Scams to Avoid: Cloned Look-Alike Domains and How to Spot Them

A cloned site is a photocopy of a login page with a different owner. It is cheap to make and it works because people read logos, not addresses. ME777 is an independent guide, not a casino. It takes no deposits, runs no games and has no login or cashier to clone. For readers 21+.

What a cloned domain is

Someone copies the design of a casino's site, places it on an address that looks nearly the same, and waits. Visitors who log in hand over their username and password. Visitors who deposit send money to the cloner. Some clones show a working lobby with a fake balance to keep the victim depositing.

How look-alike addresses are built

TechniqueIllustrative patternHow to catch it
Swapped or dropped characterA zero for the letter o, a doubled letter removedRead the address one character at a time
Added wordThe brand plus 'login', 'vip', 'official' or 'ph'Extra words are not proof of anything
Different endingSame name on another extensionThe extension is part of the identity. Check all of it
Subdomain trickThe brand appears at the start, but the real domain is the part just before the first slashLook at the last two segments before the slash
Look-alike lettersCharacters from another alphabet that resemble Latin onesType the address yourself; never paste from a message

The patterns above are described in general terms on purpose. No real addresses are listed, since a list of clones would be out of date within days.

Claims and replies

ClaimWhy it is falseWhat to do
'The padlock means the site is safe'A padlock shows the connection is encrypted. Clones have padlocks tooVerify the domain, not the icon
'This is our backup link'Anyone can call a domain a backup. Legitimacy comes from the licence recordCheck the exact domain on PAGCOR's list
'Old site closed, log in here to keep your balance'A balance does not move to a domain sent by messageLog in only at the address you typed and verified
'First result on the search page, so it must be official'The top results are often paid adverts that anyone can buyScroll past adverts or type the address directly
'Scan this QR to go to the cashier'A QR code is just a link you cannot readCheck the address it opens before entering anything

A five-step address check

  1. Type the address by hand the first time.
  2. Compare it, character by character, with PAGCOR's published list on the regulator's own site.
  3. Bookmark it, and use only the bookmark afterwards.
  4. Let a password manager fill the login. If it does not offer to, the domain is not the one you saved.
  5. At the cashier, confirm the address has not changed and that the payee is a business.

What a real KYC request never asks for

Clones often add a 'verification' page to harvest more than a password. A licensed operator's KYC takes an ID and a selfie through an upload page inside your account. It never asks for your e-wallet MPIN, a one-time code, online banking credentials, a card security code or a fee to verify, and it never asks you to send documents to a chat account.

  • Fake apps. The clone offers an install file. Now the copy lives on your phone with whatever permissions it requested.
  • Paid search adverts. An ad with the brand's name leads to the clone, sitting above the real result.
  • Fake support. A helpline number on the clone connects to the cloner, who asks for codes.
  • Withdrawal fees. The clone's fake balance can be 'released' for a payment, and then another.

Reporting route

  1. Tell the real operator through support on its verified domain, and change your password there.
  2. If you paid, report the transaction through your e-wallet's in-app helpline. Use Help inside the app, never a number someone sent you or one printed on the clone.
  3. PAGCOR publishes a complaint channel on its website, which is also a place to report sites misusing a licensee's name.
  4. For fraud, report to the PNP Anti-Cybercrime Group or the NBI Cybercrime Division with the clone's address, screenshots and payment references.

No hotline numbers are given here, because numbers change and fake ones circulate. Use the contacts on each official website.

If you logged in to a clone

  • Change the password on the genuine site at once, and anywhere else you used the same one.
  • Turn on two-factor authentication if the operator offers it.
  • Check your real account for withdrawals or changed payout details.
  • If you entered wallet details or a code, change your MPIN and report through the wallet app.
  • Remove any app the clone had you install.

About this site's own name

Brand names like the one on this guide appear on many unrelated domains. That is exactly why the check must be on the address, not the name. ME777 here is a reading site. It will never ask you to log in, deposit or verify.

Frequently Asked Questions

How do I know which domain is the real one?

By the licence record, not by appearance. Find the exact domain on PAGCOR's published list, on the regulator's own website.

Does a padlock or https mean a site is genuine?

No. It only means the connection is encrypted. Cloned sites use it as well.

Is this ME777 site a casino login?

No. It is an independent guide with no accounts or payments.

I typed my password into a fake site. Is my money gone?

Not necessarily. Change the password on the real site immediately and check for unauthorised withdrawals.

Can clones be taken down?

They can be reported and often are removed, but new ones appear quickly. Your own address check is the reliable defence.

Why not publish a list of fake domains?

It would be incomplete and outdated at once, and could imply that unlisted addresses are safe.

Before You Choose an Operator

Compare PAGCOR-licensed operators, read the bonus terms and set a budget before you deposit.

Continue Exploring