- The Mess: A fraud network called DoppelCart has linked around 119,000 fake-shop domains into one massive operation. More than 105,000 were still active in the latest scan.
- The Damage: The stores clone legitimate brands and can steal card details, personal data and bank verification codes during checkout.
- The Fix: Stop buying from unfamiliar discount stores, verify the real domain independently and never trust a shop simply because its design looks legitimate.
This is not one fake store.
It is an industrial-scale fake-store machine.
Researchers at German cybersecurity company Nebty identified roughly 119,000 domains connected through shared infrastructure and recurring shop software. The cluster represents about 2.72% of the entire .shop domain population in their September 2026 snapshot.
Nebty calls the operation DoppelCart.
The network copies legitimate businesses instead of inventing completely fake brands. Product catalogs, descriptions, images and branding are reproduced so accurately that a visitor can easily believe they have landed on the real store.
Some archived shops even loaded image assets directly from the legitimate company’s infrastructure. Discounts of up to 65% make the fake storefronts even more convincing.
And then comes checkout.
Researchers found that malicious checkout code can collect information entered by shoppers, including card numbers, expiration dates, CVV codes, names, addresses, email addresses and phone numbers. BleepingComputer reports that the infrastructure includes 27 commerce backends, while 96% of confirmed shops shared identical build files.
The nastiest part is the second factor.
Some checkout implementations can intercept the one-time code sent by a bank to approve a transaction. The browser becomes the collection point, so the attacker does not necessarily need to break the bank’s authentication system.
They just steal the information before it reaches the legitimate payment flow.
That turns a fake-shop operation into something much more dangerous than simple counterfeit retail.
The scale is also difficult to ignore.
Nebty identified 118,996 distinct domains after consolidating www variants. Its investigation archived 106,095 HTML pages. The researchers identified tens of thousands of legitimate brands being impersonated across the network.
The previous large-scale comparison, BogusBazaar, involved more than 75,000 domains.
DoppelCart is substantially larger.
And this is not theoretical infrastructure sitting in a database.
BleepingComputer reported that more than 105,000 DoppelCart shops remained active during the latest scan.
For consumers, the practical defense is annoyingly simple.
Do not enter card details into a shop reached through a suspicious advertisement just because the website looks professional.
Check the domain.
Check the company’s official website separately.
Check whether the store has a real history.
And if a product normally costs €500 and some unknown .shop domain offers it for €175, assume the discount is part of the attack.
Bugstoday Opinion
DoppelCart is what online fraud looks like after automation removes the boring parts.
One template.
Thousands of domains.
Real brands.
Copied products.
Automated checkout infrastructure.
And potentially stolen payment data flowing straight to criminals.
The scary number is not 119,000.
It is 105,000 still active.
That means this is not an old dataset describing yesterday’s fraud. It is an operating attack surface.
The fake shop does not need to hack the brand.
It only needs you to believe that you are already on the brand’s website.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
nebty
BleepingComputer




