DoppelCart Fake Shop Network Uses 119,000 Websites to Steal Payment Card Data
A large-scale e-commerce fraud operation known as DoppelCart is using more than 119,000 domains to operate fake online stores designed to steal payment card and personal information.
Most of the fraudulent websites use the .SHOP top-level domain, representing approximately 2.72% of all websites registered under the extension.
German cybersecurity company Nebty discovered DoppelCart and described it as the largest publicly documented fake shop network based on the number of domains involved. The operation is significantly larger than the previously identified BogusBazaar network, which operated approximately 75,000 websites and reportedly generated an estimated 850,000 fraudulent transactions.
Nebty’s latest scan found that more than 105,000 DoppelCart websites remain active.
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the stores confirmed to be part of the DoppelCart network use the same website build files. The sites ultimately connect to 27 commerce backends.
The fraudulent stores impersonate legitimate businesses by copying product catalogs, descriptions, logos, branding, and images. In some cases, the fake websites load content and other assets directly from the real company’s servers, making them appear more authentic to shoppers.
Nebty identified DoppelCart stores impersonating 44,182 different brands, with a median of two fake websites per brand, Scheungraber said.
Several brands—including SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS—were targeted more extensively, with more than 30 fraudulent stores created for each brand.
The fake online shops commonly promote discounts of up to 65% to attract bargain-hunting consumers and encourage them to complete a purchase.

Source: BleepingComputer
While examining checkout pages from the DoppelCart network, Nebty found code designed to collect sensitive payment and identity information, including:
- Payment card numbers
- Card expiration dates
- Card security codes
- Cardholder names
- Email addresses
- Telephone numbers
- Physical addresses
According to a Nebty report shared with BleepingComputer, the stolen information is transmitted in real time to a command-and-control server through WebSocket connections.
The checkout code can also forward one-time verification codes sent by a victim’s bank. Attackers could potentially use these codes to bypass additional payment security checks and authorize fraudulent transactions.
Nebty said some DoppelCart stores display legitimate customer support addresses associated with the impersonated brands. Victims who never receive their orders may then contact the real company, unaware that their payment and personal details were submitted to criminals.
Scheungraber said Nebty attempted to contact the primary hosting provider used by the DoppelCart websites but did not receive a response.
Nebty also provides a searchable DoppelCart database to help businesses identify fake stores, detect brand impersonation, and take steps to protect their customers and online reputation.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



