More than 100,000 fake stores are out to steal your card details
Researchers uncovered DoppelCart, a network of roughly 119,000 cloned fake shops that harvest card details and one-time bank codes during checkout.
Researchers at German firm Nebty identified 118,787 .shop domains tied to cloned online stores, representing 2.72% of the TLD population examined and described as the largest publicly documented fake-shop network by domain count. The shops mimic more than 44,000 brands, advertise discounts up to 65%, and 96% of confirmed shops reportedly share identical build files using just 27 ecommerce backends. Fraudulent checkout pages send card numbers, CVVs, billing data and bank one-time confirmation codes to attacker-controlled servers in real time over WebSockets, allowing criminals to complete payments while victims are still checking out.
- Largest documented fake-shop network by associated domain count
- Clones catalogs, branding and images from more than 44,000 brands
- Real-time WebSocket capture of one-time codes enables fraudulent payments
- Some brands such as SodaStream and Daniel Wellington have 30+ clones each
Full article563 words · extracted from malwarebytes.com · click to collapse
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.
The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.
The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.
As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.
BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.
The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.
“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”
Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.
The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.
Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.
How shoppers can stay safe
A professional-looking store, the use of HTTPS, authentic product images, and a familiar logo do not prove that a website is legitimate. Before entering payment details, shoppers should take a few minutes to verify where they are buying from.
- Check the web address carefully. If possible, reach the retailer through its official app, a saved bookmark, or a web address you already know, rather than sponsored search results or ads on social media.
- Be wary of unusually large discounts. A low price does not prove that a store is fake, but it is a reason to check the site more carefully.
- Search for the exact web address alongside terms such as “scam” or “reviews.” Check that the contact details, returns policy, and company information match the real retailer.
- Pay by credit card or another service with buyer protection. Avoid cryptocurrency, bank transfers, gift cards, and other payments that are difficult to reverse.
- Check every bank verification request carefully. Make sure the merchant and amount are correct, and never give a one-time code to a retailer or anyone who contacts you.
- Use an up-to-date, real-time anti-malware solution with web protection.
- If you’re unsure whether a store is genuine, use Malwarebytes Scam Guard to help you assess it.
If you’ve already paid, act quickly. Contact your card issuer, report the suspected fraud, ask about replacing or monitoring your card, and save screenshots, order confirmations, web addresses, and correspondence.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.malwarebytes.com/blog/scams/2026/09/more-than-100000-fake-stores-are-out-to-steal-your-card-details