119,000 Fake Shops Could Steal Your Credit Card Details: The DoppelCart Threat

The golden rule of online shopping just got a massive wake-up call. A staggering 119,000 fraudulent domains have been linked to a massive fake shopping operation known as DoppelCart, which is designed to steal your credit card details and one-time bank verification codes. Cybersecurity firm Nebty has uncovered this sprawling network of impersonation scams that clone legitimate brands so convincingly that even experienced shoppers can be fooled. Before you click "buy" on that too-good-to-be-true discount, you need to understand the mechanics of this new wave of e-commerce hacking.

This isn't just another phishing attempt; it is a sophisticated, large-scale cybercrime infrastructure that preys on trust and urgency. The threat comes at a time when AI-powered phishing and identity theft are on the rise, making it harder than ever to distinguish between a genuine retailer and a malicious clone. Here is what you need to know about the DoppelCart cluster, how these web skimming attacks work, and how to protect your financial data from this significant data breach risk.

The Anatomy of the DoppelCart Scam

Nebty discovered DoppelCart while investigating fake shops that targeted several of its customers. What started as a look into a few suspicious storefronts quickly snowballed into the largest publicly documented fake-shop cluster ever identified. Researchers noticed that stores impersonating different companies shared technical characteristics, leading them to follow digital breadcrumbs through publicly available website scans. The investigation eventually grew to include roughly 119,000 associated domains, a number that dwarfs previously known operations like BogusBazaar, which involved more than 75,000 domains.

While Nebty is careful to note that shared infrastructure does not prove that one person or organization controls every DoppelCart store, the technical overlap is undeniable. Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the confirmed shops shared identical build files and resolved to just 27 commerce backends. This centralization suggests a highly organized criminal enterprise rather than a loose collection of independent scammers.

The .shop Domain Epidemic

One of the most alarming aspects of this hacking campaign is its saturation of the .shop top-level domain. Nebty's September 2026 data included 118,787 distinct .shop domains linked to the cluster out of 4,361,908 .shop domains in the company's snapshot. That translates to roughly one out of every 37 .shop domains being part of this fraudulent network. While these numbers represent domains listed in the DNS zone rather than active storefronts at a single moment, the scale is a clear signal that attackers are leveraging cheap, low-trust TLDs to mass-produce malware and scam sites.

Why These Fake Stores Look So Convincing

The days when every scam website looked like a poorly coded Geocities page are over. DoppelCart sites are dangerous because they aggressively copy product catalogs from real companies, including descriptions, branding, and images. In some cases, researchers found fake stores loading assets directly from the legitimate company's servers. This creates a "hall of mirrors" effect where the page looks, feels, and even loads exactly like the real store.

Scheungraber says DoppelCart shops mimic 44,182 different brands, with a median of two clones for each brand. However, some brands received much more attention, with researchers finding more than 30 shops apiece targeting companies including SodaStream, Velasca, CurrentBody, and Daniel Wellington. These aren't random mom-and-pop shops; they are specific, trusted brands chosen to maximize consumer trust and transaction volume.

The Checkout Trap: Capturing Your Data

The real danger begins when you decide to check out. Nebty tested several checkout pages tied to the DoppelCart cluster and found code specifically designed to collect payment details, usernames, and passwords. According to the researchers, those fields—including your name, address, and credit card information—can be transmitted through WebSockets to command-and-control infrastructure in real time. This means an attacker may receive the information while you are still sitting on the checkout page, utilizing a technique similar to web skimming.

This is a specific and dangerous evolution of the fake shop threat. Many of us have been trained to see a verification code from our bank as an extra layer of protection. DoppelCart can potentially turn that security step against you by relaying the one-time confirmation code issued by your bank to the attackers. They may then use that code to bypass two-factor authentication and complete fraudulent transactions in your name. If a checkout page asks for a bank code, read the message carefully and verify the transaction details; if anything seems off, stop immediately.

Tactical Countermeasures: How to Spot a Fake Online Store

A professional-looking site no longer gives you enough information to decide whether a retailer deserves your trust. Here are the operational security (OpSec) steps you must take before entering any financial data:

1) Scrutinize the Web Address: Look at the domain in your browser before entering payment information. A fake site may use a recognizable company name inside a completely different domain (e.g., nike-shoes-discount.shop). Find the official website independently via a search engine. Also, don't let the padlock or HTTPS fool you—HTTPS only proves encryption, not legitimacy. Scammers encrypt websites too.

2) Question Extreme Discounts: A 65% discount can make you want to buy before the deal disappears. That's when you should slow down. If the price difference looks unusually large, investigate the seller. DoppelCart stores specifically advertise discounts up to 65% to trigger impulse clicks.

3) Verify the Contact Trail: Check the company's contact information. A cloned website can look impressive while having very little legitimate history behind it. Look beyond reviews displayed on the website itself; search for independent complaints or reports connecting the domain to scams. Be wary if the "customer support" email is a Gmail address or if the physical address is a P.O. box.

4) Use a Virtual Credit Card: The FTC recommends paying by credit card when possible because of the protections offered. Even better, many issuers allow you to use virtual card numbers for online purchases. This keeps your primary card number away from the merchant and lets you shut down the virtual number if something goes wrong.

5) Read Bank Messages Carefully: Don't treat a one-time verification code as a routine box to fill in. Read the message your bank sends. If the merchant or transaction looks unfamiliar, do not enter the code. Contact your card issuer through a trusted channel instead.

What to Do If You Are Already Compromised

If you suspect you've entered your card details into a DoppelCart site or another fake retailer, act fast. Contact your card issuer using the number on the back of your card or the official app immediately. Tell them you entered your information on a suspected fraudulent website and ask whether the card should be locked or replaced. Check your account for suspicious charges, and if you reused a password anywhere, change it immediately to a unique one using a password manager.

If you downloaded a file or installed software from the site, update your security software and run a scan with a reputable antivirus program. Finally, report suspected fraud to the Federal Trade Commission at ReportFraud.ftc.gov to help authorities identify these fraud patterns and dismantle the operation.

Conclusion

DoppelCart represents a critical evolution in the cybersecurity landscape, proving that cybercriminals are using aggressive scaling and advanced cloning techniques to bypass our traditional "look and feel" scam detectors. As security researchers work to take down these domains, the burden of vigilance is increasingly on the consumer. The next time you see a deal that seems too good to be true, remember the 119,000 fake shops waiting to harvest your data. A moment of skepticism is a small price to pay for your financial safety.