LmCast :: Stay tuned in

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

Recorded: Sept. 8, 2026, 9:01 p.m.

Original Summarized

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

News

Featured
Latest

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Adobe fixes critical Magento zero-day exploited to backdoor servers

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

August updates trigger 0xc0000409 errors on Windows Server 2016

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

The EU CRA's Real Question: What Shipped, and When Did You Know?

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Microsoft releases Windows 10 KB5122878 extended security update

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityDoppelCart fraud network uses 119,000 fake shops to steal credit cards

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

By Bill Toulas

September 8, 2026
04:35 PM
0

A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.
German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, “BogusBazaar,” which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.
The company's latest scans show that more than 105,000 DoppelCart shops are still active.
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends.
The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes loading assets directly from the real company’s servers.
Scheungraber says that the shops mimic 44,182 different brands, with a median of two clones for each.
However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.
The fake sites advertise big discounts of up to 65% in many cases to lure bargain-hunting shoppers.

One of the fraudulent DoppelCart shopsSource: BleepingComputer
When testing several checkout pages in the DoppelCart cluster, Nebty found code that collected sensitive information related to payment cards and their holders:
Card numbers
Expiration dates
Security codes
Cardholder names
Email addresses
Phone numbers
Physical addresses
Each data field is transmitted over WebSockets to the command-and-control (C2) in real time, Netby says in a report shared with BleepingComputer.
The checkout code can also relay the one-time confirmation code issued by a victim’s bank, which the attackers may use to bypass security protections.
Nebty says some of the fake stores show the impersonated brand’s legitimate support address, leading victims who didn’t receive their purchases to contact the real company.
Scheungraber says that the company tried to contact the main hosting provider for DoppelCart sites but received no response.
Separately, Nebty created a searchable database to help companies identify DoppelCart impersonation and brand abuse and take appropriate action to protect themselves.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Android malware combo takes out loans and relays victims' credit cardsInside the Search for "Clean" Residential Proxies for CardingAdobe fixes critical Magento zero-day exploited to backdoor serversMagento StyleSmuggler zero-day exploited to deploy Linux backdoorWhy Even the Best Edge Security Still Misses High-Risk Sessions

Credit Card
DoppelCart
E-Commerce
Fraud
Payment card
Shop

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Sponsor Posts

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

CTI Starter Kit + 2026 SANS CTI Survey

Unify ransomware protection and recovery for every client

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A massive fraudulent operation known as DoppelCart utilizes over 119,000 domains to operate a network of counterfeit e-shops designed to steal payment card details. The German cybersecurity startup Nebty documented DoppelCart as the largest publicly cataloged fake-shop cluster based on domain count, significantly exceeding the second-largest cluster, BogusBazaar, which managed 75,000 sites and was linked to an estimated 850,000 fraudulent transactions. Current scans indicate that over 105,000 of these DoppelCart shops remain active. The impersonation strategy involves copying product catalogs, branding, descriptions, and images from legitimate businesses, sometimes pulling assets directly from the real company servers, mimicking thousands of brands with a median of two clones each. Certain brands, such as SodaStream, Daniel Wellington, and Dreame, were disproportionately targeted, with more than thirty fake shops associated with each brand; these sites often lure victims with substantial advertised discounts, sometimes reaching up to sixty-five percent. Upon testing the checkout procedures across the DoppelCart cluster, Nebty discovered that the checkout code is engineered to collect highly sensitive personal and financial information, including card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses. This data is transmitted in real time via WebSockets directly to the command-and-control infrastructure. Furthermore, the fraudulent system has the capability to relay one-time confirmation codes issued by victims’ banks, allowing attackers to potentially circumvent existing security protections. In an effort to further deceive victims, some fake stores display the legitimate support address of the impersonated brand, directing confused customers to contact the actual company. The report indicates that attempts by the company to engage the main hosting provider for these sites were unsuccessful. Separately, Nebty has established a searchable database intended to assist companies in identifying and remediating this type of impersonation and brand abuse. Additionally, the context surrounding credential security suggests that once attackers gain valid credentials, defenses weaken considerably, as only thirty-seven percent of their actions are successfully blocked; this principle is further illustrated by defense measures such as the Blue Report 2026, which assesses various defensive techniques across massive simulation environments.