D Directive Publications Blog Guides for medical & scientific authors

Hijacked Journals: How to Spot a Cloned Journal Website

Updated October 08, 2026
Two near-identical journal homepages side by side, with their web addresses highlighted to show the difference between a genuine journal site and its clone
The title and ISSN can be copied. The history of a web address is much harder to fake.

A cloned journal website can carry a real title, a valid ISSN and even an index listing. The web address is where the deception shows, if you check it.

Key point: A real title and a valid ISSN do not prove a website belongs to the journal, so confirm the URL through independent records before you submit or pay.

What a hijacked journal is, and what it is not

A hijacked journal is a website that impersonates a real journal. Retraction Watch, which hosts a public list of them, describes hijacked journals as mimicking legitimate journals by adopting their titles, ISSNs and other metadata, usually without permission. Many charge fees and promise fast publication and indexing in databases such as Scopus.

That is a different problem from a predatory journal, which trades under its own name, so checking its peer review, board and fees tells you most of what you need; our guide to predatory journal red flags covers those checks. A hijacked site borrows a name that passes them. The question is not "is this journal real?" but "is this website the journal?"

"Hijacked journal" and "cloned journal" mean the same thing, so search both when you look up a title. The Retraction Watch Hijacked Journal Checker passed 400 entries in December 2025, up from a little over 100 in May 2022, according to Retraction Watch — about seventy to eighty new cases a year, so re-check each time you submit, not once.

How a cloned journal website is built

Three patterns are well documented:

  • A look-alike address. A convincing copy of the journal's site at a similar web address, with authors sent to it through marketing emails.
  • A lapsed domain. When a journal fails to renew its address, or moves and lets the old one go, someone else can buy it. In 2015 a Science journalist demonstrated this by buying the old domain Web of Science still listed for a journal that had moved. Database links then lead to whoever owns the address now.
  • Networks with reused parts. Large networks run dozens of clone sites, often with the same template and even identical papers across their archives.

What matters most is that clones reach the places you might use to check them. Anna Abalkina, who created the checker with Retraction Watch, reports that papers from hijacked journals turn up in Google Scholar, and that one study found 67 hijacked journals had compromised the data of authentic journals in Scopus, sometimes including the homepage link in the profile. A database record tells you a journal exists, not which website is the journal's.

Hijackers keep targeting the same kinds of titles, Abalkina notes: journals indexed in Scopus or Web of Science, local-language journals and niche journals. If your target fits, check harder.

Warning signs on a suspicious site

Signal What it suggests
You arrived from an unsolicited email or a search result This address is not yet tied to the journal
Promises of fast publication and Scopus indexing The lure Retraction Watch describes
Recent papers far outside the journal's field Topic mismatch is common in hijacked journals
The same article under another journal's name Search a title in quotes; clone networks reuse archives
DOIs that do not start with "10." or do not resolve Abalkina reports fake DOIs starting with 16 or 20

None proves a hijack alone; small legitimate journals can have dated websites. But a DOI signal, or any two together, is reason to run the full check.

How to verify a journal URL in eight steps

  1. Put the link aside and note the ISSN. Copy the title and ISSN, but do not use the link you were given. A clone copies the ISSN too, so it is a search key, not evidence.
  2. Look up the ISSN in the ISSN Portal. The free view shows title, country, medium, the URLs of digital resources and the last-update date; publisher and publication dates are subscription-only except for open access titles in ROAD. Records can list several URLs, some old — and some, including major subscription journals, list none. An empty URL field only means this record cannot settle it.
  3. Cross-check a second independent record. For biomedical titles, read the Electronic Links field in the NLM Catalog record — but NLM stopped providing links for journals it does not collect, so it can read "Access not provided by NLM" (NLM Technical Bulletin). That is common for the niche and local-language titles hijackers favour, and means no URL, not a bad journal. The record still names the publisher, which the free ISSN view does not. Otherwise use DOAJ or the claimed index.
  4. Compare the domains character by character. Look for extra words, hyphens, a different ending such as .org for .com, or the journal name inside someone else's domain.
  5. Check the domain's age and history. Find the creation date in the registration data (ICANN Lookup covers generic domains; country-code domains have their own registries). Abalkina names an anonymously registered, recently created domain as a warning sign, but weigh the halves differently: redacted owner names are common on legitimate sites, while a domain created last year under a decades-old title is hard to explain. Then see how long the Wayback Machine shows the address hosting this journal. A redirect from a record's old address is normal — journals move — but a recent domain or an archive gap suggests a lapsed domain the record now points at.
  6. Test the archive, its DOIs and who owns them. Open several recent articles. Do the topics fit the title? Paste a DOI into doi.org: it should begin with "10." and land on that article. Then check who registered the prefix, because a resolving DOI is not proof on its own — Abalkina reports that fraudulent publishers sometimes register real DOIs for hijacked journals, caught by cross-checking Crossref. Open api.crossref.org/prefixes/10.xxxx: the member should be the genuine publisher.
  7. Search the Hijacked Journal Checker. Look for the title and the exact address in the Retraction Watch Hijacked Journal Checker. A clean result only means this site has not been reported yet.
  8. Confirm with the publisher before you pay. Find the publisher from a record that names it for free — the NLM Catalog Publisher field, DOAJ, a Scopus or Web of Science profile, or the ISSN Portal for ROAD open access titles. Write using contact details you found yourself, never an address on the site in question.

