Keeping your website and name safe: passwords, fake copies and what to do if it goes wrong

· 7 min read

When you put your name, your phone number and your profession on a public page, you also make yourself something people can copy. Criminals set up fake versions of professionals’ pages to take deposits or collect details, take over accounts with weak passwords, and send emails that look like yours. Most of the protection is simple and free. This guide covers the habits that matter, how to notice a fake, and a plan for the day something goes wrong.

The short answer

  • Make sure your page loads over HTTPS, shown by a padlock and “https://”. A hosted platform should handle the certificate for you.
  • Use a different, long password for every account, kept in a password manager, and turn on two-step sign-in for your email first, because email resets everything else.
  • Search for your own name and page regularly. Fake copies and fake profiles are easier to remove when you spot them early.
  • Tell clients how you will and will not contact them, such as never asking for payment details by message.
  • Have a plan: who to call, what to change first, and where to report a fake.

What can go wrong

Common problems and what causes them
ProblemHow it happensWhat it costs you
Account takeoverA reused or weak password is stolen from another site, or you are tricked into giving it awayYour page, email or profiles are changed or locked
A fake copy of your pageSomeone copies your text and photograph to a similar address and takes deposits or detailsClients are harmed and your name is damaged
Email impersonationA message appears to come from you, or from your bank or supplier, asking for money or login detailsMoney lost, clients misled
Expired or hijacked domainThe renewal fails or the account is compromisedYour site and email disappear, and someone else may register the name
Outdated softwareA plugin, theme or tool you installed is not updatedA hacked page that sends visitors elsewhere
Fake profiles and listingsSomeone creates a profile in your name on a directory or social networkWrong details, or false claims, under your name

1. HTTPS: the padlock

  • HTTPS encrypts what passes between your visitor and your page, and shows a padlock. Browsers warn visitors about pages without it, which looks alarming on a professional site.
  • A hosted platform normally provides and renews the certificate for you. Check that your own page loads with “https://” and no warning.
  • If you manage your own hosting, turn on automatic renewal for the certificate and make sure all addresses redirect to the secure version.
  • HTTPS shows that the connection is encrypted, not that the page is honest. Fake pages can have a padlock too.

2. Passwords and two-step sign-in

  1. Install a reputable password manager and let it create a long, random, different password for every account.
  2. Protect the manager with one strong passphrase that you do not use anywhere else.
  3. Turn on two-step sign-in (also called two-factor or multi-factor authentication) for your email first, then your domain account, your website platform, your bank and your social profiles. An app or a security key is stronger than a text message.
  4. Save the recovery codes somewhere safe and offline.
  5. Make sure your recovery email and phone number are current and secure.
  6. Never share a password in a message. If an assistant or an agency needs access, use a separate login that you can remove.
  7. Sign out of shared computers and review which devices are signed in every few months.

3. Phishing: recognising the trap

  • A message that creates urgency (“your page will be deleted today”) or fear is a warning sign.
  • Check the sender’s address and the real destination of any link before you click. On a phone, press and hold the link to preview it.
  • Be suspicious of a request to log in through a link in a message. Go to the service by typing its address or using your own bookmark.
  • Be suspicious of any request to change payment details, especially for a supplier or a client, until you confirm by phone using a number you already had.
  • Do not open unexpected attachments.
  • If you click something you should not have, change the password for that account from a clean device and tell the provider.

4. Fake copies of your page

Professionals with a trusted name are targets for copies. The giveaway is usually a different address or a request for money.

  1. Search for your name, profession and city every few months, and look at the images tab too.
  2. Search for a distinctive sentence from your page in quotation marks. Copies often reuse your text.
  3. Do a reverse image search on your photograph. Most browsers and search engines offer it.
  4. If you find a copy, take screenshots with the date and web address visible.
  5. Report it to the hosting company, the domain registrar and the search engine. Most have forms for impersonation and copyright infringement. Use the details on the copy’s address lookup.
  6. Report it to your professional body, which may take action, and to the police or consumer authority if money was taken.
  7. Warn your clients on your page and your profiles in plain words: “My only web address is… I never ask for payment details by message.”

5. Your domain and email

  • Register your domain in your own name, with two-step sign-in, and auto-renewal on. See choosing a web address.
  • Use a professional email address with a provider that supports two-step sign-in. See professional email for your practice.
  • Keep your registrar and your site platform logins separate.
  • Check that the contact email on every account is one you read.

6. Your content and your software

  • Keep software up to date, or use a platform that does it for you. Remove plugins and tools you no longer use.
  • Be careful what you publish. Do not put your home address, your children’s school or personal details on a public page. Use a business address or a general area.
  • Do not publish client names, photographs or case details without clear written permission.
  • Back up your content. Keep a copy of your text and photographs on a drive or in a folder that you control.
  • Review who has access to your accounts and remove people who no longer need it.

Tell clients what to expect

A short line on your page helps clients spot a fake and reduces risk.

A short notice for your page (invented example; adapt it)
My web address is annaweiss.example. I will never ask you to pay by message, send card details by email or change bank details by text. If you are unsure, call me on 020 7946 0000.

If something goes wrong

  1. Stay calm and act in order. Write down what you notice and when.
  2. Secure your email first: change the password from a clean device and turn on two-step sign-in. Email can reset every other account.
  3. Then change passwords for the affected accounts, starting with your site platform, domain and bank. Sign out all other sessions.
  4. Contact the provider of any compromised account. Use the support route on their official site.
  5. Contact your bank immediately if money or card details are involved.
  6. Tell clients who might be affected, in clear words, and say what to do.
  7. Report the incident to your regulator or professional body if required, and to the police or the relevant cyber-crime reporting service in your country.
  8. If personal data may have been exposed, check whether the law in your country requires you to notify the data protection regulator and the people affected. In the UK and EU this is generally within 72 hours for the regulator. See privacy notice and cookies.
  9. Afterwards, work out what happened and change the habit that allowed it.

Common mistakes

  • One password used everywhere.
  • No two-step sign-in on email.
  • Clicking a link in an alarming message instead of going to the site directly.
  • Letting a domain lapse.
  • Never searching for your own name.
  • Telling nobody when a fake appears.
  • Giving access to a freelancer using your own login.

Where BeVisible fits

Hosting and SSL (the padlock) are included in every BeVisible plan, and you do not manage a server or plugins yourself. The habits above, such as a strong password and two-step sign-in for your email, remain yours. You can build and preview free, and publish free for 7 days with no card needed; after that one yearly plan keeps a website online, and one plan covers one website. Start from a photo or type your details.

Frequently asked questions

What is HTTPS and do I need it?

HTTPS encrypts the connection between your visitor and your page and shows a padlock. Browsers warn visitors about pages without it, so a professional page should always use it. A hosted platform usually provides it for you.

Does a padlock mean a website is safe?

No. It means the connection is encrypted. Fake and harmful pages can have a padlock too, so check the web address and what the page asks you to do.

What should I protect first?

Your email account. Most other accounts can be reset through it, so give it a long unique password and two-step sign-in before anything else.

How do I find a fake copy of my page?

Search for your name, profession and city; search for a distinctive sentence from your page in quotation marks; and run a reverse image search on your photograph. Do this every few months.

What should I do if someone copies my page?

Take dated screenshots, report it to the hosting company, the domain registrar and the search engine, tell your professional body, report it to the authorities if money was taken, and warn your clients.

Do I need to tell anyone if my accounts are hacked?

Tell your provider, your bank if money is involved and any clients who may be affected. If personal data may have been exposed, check whether your country’s data protection law requires you to notify the regulator, which is generally within 72 hours in the UK and EU.

Read next