119,000 Fake Shops Are Mimicking Real Brands to Steal Card Details

Researchers uncovered more than 119,000 DoppelCart fake shopping domains impersonating thousands of brands and collecting shoppers’ payment information.

Sep 10, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Researchers have uncovered a fake-shopping network spanning more than 119,000 domains.

German cybersecurity company Nebty identified the operation, dubbed DoppelCart, which imitates legitimate retailers by copying their branding, product catalogs, descriptions, and images. The fake checkout pages can capture card numbers, expiration dates, security codes, billing information, and, in some cases, bank-issued confirmation codes.

More than 105,000 of the identified domains were reportedly still online when Nebty published its findings. Researchers say the scale makes DoppelCart the largest publicly documented fake-shop cluster they have identified.

Inside the DoppelCart fake-shop network

According to BleepingComputer, the sheer number of fake domains recorded in this campaign is so large that Nebty, the German cybersecurity company that uncovered the fraud, called it the largest publicly documented fake-shop cluster.

That number stands against the previously documented BogusBazaar network, which was linked to more than 75,000 domains.

Researchers found that 96% of confirmed DoppelCart shops shared technical similarities and connected to just 27 e-commerce backends, suggesting that what appears to be thousands of separate stores is supported by a much smaller centralized infrastructure.

The stores also copied legitimate retailers’ catalogs, descriptions, and images, with researchers identifying 44,182 impersonated brands and discounts of up to 65%. Brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS saw impersonation frequency reach 30, far above the median impersonation rate of two for other brands.

Online shoppers expect to check out with their cards, believing their card data is masked and never shared with retailers. However, Nebty found that during checkout, the attackers collected banking information including card numbers, expiration dates, security codes, and cardholder names. 

Advertisement

Other collected data includes victims’ email addresses, phone numbers, and even their physical addresses.

The attackers relay this data over a command-and-control server via WebSockets. When a victim experiences an issue, the fake page redirects them to the support address of their impersonated brand, a clever play of confusion.

Why does a campaign like this still work

Shopping is already one of the most crowded and competitive parts of the internet, yet DoppelCart made thousands of fraudulent stores look convincing enough to matter. That is because the attackers are not asking people to do something unusual — they are taking familiar shopping habits and using them against the buyer.

A steep discount creates urgency, a familiar brand creates trust, and a polished checkout page makes the purchase feel routine. Add copied products, real-looking images, and familiar branding, and shoppers may have very little reason to stop and question the store before entering their payment details.

The safest approach is to flip the biggest thing attackers bet on against you — slowing down. 

Check the domain carefully, search for the retailer independently rather than following an ad, compare the price with other established sellers, look for a real business history, and be suspicious of discounts that seem unusually generous.

A security homework for all enterprises 

According to SC Media, Nebty has created a public database that lets retailers check whether their brands are among the 44,182 brands DoppelCart has impersonated.

But the bigger lesson goes beyond this one campaign. The problem underscores the need for proactive threat intelligence. Any company that is valuable enough to attract customers is also valuable enough to attract threat actors, even if it operates outside the technology sector.

For retailers, that means looking beyond protecting their own networks and actively watching for fake domains, cloned storefronts, and other signs that criminals are abusing their brand. 

DoppelCart shows how quickly that abuse can scale: a relatively small number of underlying systems can support tens of thousands of convincing storefronts, turning brand impersonation into an infrastructure problem rather than a one-off scam. 

Advertisement

Other news: Researchers used AI to build WeWorm, a zero-click WeChat exploit that could hijack accounts through unanswered calls and potentially put more than 1 billion accounts at risk before Tencent mitigated the flaw. 

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.