← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

DoppelCart Fraud Network Uses 119,000 Fake Shops to Steal Credit Card Data

🔄 Updated 12h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DoppelCart operates 119,000 fake e-shops, with 105,000 currently active.
  • Sites mimic 44,182 brands, copying product catalogs and branding.
  • Collects card numbers, expiration dates, security codes, and personal info.
  • Data is transmitted via WebSockets to C2 servers in real time.

Massive Fake Shop Operation Discovered

German cybersecurity startup Nebty identified "DoppelCart," a large-scale fraud operation utilizing over 119,000 domains to host fake e-commerce shops. This network is described as the largest publicly documented fake-shop cluster by domain count, exceeding previous operations like "BogusBazaar."

The majority of these domains are within the .SHOP top-level domain, representing 2.72% of all sites on that TLD. Nebty's latest scans indicate that more than 105,000 DoppelCart shops remain active.

Impersonation Tactics and Data Theft

DoppelCart shops impersonate 44,182 different brands by replicating product catalogs, descriptions, branding, and images, sometimes loading assets directly from legitimate company servers. Some brands, including SodaStream and Daniel Wellington, have over 30 cloned shops.

The fake sites attract shoppers with advertised discounts of up to 65%. During checkout, the sites collect sensitive payment card information, including card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses. This data is transmitted in real time via WebSockets to command-and-control servers.

Bypassing Security and Victim Impact

The checkout code can also relay one-time confirmation codes issued by banks, potentially allowing attackers to bypass security measures. Victims who do not receive their purchases may contact the legitimate companies, as some fake stores display the impersonated brand’s actual support address.

Nebty attempted to contact the main hosting provider for DoppelCart sites but received no response. The company has created a searchable database to assist brands in identifying and addressing DoppelCart impersonation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A network named "DoppelCart" operates over 119,000 fake e-commerce sites to steal payment card details from shoppers. The sites impersonate legitimate brands and offer large discounts to lure victims, transmitting collected data in real time to command-and-control servers.