How Our Company Details Ended Up on a Fake Website

How Our Company Details Ended Up on a Fake Website

8 min read
Jorg

Jorg

Founder & CEO

What happens when a fake website uses your real company details? We experienced it ourselves. Here’s how it can affect customers, search engines and AI, and what businesses can do about it.

A professional-looking website, a registered company name, a real address and a valid Chamber of Commerce number.

At first glance, those sound like pretty good signs that you are dealing with a legitimate business.

Unfortunately, they aren't.

We learned that firsthand when we discovered that a website we had nothing to do with was using our registered company information. Someone had taken legitimate business details and placed them on another website, creating the impression that our company was behind it.

The consequences go further than misleading a few visitors. Search engines index websites. Security services analyse them. AI assistants increasingly search the web and combine information from different sources to answer questions.

That creates a new problem: false information doesn't necessarily stay on the fake website.

It can become part of how machines understand your company.

We Found Our Company Details on a Website That Wasn't Ours

Discovering a fake website is one thing. Discovering your own company information on it feels very different.

The website was using registered details belonging to our company despite having no affiliation with RubberDucky or Orange Branding. To a visitor, those details could make the website appear much more trustworthy than it actually was.

That is exactly why legitimate company information is valuable to malicious operators.

People have learned to look for signs of credibility before buying online. They check whether there is an address, company name, Chamber of Commerce registration or other legal information somewhere in the footer or contact page. Adding real information from an existing company gives a fraudulent website an instant layer of credibility.

The frustrating part is that someone doing a basic background check might actually find confirmation.

The company exists. The registration exists. The address may exist.

The false part is the relationship between that company and the website.

That distinction becomes increasingly important because visitors are no longer the only ones trying to understand who is behind a website.

Machines are doing it too.

AI Search Can Repeat a Relationship That Doesn't Exist

Search is changing.

People increasingly ask AI assistants questions they previously typed into a traditional search engine. Instead of opening ten results and comparing them manually, they ask a system to do part of that research for them.

That is convenient, but it creates an interesting problem when information on the web is wrong.

Imagine that a fraudulent website repeatedly mentions the name, address and registration details of a legitimate company. Search engines may discover those pages, while AI-powered search systems can encounter the same information when retrieving sources from the web.

A machine then has to determine how those entities relate to each other.

If it gets that relationship wrong, an AI-generated answer can potentially associate the suspicious domain with the legitimate company. A user may never even visit the original website where the false claim appeared.

This doesn't mean every AI system will automatically believe whatever is written on a website. Different systems use different retrieval, ranking and verification mechanisms.

But it exposes an important new reputation problem.

You are no longer correcting misinformation only for humans.

You may also need to create enough clear, authoritative evidence for machines to understand that Website X does not belong to Company Y.

Real Company Details Can Make a Fake Website More Convincing

A Chamber of Commerce registration is useful because it allows you to verify that a business exists. What it cannot prove by itself is that the website currently displaying that registration actually belongs to that business.

Company names, addresses and registration numbers can often be found through public sources. Someone copying those details doesn't need to change them or create a sophisticated forgery.

They can simply use the truth in the wrong context.

Imagine finding an unfamiliar webshop. You become suspicious, scroll to the bottom and find a company name and KvK number. You search the number and discover a genuine Dutch business with matching details.

Everything appears to check out.

Except you have only established that the company exists. You haven't established a relationship between that company and the domain you are visiting.

This is why verification should involve multiple independent signals.

Does the legitimate company's own website mention the domain? Do its official contact details correspond with those shown on the website? Does the email address make sense? Can you independently connect the organisation, brand and domain?

The better question isn't simply "Is this company real?"

It is "Does this website actually belong to that company?"

Those are two very different checks.

What a Fake Website Can Do to a Real Company

When someone steals your company identity, the obvious problem is that customers may lose money.

For the company being impersonated, however, the damage can continue long after the fraudulent website disappears.

Customers may contact the real company asking where their order is. Negative reviews can appear against the legitimate business. Banks, payment providers or other organisations may receive complaints containing the real company's details. Search engines can discover pages connecting the company name to the suspicious domain, while AI assistants may encounter the same association.

