An apparently legitimate fashion storefront illustrated how fraudulent retail sites can combine search visibility, convincing localisation and shared payment infrastructure to defraud online shoppers.
Original investigation date: 14 February 2024
Article type: Security investigation
During this investigation I examined the domain flylondonnederlands.com, which appeared to impersonate the Fly London brand and offer products to Dutch-speaking customers.
At the time of the investigation, several characteristics made the site particularly concerning:
it presented itself as a functioning retail site;
it could process or attempt payment transactions;
it appeared prominently in relevant search results;
it used Dutch-language content;
it shared technical characteristics with other fraudulent retail sites I had investigated; and
the underlying payment layer appeared to be separate from the visible storefront.
The broader lesson is that a fraudulent retail site should be investigated as infrastructure, not only as a webpage.
The site was discoverable through ordinary web search for the relevant brand.
That is important because it changes the victim's starting assumption. A person searching for a known product is not necessarily in a suspicious state of mind. If a convincing fake appears near the top of the results, the user may reasonably believe they have found an authorised local storefront.
Search visibility therefore becomes part of the attack chain.
The site was localised for a Dutch-speaking audience and reproduced the familiar mechanics of online retail.
A fraudulent storefront does not need to be technically perfect. It needs to be credible enough to carry the customer from search result to checkout before doubt interrupts the process.
Useful indicators included:
brand imitation;
local language;
a complete product catalogue appearance;
shopping-cart behaviour;
payment options; and
an apparently normal checkout journey.
One of the most important findings was that the visible retail site appeared to be connected to a separate payment-processing layer.
This is significant because multiple fake storefronts can potentially reuse the same backend services.
From an investigative perspective, that means the storefront domain may be disposable while the underlying infrastructure is more valuable to map.
Questions worth asking include:
Does the payment flow redirect to another domain?
Do several fake stores use the same endpoint?
Are the same scripts or identifiers reused?
Which providers host the payment infrastructure?
Which merchant or acquiring relationships receive the funds?
Following those links can expose a broader campaign.
At the time of the research, the site shared code or infrastructure characteristics with other suspicious retail domains, including a fake Brooks store that I investigated separately.
That similarity suggested that the sites were not necessarily isolated one-off scams.
However, shared code does not automatically prove common ownership. Fraud kits, templates and payment services can be reused by different operators. The right conclusion is that the overlap is an investigative lead.
At the time of the investigation, the site had not necessarily been blocked consistently by reputation services.
That illustrates a recurring weakness in defensive systems: reputation is often retrospective.
A newly registered domain can look legitimate long enough to attract victims before enough reports accumulate to change its reputation score.
For high-risk transactions, users and organisations therefore need controls that do not depend only on whether a domain appears on a blacklist.
A brand-impersonation response process should include:
monitoring for domains that imitate the brand name;
monitoring search results for fraudulent storefronts;
preserving screenshots, DNS information and payment evidence;
reporting the domain to the registrar and hosting provider;
reporting associated payment infrastructure;
notifying search platforms where appropriate;
warning customers through official channels; and
checking whether the same infrastructure supports additional fake stores.
The objective should be both takedown and discovery. Removing one domain is useful; identifying the wider network is better.
Before buying from an unfamiliar local version of a known brand:
compare the domain with the brand's official website;
check whether the retailer is listed as authorised;
be suspicious of unusually large discounts;
look for credible company and contact information;
do not assume a high search position means the seller has been verified; and
use payment methods that provide appropriate consumer protection and dispute options.
The original investigation contained several useful technical observations, but it is important to keep the analytical categories separate:
Observed: a suspicious storefront, functioning payment behaviour, search visibility and infrastructure overlap.
Inferred: the site was likely part of a broader fraudulent retail ecosystem.
Unknown: the definitive identity and location of the operators.
That distinction makes the investigation more reliable and easier for another analyst to reproduce.
The flylondonnederlands.com case was not interesting because the page itself was unusually advanced. It was interesting because the entire commercial experience looked plausible enough to move a customer toward payment.
The key defensive lesson is therefore:
Do not investigate fake shops as isolated webpages. Follow the domain, hosting, code reuse, email, search visibility and payment infrastructure as one attack system.
That is where the larger pattern usually becomes visible.