Scams to Avoid: Clone Domains and Look-alike Sites
A clone domain is the quietest scam in this market, because nothing looks wrong. The logo is right, the games load, the cashier accepts your deposit — and the company behind it is not the one you thought you were dealing with. 100JILI is an independent guide with no cashier, no lobby and no games, which means we have nothing to sell and no balance to release. Below: how clones work, four scams that attach to them, what genuine verification never asks for, and where to take a complaint. 21+.
How a clone domain works
Someone registers an address a character or two away from a real one — a hyphen inserted, a doubled letter, the digit 1 standing in for a lower-case l, the digit 0 for an o, or a different extension entirely. Then they copy the real site's appearance, which is trivial, and buy traffic to it through search ads, social posts and forwarded links.
From there the clone makes money two ways. It collects the login you type, which is often reused on your e-wallet or email, and it takes deposits into accounts that have nothing to do with the operator. Winnings exist on screen and never leave, because there is no cashier behind the number.
The reason clones persist is that the victim does not know which site they were on. People remember a brand name, not a string of characters, and the whole design of the attack is that the two feel identical.
Where people land on one
- A paid search result above the real one, using the brand's logo and colours
- A forwarded link in a chat group, often described as the "new" or "VIP" address
- A comment under a social post about a stuck withdrawal
- A QR code, which hides the destination until you are already there
- A "maintenance" or "server migration" notice telling you to move to a new domain today
Two habits remove nearly all of this exposure. Type the address yourself, or use a bookmark you created yourself from an address you typed — and never navigate to a cashier from a link somebody handed you.
Four that travel with clones
- The release fee. Your withdrawal is "held" pending a clearance charge, tax or unlock payment. A real operator deducts from a balance and never needs money sent in to send money out.
- OTP and password phishing. A chat or caller needs "just the code". That code authorises a transaction, and the transaction will not be yours.
- Fake agents on Telegram and Facebook, offering to escalate your payout or grant VIP access. Operators do not run cashier business through social profiles.
- Predictor and hack apps, sold as a way to recover losses. Results are generated server-side; the app's real output is the permissions it collects.
Claim, reality, response
| What you are told | Why it is false | What to do |
|---|---|---|
| "We have migrated, use this new address" | Look-alike domains exist to collect logins; migration notices are the standard pretext | Type the address you already know, letter by letter, and verify with support inside your account |
| "This is the official mirror for faster access" | Mirrors are indistinguishable from clones from the outside | Use one address only — the one you typed and bookmarked yourself |
| "Pay the release fee and the withdrawal clears" | No cashier requires an inbound payment to send an outbound one | Pay nothing; raise a written ticket with the operator and keep every screenshot |
| "Give me the OTP to verify your account" | A one-time code exists so that nobody else can act for you | Never share it; if you already did, use your e-wallet's own in-app help immediately |
| "I am your VIP agent, here is my link" | A logo and a display name cost nothing to copy | Use only the support channel inside your logged-in account |
| "This app predicts the next result" | Outcomes come from the operator's servers, not your handset | Uninstall it and revoke every permission it was granted |
How to check the address you are on
- Read the domain character by character, out loud if necessary. Clones rely on you skimming.
- Check the extension as well as the name. The same word with a different ending is a different company.
- Open the terms and look for the operating company name, then check it against PAGCOR's published records from pagcor.ph typed into the bar.
- Distrust any address you arrived at by clicking, including from a search advertisement.
- Once you are satisfied, bookmark it yourself and use the bookmark from then on.
- Treat a padlock as meaningless for this purpose. Encryption says the connection is private, not that the company is who it claims.
What real verification never asks
KYC is normal. Licensed operators ask for identity documents, usually before a first withdrawal, because they are required to. The difference between that and a scam is documents versus secrets.
- Never a one-time password, PIN, MPIN or account password
- Never a transfer from you to "test" or "activate" the account
- Never remote access or a screen-sharing session
- Never ID photographs sent to a personal chat account instead of the site's own upload form
- Never a full card number with CVV typed into a chat
And the direction is as important as the content: verification starts from inside your logged-in account on a site you navigated to yourself. A request that arrives by DM, call or SMS link has begun at the wrong end.
Escalation route
- The operator's own support, in writing, with amounts, dates and transaction references. Keep every reply — the later steps depend on that record.
- Your e-wallet or bank, through its own app. Open GCash, Maya or your banking app and use the in-app help you navigated to yourself, never a number someone sent you.
- PAGCOR's published players' concerns channel, reached from pagcor.ph typed into the address bar, with your ticket reference to hand.
- The PNP Anti-Cybercrime Group or the NBI Cybercrime Division for phishing, impersonation and theft; both publish current reporting channels on their official government sites.
No hotline digits appear on this page by design. Numbers change, and a stale number in a guide is the opening a fake helpline uses. The channel names are stable; look up the current details on the official source each time. This site is an independent guide for adults 21 and over — it takes no deposits, runs no games and cannot release a balance. If chasing a loss brought you here, the responsible-gaming page is the relevant one.
Frequently Asked Questions
I think I logged into a clone. What should I do first?
Change that password immediately, and change it anywhere else you reused it — e-wallet and email first. Then check for unfamiliar devices or sessions on those accounts, report it through your e-wallet's own in-app help, and open a written ticket with the real operator.
Does the padlock icon mean a site is genuine?
No. It means the connection is encrypted, which any site can arrange for free, including a clone. It says nothing about who operates the domain.
Are official mirror sites a real thing?
From the outside you cannot distinguish a mirror from a clone, and that is reason enough to use one address only — the one you typed and bookmarked yourself. Treat "use our mirror" messages as unverified by default.
How did they get my details?
Usually from the clone login itself, from public complaint posts where people share account information, or from earlier phishing. Knowing your username or the amount you are owed is a sales technique, not proof of identity.
Can you recover money taken by a clone site?
No. We have no cashier, no account access and no relationship with anyone's funds. Report it to your e-wallet through its in-app help and to the PNP Anti-Cybercrime Group, and keep every screenshot you have.
Why does this page not list hotline numbers?
Because an outdated number is worse than none — that gap is what fake helplines exploit. We name the channels and you take the current contact details from the official site.