
A large-scale operation called “DoppelCart” uses more than 119,000 domains to run a network of fake e-stores that steal payment card details.
Most of the domains are in the .SHOP top-level domain, which accounts for 2.72% of all sites in the TLD.
German cybersecurity startup Nebty discovered DoppelCart and described it as the largest publicly documented cluster of fake stores by number of domains, far surpassing the second largest, “BogusBazaar,” which operates a network of 75,000 sites that record about 850,000 fraudulent transactions.
The company’s latest scans show that more than 105,000 DoppelCart stores are still active.
Nebty CEO Benedict Schoengraber told BleepingComputer that 96% of stores confirmed to be part of DoppelCart share identical build files and solve up to 27 commerce backends.
The sites pose as legitimate businesses by copying product catalogs, descriptions, branding and images, sometimes loading assets directly from the real company’s servers.
Schoengraber says the stores imitated 44,182 different brands, with an average of two clones for each.
However, some brands such as SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS received more attention, with over 30 stores each.
Fake sites advertise deep discounts of up to 65% in many cases to attract bargain-seeking shoppers.

Source: BleepingComputer
When testing several payment pages in the DoppelCart cluster, Nebty discovered code that collected sensitive information related to payment cards and their holders:
- Card numbers
- Expiry dates
- Security codes
- Names of cardholders
- Email addresses
- phone numbers
- Physical addresses
Each field of data is transmitted over WebSockets to the Command and Control (C2) in real-time, Netby says in a report shared with BleepingComputer.
The payment code can also relay the one-time verification code issued by the victim’s bank, which attackers can use to bypass security protections.
Nebti says some of the fake stores display the counterfeit brand’s legitimate support address, prompting victims who haven’t received their purchases to contact the real company.
Schoengraber says the company has tried to contact the primary hosting provider for DoppelCart sites, but has not heard back.
Separately, Nebty created a searchable database to help companies identify DoppelCart misrepresentation and brand abuse and take appropriate action to protect themselves.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.
