DoppelCart: 119,000 fake online shops caught stealing payment card data

German researchers call the network the largest documented fake-shop cluster by domain count

edit
By LineZotpaper
Published
Read Time2 min
A fraud network dubbed "DoppelCart" is running more than 119,000 fake online stores designed to steal payment card details, according to German cybersecurity startup Nebty, which describes it as the largest publicly documented fake-shop cluster by domain count.

The network is concentrated in the .SHOP top-level domain, where its sites account for 2.72 percent of all registered domains, Nebty said in a report shared with BleepingComputer. The company's latest scans show that more than 105,000 DoppelCart shops are still active.

Nebty says 96 percent of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends. The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding and images, sometimes loading assets directly from the real company's servers.

Nebty CEO Benedikt Scheungraber told BleepingComputer that the shops mimic 44,182 different brands, with a median of two clones for each. Some brands drew heavier attention, including SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS, each with more than 30 fake shops.

The fraudulent sites lure bargain-hunting shoppers with discounts of up to 65 percent. When Nebty tested several checkout pages, it found code that collects card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers and physical addresses, transmitting each field over WebSockets to a command-and-control server in real time. The checkout code can also relay the one-time confirmation code issued by a victim's bank, which attackers may use to bypass security protections.

Some of the fake stores display the impersonated brand's legitimate support address, meaning customers who never receive their purchases end up contacting the real company. Nebty says it attempted to contact the main hosting provider for DoppelCart sites but received no response. The company has created a searchable database to help businesses identify whether they are being impersonated and take protective action.

§

Analysis

Why This Matters

  • Shoppers who fall for the heavily discounted fake stores risk having their payment card details and personal information stolen.
  • At more than 119,000 domains, the network represents a significant share of the .SHOP TLD, and the majority of the shops remain active.
  • Brands being impersonated face reputational damage, customer complaints and the burden of unwinding fraudulent purchases.

Background

Fake online storefronts and card-skimming operations are a well-established threat in e-commerce. Earlier magecart-style attacks have historically compromised legitimate payment pages to steal card data. DoppelCart differs in approach and scale: rather than injecting code into real sites, it operates its own network of fraudulent storefronts that imitate established brands to lure shoppers. The second-largest documented cluster, "BogusBazaar," operated 75,000 sites and recorded an estimated 850,000 fraudulent transactions, making DoppelCart substantially larger by domain count.

Key Perspectives

Nebty / security researchers: The startup has documented the network's infrastructure, identified the common build files and backends, and released a searchable database to help brands check for impersonation. Hosting providers: Nebty's outreach to the main hosting provider went unanswered, leaving the bulk of the infrastructure online and operational. Impersonated brands: Companies whose names and catalogs are copied must field complaints from customers who never received goods, while managing damage to their reputation. Consumers: Bargain hunters are the primary targets, and the use of deep discounts plus cloned branding makes fraudulent sites difficult to distinguish from legitimate ones.

What to Watch

  • Whether hosting providers or domain registrars take action against the .SHOP domains, and how quickly the network can be disrupted.
  • Whether DoppelCart operators migrate to other top-level domains if .SHOP infrastructure is taken down.
  • Whether law enforcement or payment card industry bodies launch investigations or add the domains to blocklists.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.