Skip to main content
Emerging ThreatsData Breaches

DoppelCart Network Exposes 119,000 Fake Shops Stealing Credit Cards

Cluttered server room with rows of computer equipment and monitors, lit by natural daylight through a window.

More than 119,000 domains are part of a single fraud operation that builds thousands of fake online shops to harvest payment-card data and related personal details.

Scale and structure of the DoppelCart cluster

German cybersecurity startup Nebty identified the operation, which it has named “DoppelCart.” Nebty describes it as the largest publicly documented fake‑shop cluster by domain count, dwarfing the previously reported “BogusBazaar” (75,000 sites). Most DoppelCart domains live in the .SHOP top‑level domain, where they account for roughly 2.72% of all sites on that TLD.

Nebty’s scans show that more than 105,000 of the DoppelCart shops remain active. The company told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends — indicating a centrally managed infrastructure operating at unusually large scale.

How the fake shops impersonate legitimate brands

The DoppelCart sites copy product catalogs, descriptions, branding, and images from legitimate businesses; in some cases they even load assets directly from the real company’s servers. Nebty reports the cluster mimics 44,182 different brands, with a median of two clones per brand. A handful of brands received outsized attention — SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS each had more than 30 shops impersonating them.

The fraudulent stores advertise steep discounts — up to 65% in many cases — to lure bargain‑seeking shoppers into completing checkout flows on the fake sites.

What the checkout code collects and how it exfiltrates data

Nebty analyzed multiple DoppelCart checkout pages and found code that captured extensive payment and identity data. The fields collected include card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses. According to Nebty, each data field is transmitted over WebSockets to a command‑and‑control (C2) server in real time.

The checkout code can also relay one‑time confirmation codes issued by a victim’s bank, a capability the researchers warned attackers may use to bypass security protections.

Nebty’s outreach, hosting provider response, and tools for brands

Nebty says it attempted to contact the network’s main hosting provider but received no response. Separately, the company has created a searchable database intended to help companies identify DoppelCart impersonation and brand abuse and take appropriate action to protect themselves.

That database is presented as a practical step for brands to find and flag clones quickly, since many DoppelCart shops present the impersonated brand’s legitimate support address — a detail that can funnel aggrieved customers toward the real company and create additional reputational and operational damage.

What this means for technologists, affected enterprises, and consumers

  • Technologists and security teams: expect to encounter mass‑produced sites that share build files and resolve to a small number of backends; watch for data exfiltration over WebSockets from checkout pages and for scripts that capture one‑time codes during payment flows.
  • Affected enterprises and procurement leaders: Nebty’s searchable database offers a way to locate impersonations quickly; brands that discover clones should be prepared to document copied assets and to seek takedown or hosting‑provider action, noting Nebty’s report that outreach to the main hosting provider drew no response.
  • End users and the general public: steep discounts (advertised up to 65%) on sites that otherwise look legitimate can be a red flag; victims may have their card details and one‑time bank confirmation codes captured in real time, and some fake shops list real support addresses that can misdirect follow‑up inquiries.

DoppelCart’s size—more than 119,000 domains with over 105,000 active shops, centralized build files, and real‑time C2 exfiltration—marks it as a major organized effort to monetize cloned e‑commerce infrastructure. Nebty’s searchable database and its outreach to the hosting provider are immediate mitigation steps; whether those actions will materially reduce the cluster’s reach remains to be seen.

Original story at BleepingComputer