Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » DoppelCart Security Threat Spans Nearly 119,000 Fake-Shop Domains Impersonating 44,000 Brands

DoppelCart Security Threat Spans Nearly 119,000 Fake-Shop Domains Impersonating 44,000 Brands

By:
Last updated:September 10, 2026
Human Written
  • Nebty found nearly 119,000 domains tied to the DoppelCart fake-shop network, including 118,787 .shop domains.

  • The sites copy real brands and products, then use checkout pages to collect payment and bank verification data.

  • The network spans more than 44,000 brands, but shared infrastructure does not prove one group runs every site.

Nearly 119,000 Fake Shops Impersonating Real Brands Found in DoppelCart Network

A network of fake online stores is impersonating real retailers and putting shoppers’ payment details at risk.

German cybersecurity company Nebty has identified DoppelCart, a cluster of almost 119,000 domains linked by shared website and infrastructure traits. The company calls it the largest publicly documented fake-shop cluster by domain count.

According to Nebty’s September 2026 Snapshot, DoppelCart had 118,787 .shop domains. That makes up 2.72% of the 4.36 million .shop domains Nebty examined. This means that one in every 37 .shop domains belongs to the DoppelCart fake shop network.

Nebty says the count covers domains associated with the cluster, not stores confirmed active at the same time.

Fake Stores Copy Real Brands

DoppelCart makes fake stores look familiar. Nebty found sites copying product catalogs, descriptions, logos, images, and other material from legitimate retailers. Some fake sites even pulled images directly from the real company’s servers.

One examined store copied product descriptions word for word and reused product images from the legitimate store. That can make a fake store feel safe. Shoppers may recognize the products and assume the site is legitimate.

Nebty found that the network impersonates 44,182 brands. The median was two fake shops per brand, although some companies faced far more copies.

SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS each had more than 30 shops in the cluster. Nebty found examples advertising discounts of up to 65%.

The Checkout is Where the Real Danger Starts

The fake storefront is only part of the operation. Its checkout can be built to capture payment information. Reporting based on Nebty’s findings says 96% of confirmed DoppelCart shops shared identical build files and connected to just 27 e-commerce backends.

Nebty says the network was identified through repeated website and infrastructure features. It also stresses that shared technical foundations do not prove every domain belongs to one criminal group.

The payment pages can harvest user data. They collect things like card numbers, card expiry dates, CVVs, full names, email addresses, phone numbers, even billing addresses, and send them over in real-time via WebSockets to systems controlled by the attackers. Pages may also request one-time bank confirmation codes.

If criminals receive a bank authentication code during checkout, they may be able to use it during the same transaction. A fake shop can do more than take money for an order that never arrives. It can also steal financial information.

Real Brands can get the Complaints

The damage does not always stop with shoppers. Nebty says fake stores sometimes copy the legitimate retailer’s support address. When customers do not receive their orders, they may contact the real company instead.

The legitimate business must then explain that the customer bought from a different website. Nebty has published its investigation database so businesses can check whether their brands appear in the network. It includes evidence for confirmed entries and domains that may no longer be online.

Nebty says some takedowns have worked, although most of the cluster remained online at publication.

Fake-shop Networks are Getting Bigger

DoppelCart is not the first large fake-store operation. In 2024, SRLabs identified the existence of BogusBazaar, a network made up of more than 75,000 domains. This network processed over 850,000 fraudulent orders. Its main target was Western European countries and the USA.

DoppelCart is larger by domain count, but the investigations used different methods and time periods. AI-assisted website tools could make this type of fraud easier to scale. Malwarebytes reported in February that criminals were using AI website builders to clone trusted brands and create convincing storefronts with little technical skill.

That does not mean AI created DoppelCart. Nebty found shared website and infrastructure traits, not proof that AI built the network.

A Florida smoke shop owner was arrested after a year-long investigation into a fatal overdose. Authorities linked him to MDMA that was about 2.5 times stronger than typical street doses and seized two pounds of MDMA, LSD, psilocybin mushrooms, and cryptocurrency machines.

How Shoppers Can Avoid Fake Stores

A polished website is not proof that a store is real. HTTPS, logos, product photos, and clean layouts can all appear on scam sites.

Before paying, check the domain carefully. Contact the retailer via the official application or website link or address that you know.  Beware of suspiciously low prices. Too large discounts are a red flag; stop and perform extra checks to be sure they’re legit.

Search for the store name and domain with terms such as “scam” and “reviews.” Check its address, contact details, return policy, and payment information. Use payment methods with buyer protection. Avoid cryptocurrency, gift cards, bank transfers, and other hard-to-reverse methods.

Finally, treat bank verification requests with care. Check the merchant and amount before approving. Never share a one-time bank code with a seller or anyone who contacts you.

If you entered card details on a suspicious store, contact your card issuer quickly. Consider replacing the card, and keep track of the account. Save your screenshots and order receipts as they’ll be handy when filing a fraud report.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.