A clean run — records agree, long domain history, DOI prefix owned by the publisher — means record the date and submit. If two sites claim the same title, never choose on design or ranking: ask the publisher, then report the other.

If you have already submitted or paid

  1. Stop. Send no more payments, files or forms.
  2. Preserve everything. Save emails, invoices, receipts, the exact URL and screenshots. Abalkina notes that clone sites are often abandoned once detected and their domains expire, so capture it now.
  3. Contact your bank or card issuer promptly. Ask whether the payment can be disputed or recalled; options and limits depend on the method and country.
  4. Tell the people involved. Co-authors, your research office and the genuine journal, using details from its verified site. If grant funds paid, involve the office before the funder.
  5. Report the site. Use the form linked from the Hijacked Journal Checker, plus your national fraud channel if money was lost.
  6. Clear the manuscript. Ask the site in writing to remove the paper, keep the reply or its absence, and explain the history to the next editor.

What research offices and libraries can do

  • Store URLs, not just titles. An approved journal list should hold the ISSN, the verified address and the date checked, and be re-checked because domains change hands. A title-only list cannot tell a journal from its clone.
  • Match the payee to the verified site. Ask for the verified journal URL on fee payment requests, and query invoices from a different domain.
  • Teach it with live records. In workshops, have researchers run steps 2 to 6 on a real ISSN record. Our guide to how institutions can spot predatory publishing risks covers building such checks into training and payment workflows.

Checking a medical journal's indexing claims

"Indexed in PubMed/MEDLINE" is the lure aimed hardest at biomedical authors, and it is easy to test. PubMed carries records from several sources, including PubMed Central deposits, so a paper there does not mean the journal is indexed for MEDLINE. MEDLINE selection is a formal editorial decision, and it is recorded: search the NLM Catalog for the title or ISSN and read the record's indexing statement, not the journal's. Adding currentlyindexed to the search limits results to titles currently indexed for MEDLINE — a direct yes or no.

Note the trap: a clone usually quotes the real journal's MEDLINE status or impact factor accurately, because the claim is true of the title and false of the website. State the cost plainly to co-authors: a trial report on a clone is not deposited where systematic reviewers and guideline developers will find it.

Check the address, not the look

A title, an ISSN and a website's look can all be copied, and so, sometimes, can a working DOI. What a clone cannot easily manufacture is a web address with years of history, or a DOI prefix registered to the real publisher. If you are still choosing where to send a paper, our guide to choosing a journal without getting scammed covers fit and legitimacy together. The same habit applies to every publisher, including us: type the Directive Publications address yourself, and read the author guidelines before you submit.

Frequently asked questions

What is a hijacked journal?

A hijacked journal is a website that impersonates a legitimate journal, copying its title, ISSN and other metadata without permission. Many charge publication fees and attract authors with promises of fast publication and database indexing. It differs from a predatory journal, which operates under its own name, because the journal being copied is real.

How do scammers clone a legitimate journal website?

They copy the real journal's title, ISSN and appearance onto a web address they control. Some use a similar-looking address, and others buy a domain the genuine journal allowed to lapse, so old links in databases can lead straight to the clone. Networks of hijackers often reuse the same site template and even identical papers across many clone sites.

Is there a list of known hijacked journals?

Yes. The Retraction Watch Hijacked Journal Checker, created by researcher Anna Abalkina with Retraction Watch, is a public spreadsheet of hijacked journals that keeps websites on the list even after they expire. New cases are added as they are confirmed, and anyone can suggest a title. A journal missing from the list is not proof that a website is genuine.

How can I confirm a journal's official URL?

Start from the ISSN, not from a link in an email or a search result. The free ISSN Portal record gives you the title, country and any URLs, and a second independent record such as the NLM Catalog or DOAJ should agree with it. Then weigh the evidence a clone cannot copy: how long the domain has hosted this journal, and whether the Crossref member behind its DOI prefix is the genuine publisher.

What should I do if I paid a hijacked journal?

Stop further payments and keep every email, invoice, receipt and screenshot of the site. Contact your bank or card issuer promptly to ask whether the payment can be disputed, and tell your co-authors, your research office and the genuine journal. Report the site to the Retraction Watch Hijacked Journal Checker, and ask the site in writing to remove your paper before you submit it anywhere else.

Ready to submit with confidence?

Use transparent peer review and clear author guidelines.

Submit your manuscript