIndustry News

Fake Car Dealership Websites: What to Do If Yours Is Cloned

Scammers are cloning real dealership websites, often with AI. How to find a copy of yours, who to report it to, and how to prepare your staff.

The AutoDealer.io Team October 6, 2026 Updated October 6, 2026 14 min read

A scammer doesn't have to hack your dealership to pretend to be it. They register a domain that looks like yours, copy your logo, your photos and your listings, and put up a site that takes deposits for cars the buyer will never see.

On September 1, 2026, the Federal Trade Commission published a consumer alert, Scammers are spoofing car dealership websites. It describes buyers who pay up front, arrive at the real dealership, and learn the store has no record of the order, the payment or the car.

The alert is written for shoppers. This article is for the dealer on the other side of it: the store whose name is on the fake site.

What the FTC says is happening

According to the alert, scammers:

  • Clone a real dealer's website, often using AI, copying brand logos, vehicle listings and photos "down to the last detail." Some of the fake sites add invented customer testimonials.
  • Advertise rare muscle cars or hard-to-find classics to draw buyers in.
  • Describe the buying process in detail and offer flexible return policies, so the buyer relaxes.

Then they ask for money up front. The FTC tells shoppers to walk away from any dealer that insists on an upfront payment by wire transfer only.

Impersonating dealers is not new. An FTC spokesperson told the Detroit Free Press that the agency has had these reports for some time and believes AI has made it easier to spin up a fake dealer site quickly. The same column reported that the fake sites so far appear to focus on used car dealerships, including stores that sell classic and collector cars.

How much money is involved

Enough to matter to the buyer, and to the store whose name was used.

  • The FTC spokesperson said the owner of an Indiana dealership told a law enforcement partner that consumers had lost more than $70,000 to a fake website impersonating his business.
  • In April 2026, Automotive News reported on the same pattern. Frank McKenna, chief strategist at the fraud-prevention firm Point Predictive, said the fake dealerships offer a 14-day buyback guarantee to build trust, and that victims typically lose $50,000 to $100,000.
  • In August 2026, the Better Business Bureau warned about a site that appeared to impersonate Todd's Toys, a longtime dealership in Hixson, Tennessee. As WDEF reported, the fake site listed a different phone number from the real business, and its vehicle photos matched cars a dealership in Dothan, Alabama had already sold. The dealership's name had been digitally added to the photos.

That last case is worth a second look. The scammers borrowed one dealer's name and a different dealer's photos. Your pictures can end up on a fake site that carries somebody else's name.

Does a cloned website mean you were hacked?

No, not by itself.

Your logo, address, phone number, photos, prices and vehicle descriptions are public on purpose. Anyone can copy them without touching your DMS, your CRM, your website login or your customer records.

Treat these as two different problems:

  • Compromise: someone got into your real website or systems.
  • Impersonation: someone built a separate site that looks like yours.

You can be impersonated without any breach. Still, take ten minutes to rule out the first one. Check that your real site, your domain settings and your Google Business Profile show what you expect, and that nobody has added a user, a redirect or a new phone number.

Why it becomes the real dealer's problem

The buyer loses the money. The dealer gets what comes after:

  • A victim at the counter or on the phone, asking where the car is
  • One-star reviews and fraud complaints filed against the real store
  • Your photos and listings used to sell cars you never offered
  • Employees' names used in emails and texts they never sent
  • Hours spent with victims, platforms and investigators

None of that requires the dealer to have done anything wrong.

How to find a copy of your website

Search for yourself the way a shopper would. Once a month is reasonable, and more often if you sell classics, collector cars or anything else that ships.

  • Your dealership name in quotes, alone and with "inventory" or "cars"
  • Your phone number and your street address
  • A distinctive sentence from your About page or a vehicle description, in quotes
  • A reverse image search on a few of your own vehicle photos
  • Your name on Facebook, Instagram and TikTok, plus the sponsored results above a Google search for it

Look closely at any domain that resembles yours. The usual tricks are an added word ("auto," "motors," "sales," your state), a dropped or swapped letter, or a different ending such as .net or .co in place of .com. This is called a lookalike domain, or typosquatting.

