Cloned payment pages imitate the checkout, invoice, or account portal of a legitimate organisation. Their purpose is usually to collect card details, passwords, identity documents, or one-time security codes. A convincing design is not evidence that a page is genuine.
Check the address, not only the design
Attackers can copy logos, colours, legal text, and product images. The domain name is more useful. Look for misspellings, extra words, unusual subdomains, or a different ending. HTTPS only means the connection is encrypted; it does not establish that the operator is legitimate.
Treat urgency as a warning signal
Fraudulent invoices often threaten account closure, penalties, delivery failure, or loss of access. Urgency is intended to reduce verification. A legitimate organisation should allow you to confirm the request through a known telephone number or its official application.
Look for inconsistent payment behaviour
- The beneficiary or merchant name does not match the organisation.
- The page requests card details and then asks for a banking security code.
- A supposed refund requires an advance payment.
- Support staff move the conversation to encrypted messaging.
- The payment amount or currency changes unexpectedly.
If you entered information
Contact your bank or card issuer using a trusted number, change affected passwords, revoke active sessions, and retain the original message and URL. Do not continue interacting solely to gather more evidence.
Related investigation / GS-0601Operation Phantom Pay →How this relates to our findings
Reports connected to GS-0601 describe repeated invoice templates and cloned payment flows. Ghost Six records the domain, sending address, timestamps, and corroborating submissions separately so that conclusions can be traced to specific evidence.
Editorial note
This article provides general safety information and is not legal or financial advice. The Ghost Six Editorial Desk publishes without individual bylines to protect contributors.
.png)