Researchers have uncovered a fake-shopping network spanning more than 119,000 domains.
German cybersecurity company Nebty identified the operation, dubbed DoppelCart, which imitates legitimate retailers by copying their branding, product catalogs, descriptions, and images. The fake checkout pages can capture card numbers, expiration dates, security codes, billing information, and, in some cases, bank-issued confirmation codes.
More than 105,000 of the identified domains were reportedly still online when Nebty published its findings. Researchers say the scale makes DoppelCart the largest publicly documented fake-shop cluster they have identified.
Inside the DoppelCart fake-shop network
According to BleepingComputer, the sheer number of fake domains recorded in this campaign is so large that Nebty, the German cybersecurity company that uncovered the fraud, called it the largest publicly documented fake-shop cluster.
That number stands against the previously documented BogusBazaar network, which was linked to more than 75,000 domains.
Researchers found that 96% of confirmed DoppelCart shops shared technical similarities and connected to just 27 e-commerce backends, suggesting that what appears to be thousands of separate stores is supported by a much smaller centralized infrastructure.
The stores also copied legitimate retailers’ catalogs, descriptions, and images, with researchers identifying 44,182 impersonated brands and discounts of up to 65%. Brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS saw impersonation frequency reach 30, far above the median impersonation rate of two for other brands.
Online shoppers expect to check out with their cards, believing their card data is masked and never shared with retailers. However, Nebty found that during checkout, the attackers collected banking information including card numbers, expiration dates, security codes, and cardholder names.
Other collected data includes victims’ email addresses, phone numbers, and even their physical addresses.
The attackers relay this data over a command-and-control server via WebSockets. When a victim experiences an issue, the fake page redirects them to the support address of their impersonated brand, a clever play of confusion.
Why does a campaign like this still work
Shopping is already one of the most crowded and competitive parts of the internet, yet DoppelCart made thousands of fraudulent stores look convincing enough to matter. That is because the attackers are not asking people to do something unusual — they are taking familiar shopping habits and using them against the buyer.
A steep discount creates urgency, a familiar brand creates trust, and a polished checkout page makes the purchase feel routine. Add copied products, real-looking images, and familiar branding, and shoppers may have very little reason to stop and question the store before entering their payment details.
The safest approach is to flip the biggest thing attackers bet on against you — slowing down.
Check the domain carefully, search for the retailer independently rather than following an ad, compare the price with other established sellers, look for a real business history, and be suspicious of discounts that seem unusually generous.
A security homework for all enterprises
According to SC Media, Nebty has created a public database that lets retailers check whether their brands are among the 44,182 brands DoppelCart has impersonated.
But the bigger lesson goes beyond this one campaign. The problem underscores the need for proactive threat intelligence. Any company that is valuable enough to attract customers is also valuable enough to attract threat actors, even if it operates outside the technology sector.
For retailers, that means looking beyond protecting their own networks and actively watching for fake domains, cloned storefronts, and other signs that criminals are abusing their brand.
DoppelCart shows how quickly that abuse can scale: a relatively small number of underlying systems can support tens of thousands of convincing storefronts, turning brand impersonation into an infrastructure problem rather than a one-off scam.
Other news: Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls and potentially put more than 1 billion accounts at risk before Tencent mitigated the flaw.