Two more signals cost nothing. Ask staff to mention any call about a car you don't stock or a deposit you never took. And when a caller says "I saw it on your website," ask for the address they were on.

What to do if someone cloned your dealership website

Move quickly, in this order.

1. Save the evidence first

A fake site can change or vanish within hours. Before you report anything, capture:

  • The full web address of every page you can find
  • Screenshots of the home page, the copied listings and the contact page
  • The phone numbers, email addresses and payment instructions on the site
  • Social profiles and ads that point to it
  • Anything a victim sends you: emails, texts, receipts, wire details

Note the date and time on each item. Keep your own originals too, the listing and photos as they appear on your site, so you can show which came first.

2. Report the domain to its registrar and its web host

Look the domain up at lookup.icann.org. The result names the registrar, the company the domain was registered through, and its abuse contact.

ICANN, which oversees domain registrars, counts phishing as DNS Abuse, and its definition of phishing includes luring people to copycat websites. Since April 5, 2024, a registrar with actionable evidence that a domain is being used this way has to act promptly to stop or disrupt it. ICANN's advisory also requires registrars to publish an abuse email address or a web form that needs no login, and to confirm they received your report.

Send:

  • The fraudulent address
  • Your real address, and proof the business is yours
  • Side-by-side screenshots of the copied branding and listings
  • Evidence that the site is collecting money or personal information

If a reasonable time passes and the registrar has done nothing, you can file a complaint with ICANN.

Two limits to know about. These duties cover generic endings such as .com and .net, and country-code domains follow their own rules. And ICANN does not police website content, so a registrar may decide a clone is a content problem and send you to the hosting company. Report to the host as well. It can take the site down even when the domain stays registered.

3. Report it to the FTC

File at ReportFraud.ftc.gov and keep the confirmation with your incident notes.

Posing as a business is itself against federal rules. The FTC's rule on impersonation of government and businesses (16 CFR Part 461) took effect on April 1, 2024, and the FTC's commentary on it lists a website that copies a business's name or logo, or uses a near-miss domain, among its examples. Only the FTC can enforce that rule, so your report is the way it gets used.

4. Report it to the FBI's Internet Crime Complaint Center

The IC3 is the FBI's intake point for cyber-enabled crime. It asks people to file even when they aren't sure the complaint qualifies, and it says plainly that it can't respond to every report. Have the web addresses, email addresses, phone numbers and any payment details ready.

If a victim has already wired money, tell them to call their bank right away and then file their own complaint. The FTC spokesperson told the Free Press that a wire transfer is nearly impossible to get back once it's sent, so every hour counts.

5. Report it to Google

Google's help page on reporting a problem with Search links to a form for reporting a phishing page, and to a separate process for a phishing site that shows up as a sponsored result. A report can cut the fake site's reach while the registrar and host work through theirs.

6. Report it on every platform that shows it

That may mean Facebook, Instagram, TikTok, a vehicle marketplace, a classifieds site or a business directory. Report the account or the listing through the platform's own tools and include a link to your original listing. The Tennessee case reportedly started with ads on TikTok.

7. Talk to your attorney about the domain itself

If your dealership name is a trademark, registered or established through use, the Uniform Domain-Name Dispute-Resolution Policy gives trademark owners a way to have a domain registered in bad faith cancelled or transferred. It takes longer than an abuse report, and whether it fits is a question for counsel.

8. Warn your customers and brief your staff

Put a short notice on your real website and your social pages. Name your one official web address, and say how you do and don't take deposits.

Then give the people who answer the phone a simple script. They should know:

  • Your official domain, and that you have no other
  • How to check whether a vehicle is in inventory
  • How to check whether a customer, a lead or a deal exists
  • Who handles fraud calls, and how to reach that person
  • What to collect from a caller: the web address, screenshots, payment details

They shouldn't guess, argue or promise a refund. Their job is to find out whether the transaction ever touched your dealership, and to hand it to the right person if it didn't.

