Core Memo

Memorandum

To
Anyone who needs the day in one page
Date
September 18, 2026

Memorandum

From
Delaney Sawyer via FOX News
Date
Filed
News·5 min to read
Re

119,000 Fake Shops Tied to DoppelCart Could Steal Card Details at Checkout

Re119,000 Fake Shops Tied to DoppelCart Could Steal Card Details at Checkout

Cybersecurity firm Nebty has linked roughly 119,000 domains to a fake shopping network called DoppelCart that impersonates legitimate brands and can capture payment data, including one-time bank verification codes, as shoppers check out.

A sprawling network of fake online storefronts is impersonating legitimate brands and harvesting payment information from shoppers at checkout, according to cybersecurity researchers who have tied roughly 119,000 domains to an operation they call DoppelCart.

The sites are designed to look polished and familiar, often copying product catalogs, descriptions and branding from real companies. In some cases, researchers found the fake stores loading assets directly from the legitimate business's servers, making the deception harder to spot. The result is a checkout page that may look trustworthy even though it is controlled by criminals.

Nebty, the security company that identified the cluster, says more than 105,000 DoppelCart shops were active in its latest scans, and that the majority of the network remains online. The company discovered the operation while investigating fake shops that had targeted several of its own customers. Researchers noticed that stores impersonating different companies shared technical characteristics, then followed those connections through publicly available website scans until the investigation grew to about 119,000 associated domains.

Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the confirmed shops shared identical build files and resolved to 27 commerce backends. Most of the domains connected to DoppelCart use the.shop top-level domain. In September 2026 data, Nebty counted 118,787 distinct.shop domains linked to the cluster out of 4,361,908.shop domains in its snapshot — about 2.72%, or roughly one out of every 37 domains in that data set.

That figure comes with caveats. Nebty says the snapshot represents domains listed in the.shop DNS zone and does not show how many legitimate or fraudulent stores were operating at the same moment. The company also cautions that shared infrastructure does not prove a single person or organization controls every DoppelCart store. Even so, the technical overlap is striking.

The scale is notable when compared with earlier fake-shop operations. Researchers previously documented BogusBazaar, a network involving more than 75,000 domains. Nebty notes that observation periods and counting methods differ between investigations, so the two numbers are not perfectly comparable. Still, the company says DoppelCart represents the largest publicly documented fake-shop cluster when measured by associated domains.

DoppelCart shops mimic 44,182 different brands, with a median of two clones for each brand, according to Scheungraber. Some brands received far more attention. Researchers found more than 30 shops apiece targeting companies including SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS.

The scam often leans on steep discounts to lure shoppers. Researchers found fake shops advertising price cuts as high as 65%. A large discount alone does not prove a site is fraudulent, since real retailers run clearance sales regularly. But when an unfamiliar store beats every other seller by a wide margin, that is a signal to check who is actually behind the checkout page.

The most serious risk begins when a shopper decides to buy. Nebty tested several checkout pages tied to the DoppelCart cluster and found code collecting payment details. According to the researchers, those fields can be transmitted through WebSockets to command-and-control infrastructure in real time, meaning an attacker may receive the information while the shopper is still on the checkout page. The technique has similarities to web skimming, in which malicious code captures payment information as it is typed into an online checkout form.

Nebty also found that the checkout code can relay the one-time confirmation code issued by a victim's bank. Attackers may then try to use that code to get past protections surrounding a fraudulent transaction. That turns a security step many shoppers have been trained to trust into a potential liability. Consumers should not automatically enter a bank verification code simply because a checkout page asks for it, and should read the bank's message carefully before responding.

The sophistication of the sites marks a shift from the days when scam pages were obviously thrown together. Because much of the material on DoppelCart stores comes from the real business in the first place, shoppers may recognize the brand, see plausible products and find nothing on the page that immediately signals fraud. Nebty says the majority of the cluster remains online, leaving consumers to rely on their own scrutiny of unfamiliar retailers.

Delaney Sawyer

Author

Society Reporter

Delaney Sawyer covers public affairs, politics, business, culture and daily news for Core Memo. The role focuses on verification, context, and clear explanations for readers.

Encl.More under News