
hellostake.com Has 53 Clone Sites — More Than Any Brand We Watch
TL;DR: Our monitoring detected 53 domains impersonating hellostake.com in June 2026 — the highest clone count of any brand we watch. Investment and fintech platforms now attract more spoofed sites than household retail names, because that's where scammers believe the biggest paydays are.
The Number That Stopped Us Cold
Every month we compile clone counts across the 129 brands our system monitors. We expected the usual suspects to top the list — the big supermarkets, Apple, maybe a major bank. Instead, June 2026's leader was hellostake.com, the Australian share-trading platform, with 53 detected clones.
For context: target.com.au had 43 clones. apple.com had 42. hesta.com.au had 35. Stake sat above all of them.
That isn't a fluke. It's a signal about where scammers think the money is — and it has real consequences for anyone who trades shares or manages investments online.
Why the Reported Count Is Lower Than You'd Expect
Of those 53 detected Stake clones, only 28 were reported onward to takedown services. That gap — 25 unactioned detections — is worth explaining, because it's not negligence.
Our clone-watch pipeline has several stages: detected means we found a domain with a lexical brand match when it was newly registered. From there, we keep it under monitoring. A domain only moves to reported when we can submit it with evidence that it's actively serving harmful content. Takedown services require that evidence — a parked page with no live phishing kit attached will almost always be declined.
In June 2026 across all 129 brands, 535 detections were declined for exactly that reason. That's the most common outcome in the entire pipeline — more than detections (310), more than weaponised (25), more than taken-down (12). The system isn't broken; it reflects a real constraint in how abuse-reporting infrastructure works globally.
The practical upshot: many Stake clones are sitting parked right now, waiting for their operators to activate them. They'll look legitimate when they go live — because they were built that way from the start.
Investment Platforms Are the New Prime Target
Stake isn't alone. Look at the fintech column in June's data:
- revolut.com: 19 detected clones, 11 reported — and crucially, 4 domains confirmed weaponised within the month: revolut6.vip, bank-onboarding-onerevolutapp-webtradeplatform.com, getrevolution.shop, and revolut8.cc.
- moula.com.au (a business lender): 16 detected clones, 12 reported.
The Revolut weaponised domains are a masterclass in naming tactics. revolut6.vip uses a number suffix to look like a versioned app portal. bank-onboarding-onerevolutapp-webtradeplatform.com is deliberately long and bureaucratic — the kind of URL a nervous customer might assume is a legitimate onboarding system. getrevolution.shop mimics a promotional landing page. revolut8.cc looks like an app shortlink.
Each tactic is designed to pass a quick visual inspection. None passes a careful one.
Why Investment Platforms Attract This Volume
Three reasons converge:
1. High account balances. A successful phish on a share-trading account can yield thousands of dollars in a single session — far more than a retail gift card scam.
2. Infrequent login patterns. Many investors log in to check portfolios once a week or less. An account-takeover can go undetected longer than a daily-use banking app.
3. Unfamiliarity with legitimate communications. Newer investors may not know exactly what a genuine Stake or Revolut email looks like, making spoofed messages easier to believe.
Our Reddit cohort of 994 posts from June 2026 recorded 32 investment_fraud reports — consistent with the clone-watch signal. The dominant tactic across all scam categories in that cohort was fake_legitimacy (764 counts), followed by urgency_window (428 counts). Both are textbook investment-clone techniques: the site looks real, and the message says your account is at risk right now.
How to Verify You're on the Real Site
Your Pre-Login Checklist
- Type or use a bookmark — never follow a link from a message, even if the sender looks right
- Check the full domain — hellostake.com, not hellostake-login.shop or hellostake.com.au.support.xyz
- Look for number suffixes — revolut6, revolut8 and similar patterns are red flags
- Check the TLD — .vip, .shop, .cc, .lol, .icu and .cfd are heavily favoured by clone operators; legitimate platforms use .com or .com.au
- Long hyphenated domains are a warning sign — legitimate platforms don't name portals like bank-onboarding-onerevolutapp-webtradeplatform.com
- Enable two-factor authentication on every investment account — it limits damage even if credentials are stolen
- Set up login alerts — most platforms offer email or push notifications for new sign-ins
- If in doubt, go directly to the app — open the official iOS or Android app rather than a browser link
The Bigger Picture: 804 Clones, 12 Taken Down
Across all 129 brands we monitored in June 2026, our system detected 804 total clone domains. Of those, 12 were confirmed taken down. That ratio — 804 detected, 12 removed — isn't a failure of the takedown process so much as a reflection of how the internet's abuse infrastructure is designed. Removal requires evidence of live harm; parked sites don't qualify until they activate.
What it means for you: the environment is more hostile than the public takedown statistics suggest. The sites exist. Many are waiting. The best defence is the one you build before you click anything.
The live counts for all 129 brands, updated as our monitoring runs, are at https://askarthur.au/clone-watch.
Check something suspicious in seconds
Not sure whether a message, link or phone number is legitimate? Paste it into Ask Arthur for a free, instant AI check — no signup, and nothing you paste is stored.
Running scam-prevention for a bank, super fund, telco or digital platform? We help regulated businesses take the "reasonable steps" the Scams Prevention Framework expects. Talk to our team →
Think you've received a scam?
Check it instantly — free, private, no signup.
Check nowStay ahead of scams
Weekly alerts delivered to your inbox every Monday.