Protect the domain you actually control

A clone isn't a breach, but it is a good day to check your own locks:

  • A strong, unique password on the registrar account, with multi-factor authentication
  • A registrar lock. ICANN notes that a domain can be locked to protect against unauthorized changes, a status often shown as "Client Transfer Prohibited."
  • Auto-renewal turned on, with a card that won't expire next month
  • Recovery email and phone numbers that belong to the business, not to a former employee
  • As few administrators as possible, and old accounts removed

Consider registering the obvious variants of your name yourself. The .net and .co endings and the hyphenated version cost little to hold each year. You won't cover every variant, but you can take the easiest ones off the table.

Don't forget email

A lookalike domain can send mail too. An address such as sales@ or finance@ on a domain one letter away from yours is enough to deliver fake wiring instructions.

Ask whoever manages your email to confirm that SPF, DKIM and DMARC are set up for your real domain. Together they let a receiving mail server tell whether a message that claims to be from your domain was authorized. They do nothing about a different domain that only resembles yours, which is why the monitoring above still matters.

What to tell your customers

These scams depend on a buyer who completes everything remotely. You can make that harder without scaring anyone off:

  • State your official web address on your Google Business Profile, your social pages and your paperwork.
  • Tell remote buyers they're welcome to send a mobile inspector or to see the car in person. The FTC tells shoppers to be wary of any dealer who refuses either.
  • Put your payment policy in writing. If you never take a deposit by wire, say so.
  • Ask buyers to confirm any change in payment instructions by calling a number they found on their own, not one from an email.

Where AutoDealer.io fits

No software can stop someone from copying what your website shows the public. AutoDealer.io can't either, and anyone who tells you their product can is overselling it.

The platform helps with the other half of the problem, your real systems and your real records. Its data security covers database-level isolation between dealerships, encryption for the most sensitive fields (the dealership's EIN and customers' dates of birth and driver's license numbers), optional two-factor sign-in with an authenticator app, four staff roles, and an audit log on every meaningful change. Our guide to what the law requires for dealer data security covers the rules behind those controls.

It also helps on the day a victim calls. On a dealer management system where inventory, leads, deals and your website share one set of records, your staff can answer the questions that settle it in a few minutes:

  • Is this vehicle in our inventory, and was it ever?
  • Is that the price we published?
  • Did this person send us a lead?
  • Does this deal exist?
  • Who changed the record, and when?

A fast, confident "that didn't come from us" keeps the first phone call from turning into a dispute.

Frequently asked questions

Can scammers copy my dealership website without hacking it?

Yes. Logos, photos, listings, prices and contact details are public, so a scammer can publish them on another domain without ever getting into your real site or systems.

What should I do first if someone copies my dealership website?

Save the evidence: every web address, screenshots, contact details and payment instructions, with the date and time. Then report the domain to its registrar and web host, and file reports with the FTC, the FBI's IC3, Google and any platform showing the fake site.

Are scammers really using AI to clone dealership websites?

The FTC says so. Its September 1, 2026 alert says scammers clone a real dealer's website, often using AI, copying logos, listings and photos. An FTC spokesperson has said the agency believes AI made these sites faster to build.

Who can take a fake dealership website down?

The registrar that sold the domain and the company hosting the site. ICANN's rules require registrars to act on well-evidenced phishing on domains such as .com and .net. The FTC and the FBI take reports, but they don't remove websites on request.

Is the real dealership responsible for a customer's losses?

This article can't answer that for your situation. The scammer took the money, not your store, but a victim may still complain, post a review or contact a lawyer. Keep records of what you found and what you reported, and speak with your attorney.

How can customers tell which dealership website is real?

Check the web address letter by letter, then confirm the phone number and street address through a separate source. A dealer who refuses an in-person visit or an independent inspection, or who insists on a wire transfer up front, is a warning sign.

Does AutoDealer.io prevent dealership website cloning?

No. Nothing can stop someone from copying public content. AutoDealer.io protects dealership accounts and stored data, and gives staff one set of records to check whether a vehicle, a customer or a deal is real.

Bottom line: You can't stop a scammer from copying what's public. What's in your hands is how soon you notice, how complete your reports are, and how fast your staff can tell a caller whether a deal was ever yours.

This article is general information, not legal or cybersecurity advice. Talk to qualified legal and security professionals about a specific incident.

Get started

Ready to run your lot from one place?

Start your free trial today. Your website and AI assistants are included. No setup fees, cancel anytime.