BTC$84,644-0.31% LTC$70.01+1.79% XMR$542.22-0.81%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 8, 2026 · 2 min read · Original story

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.

Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.

German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, “BogusBazaar,” which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.

The company's latest scans show that more than 105,000 DoppelCart shops are still active.

Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends.

The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes loading assets directly from the real company’s servers.

Scheungraber says that the shops mimic 44,182 different brands, with a median of two clones for each.

However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.

The fake sites advertise big discounts of up to 65% in many cases to lure bargain-hunting shoppers.

One of the fraudulent DoppelCart shops
Source: BleepingComputer

When testing several checkout pages in the DoppelCart cluster, Nebty found code that collected sensitive information related to payment cards and their holders:

  • Card numbers
  • Expiration dates
  • Security codes
  • Cardholder names
  • Email addresses
  • Phone numbers
  • Physical addresses

Each data field is transmitted over WebSockets to the command-and-control (C2) in real time, Netby says in a report shared with BleepingComputer.

The checkout code can also relay the one-time confirmation code issued by a victim’s bank, which the attackers may use to bypass security protections.

Nebty says some of the fake stores show the impersonated brand’s legitimate support address, leading victims who didn’t receive their purchases to contact the real company.

Scheungraber says that the company tried to contact the main hosting provider for DoppelCart sites but received no response.

Separately, Nebty created a searchable database to help companies identify DoppelCart impersonation and brand abuse and take appropriate action to protect themselves.

References in this story

  1. Massive webshop fraud ring steals credit cards from 850,000 people www.bleepingcomputer.com A massive network of 75,000 fake online shops called 'BogusBazaar' tricked over 850,000 people in the US and Europe into making purchases, allowing the criminals to steal credit card information and attempt to process…
  2. DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network | nebty nebty-id.com DoppelCart connects around 119,000 fake-shop domains. See how real stores are copied and search our public database to check whether your brand is affected.
  3. DoppelCart — nebty investigations investigations.nebty-id.com Search DoppelCart, a network of fake online shops, by brand or domain. Every entry shows its evidence and how confident we are.

Guides related to this story

← Back to all news