Then there is the time involved.

Instead of running your business, you are collecting evidence, contacting organisations, answering worried customers, filing reports and explaining repeatedly that a website using your own company information has nothing to do with you.

There is also something unusually difficult about reputational damage online: proving a negative.

You have to demonstrate that you don't own a domain, didn't sell a product and aren't responsible for transactions carried out by someone else.

That is why responding publicly can matter. A clear statement on your real website creates an authoritative source explaining the situation to customers, search engines and systems using information from the web.

Silence leaves the fraudulent version of the story uncontested.

Fake Websites Don't Always Look Fake Anymore

We have all been taught the classic warning signs: terrible spelling, broken layouts, strange URLs and offers that are obviously too good to be true.

Those signals are still useful, but they are becoming less reliable.

A modern fraudulent website can have excellent English, a polished logo, realistic product photography, legal pages, customer reviews and a clean checkout. AI makes generating convincing copy and imagery easier, while modern website builders and e-commerce templates make professional design accessible to almost anyone.

That changes how we should evaluate trust online.

Instead of asking whether a website looks legitimate, look for consistency between independent sources.

Check whether the domain is associated with the company through its official channels. Compare contact details. Be cautious when payment instructions or email addresses don't match the organisation's identity. Search for the company separately instead of relying exclusively on links provided by the website you are investigating.

None of these checks is perfect on its own.

The important part is accumulation.

Trust should come from multiple independent signals pointing toward the same organisation, not from a professional design and a company number printed in the footer.

What You Can Do When Your Company Identity Is Stolen

The first step is evidence.

Take screenshots, save URLs, record dates and preserve the pages where your company name, registration details, copyrighted material or other identifying information appear. A fraudulent website can change quickly after reports start arriving.

After that, there isn't one universal "remove this website" button. Different organisations deal with different parts of the problem, so reporting through several relevant channels may be necessary.

For a Dutch company, useful places to investigate include:

  • Dutch Police: if you believe fraud or another criminal offence has taken place, start with politie.nl.
  • Google Safe Browsing: suspicious phishing pages can be reported through Google's phishing report.
  • Netcraft: Netcraft accepts reports of phishing and other malicious websites through its Report an Incident service.
  • KVK: when your registered company information is being misused, contact the KVK to determine what reporting or assistance is applicable.
  • Cloudflare: if Cloudflare services are involved, its Abuse Reporting system provides categories for reporting abuse. Cloudflare may be an intermediary rather than the website's hosting provider, so a report does not necessarily mean Cloudflare can remove the underlying site.
  • RViG: identity-related misuse may also make the Rijksdienst voor Identiteitsgegevens relevant, depending on exactly which personal or identity information has been abused.
  • BREIN: where copyright infringement involving protected entertainment or media is involved, Stichting BREIN may be relevant.
  • BumaStemra: if copyrighted music or repertoire represented by BumaStemra is involved, information and contact options are available through BumaStemra.

Which organisations are relevant depends entirely on what has been copied and what the website is doing. Trademark infringement, copyright infringement, identity misuse, phishing and payment fraud are different issues and may require different reporting routes.

Just as importantly, publish a clear warning through channels you control. State which domain is fraudulent, which domains are genuinely yours, and that there is no affiliation.

That warning isn't only for customers.

It also puts an authoritative version of the facts back onto the web.

Jorg's 2 Cents

The part I hadn't really considered before this happened was that we weren't only dealing with a fake website.

We were dealing with a fake relationship between two things on the internet.

Our company was real. Our company details were real. The other domain was real. The connection between them wasn't.

And that's becoming an interesting problem in an internet increasingly interpreted by machines.

If an AI assistant does the research for someone and confidently connects the wrong website to your company, the user might never see the clues that would have made them suspicious. They simply receive an answer.

That makes protecting your identity online about more than removing copied content.

Companies increasingly need to make their own digital identity unmistakably clear: these are our domains, these are our channels, and these are the places where information about us can be verified.

Because when someone puts your real information in the wrong place, being real is no longer enough.

The relationship has to be verifiable too.

More Articles.

Let's Build
your legacy

Start

Articles.