Look at the address bar. It is not the address you thought you typed.
Spot the difference
FakedecathIon.my
Realdecathlon.my
I vs l
Capital i · Lowercase L
In most fonts these two characters are identical vertical strokes. Your eye
reads the shape of the whole word, not the individual letters —
so the substitution is invisible at a glance, especially on a phone.
This is a controlled demonstration.
This page is operated by DecodeAI to show how a lookalike domain
works. It is not affiliated with, endorsed by, or connected to
Decathlon. Nothing here imitates their website, and nothing here asks you for
anything.
How the real attack runs
A delivery notification arrives by SMS or WhatsApp. It looks routine, because it is routine — you are genuinely expecting a parcel.
The link uses a character swap you cannot see on a small screen.
The page that loads is a pixel-perfect copy of the real checkout.
You pay a small “redelivery fee” — and hand over your card details.
The charge you authorised is trivial. The one that follows is not.
What actually protects you
Never reach a merchant through a link you were sent. Open the app or type the address yourself.
A real courier never needs your card to release a parcel. A fee request is the tell, whatever the domain says.
Check the domain, not the design. Anyone can copy a logo in an afternoon. The address bar is the only thing an attacker cannot fake.
Nothing happened to you. This page collects no data, sets no
cookies, runs no trackers, and has no forms. You are safe. If this had been the
real thing, you would already be on a checkout page.