DoppelCart fraud network uses 119,000 fake shops to steal credit cards
Recorded: Sept. 8, 2026, 9:01 p.m.
| Original | Summarized |
DoppelCart fraud network uses 119,000 fake shops to steal credit cards News Featured Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Adobe fixes critical Magento zero-day exploited to backdoor servers ShinyHunters hackers claim breach of Florida "DAVID" DMV database August updates trigger 0xc0000409 errors on Windows Server 2016 DoppelCart fraud network uses 119,000 fake shops to steal credit cards The EU CRA's Real Question: What Shipped, and When Did You Know? Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Microsoft releases Windows 10 KB5122878 extended security update Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityDoppelCart fraud network uses 119,000 fake shops to steal credit cards DoppelCart fraud network uses 119,000 fake shops to steal credit cards By Bill Toulas September 8, 2026 A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. One of the fraudulent DoppelCart shopsSource: BleepingComputer Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Credit Card Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories OpenAI admits it didn't disclose rogue AI wiki hijacking incident BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain Sponsor Posts See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. CTI Starter Kit + 2026 SANS CTI Survey Unify ransomware protection and recovery for every client Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
A massive fraudulent operation known as DoppelCart utilizes over 119,000 domains to operate a network of counterfeit e-shops designed to steal payment card details. The German cybersecurity startup Nebty documented DoppelCart as the largest publicly cataloged fake-shop cluster based on domain count, significantly exceeding the second-largest cluster, BogusBazaar, which managed 75,000 sites and was linked to an estimated 850,000 fraudulent transactions. Current scans indicate that over 105,000 of these DoppelCart shops remain active. The impersonation strategy involves copying product catalogs, branding, descriptions, and images from legitimate businesses, sometimes pulling assets directly from the real company servers, mimicking thousands of brands with a median of two clones each. Certain brands, such as SodaStream, Daniel Wellington, and Dreame, were disproportionately targeted, with more than thirty fake shops associated with each brand; these sites often lure victims with substantial advertised discounts, sometimes reaching up to sixty-five percent. Upon testing the checkout procedures across the DoppelCart cluster, Nebty discovered that the checkout code is engineered to collect highly sensitive personal and financial information, including card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses. This data is transmitted in real time via WebSockets directly to the command-and-control infrastructure. Furthermore, the fraudulent system has the capability to relay one-time confirmation codes issued by victims’ banks, allowing attackers to potentially circumvent existing security protections. In an effort to further deceive victims, some fake stores display the legitimate support address of the impersonated brand, directing confused customers to contact the actual company. The report indicates that attempts by the company to engage the main hosting provider for these sites were unsuccessful. Separately, Nebty has established a searchable database intended to assist companies in identifying and remediating this type of impersonation and brand abuse. Additionally, the context surrounding credential security suggests that once attackers gain valid credentials, defenses weaken considerably, as only thirty-seven percent of their actions are successfully blocked; this principle is further illustrated by defense measures such as the Blue Report 2026, which assesses various defensive techniques across massive simulation environments. |