A shopping site can look perfect and still be nothing more than a card-stealing copy. The products are real, the photos are familiar, and the checkout may look more polished than the store you meant to visit.
DoppelCart makes that problem difficult to dismiss as a handful of obvious fake shops. Researchers connected nearly 119,000 domains to the same broad cluster, with tens of thousands of real brands copied across the network.
The danger is not limited to receiving a poor-quality product. Some of these storefronts are built to capture card details and one-time bank codes while the victim believes an ordinary online purchase is being completed.

Overview
The network copies real stores at enormous scale
Security company Nebty identified a cluster it calls DoppelCart. Its September 2026 data contained 119,012 confirmed domain entries, which became 118,996 unique domains after addresses with and without “www” were combined.
Of those, 118,787 used the .shop suffix. That represented 2.72% of the .shop domain population examined by the researchers, an extraordinary concentration for one documented fake-store cluster.
The storefronts borrow products, branding, and images
DoppelCart sites copy legitimate retailers’ catalogs, product descriptions, brand names, and photographs. Some even load product images directly from the real seller’s infrastructure, so the pictures a shopper recognizes may genuinely come from that brand.
The copied content creates a false shortcut in the shopper’s reasoning. The product exists and the photograph is authentic, but neither fact proves that the website taking the order is connected to the real retailer.
The checkout targets cards and bank confirmation codes
Researchers found fraudulent checkout pages sending cardholder information to attacker-controlled systems in real time. The requested data can include the card number, expiration date, CVV, billing details, and a one-time confirmation code from the bank.
A one-time code is especially dangerous because it may authorize a transaction while the victim is still waiting for the fake store to confirm the order. The site can appear to be processing the purchase as criminals use the information elsewhere.
- DoppelCart is linked to almost 119,000 domains.
- The cluster includes 118,787 distinct .shop domains.
- Researchers identified more than 44,000 impersonated brands.
- The typical brand had two cloned stores, while some had more than 30.
- Advertised discounts reached as high as 65%.
- Confirmed shops shared common build files and a small set of backends.
- Checkout pages can collect card data and one-time bank codes.
- Shared infrastructure does not prove that one person operates every domain.
Why These Fake Stores Look So Convincing
A traditional scam shop might use blurry pictures, broken English, and an empty catalog. A cloned store begins with material taken from a real business, so it inherits professional photography, detailed descriptions, realistic prices, and familiar product names.
The design does not need to be invented from scratch. Templates and automated deployment tools can reproduce the same storefront under thousands of domains, then switch brand names and product feeds with relatively little work.
Large discounts supply the urgency. A 65% reduction can be explained as a clearance sale, warehouse closing, seasonal promotion, or limited-time outlet event. Shoppers who fear missing the price may skip the slow checks they normally perform.

HTTPS adds another layer of misplaced confidence. Most modern websites, including fraudulent ones, can obtain a valid certificate automatically. The padlock confirms that traffic is encrypted; it does not confirm who runs the shop or whether an order will be honored.
Social media ads and sponsored search results can place a clone in front of people already looking for the product. The shopper may never compare the address with the brand’s official domain because the advertisement appears to have done that verification for them.
The scale also helps the operation survive. Takedown of one store does little when thousands of related domains exist. A blocked domain can be replaced by another copy using the same catalog and checkout.
Company, Address, and Fulfillment Checks
The domain does not match the retailer
A cloned store may combine a brand name with words such as outlet, clearance, official, shop, or sale. The result can look plausible while remaining completely separate from the retailer’s known website.
Read the address from right to left and identify the registered domain. Extra words before it are only subdomains, and familiar words joined with hyphens do not create a relationship with the brand.
The company details are copied, vague, or inconsistent
Fake shops often reuse an address, privacy policy, or returns page from another site. The footer may name one company while the contact page names another, or the address may belong to an unrelated residence, mailbox, or legitimate business.
Search the exact company name, address, phone number, and support email independently. A real-looking legal paragraph has little value if it was copied from somewhere else.
The checkout asks for more than an ordinary order needs
A request for the card number and billing address may look normal. A demand for a banking login, card PIN, security answers, or a one-time code entered directly into the merchant page is a much stronger warning.
Read the bank’s verification message carefully. It should state the merchant and amount being authorized. Never type a code if those details differ from the purchase you intended to make.
Independent research ties the sites to shared infrastructure
Nebty published the underlying DoppelCart investigation and explained how domains were connected through website and infrastructure characteristics. The researchers are careful not to claim that every site was simultaneously active or controlled by one identified operator.
Malwarebytes summarized the shopper-facing risk, including card capture and one-time confirmation code theft. Together, the findings support a documented fake-shop ecosystem rather than a complaint about a legitimate retailer.
How the DoppelCart Fake Store Scam Works
Step 1: The operation creates or acquires large numbers of domains
The network relies on a huge inventory of web addresses, particularly under .shop. Domains can be assigned to different copied brands, parked until needed, or replaced when a browser, host, or security provider blocks them.
Volume changes the economics. Each individual store does not need to remain online for years. It only needs to attract enough shoppers before complaints and takedowns catch up.
Step 2: A legitimate retailer’s catalog is copied
Product names, descriptions, sizes, prices, and photographs are taken from real stores. A clone may even request images from the original retailer’s server rather than hosting its own copies.
That makes reverse image searches less decisive. The picture can be genuine while the seller is fraudulent. The website address and company behind the checkout deserve more attention than the catalog image.
Step 3: Ads and steep discounts bring shoppers in
The cloned store can be promoted through social media, search advertising, spam, or compromised accounts. Discounts of up to 65% create a reason to click now instead of finding the brand through its official channels.
Some visitors arrive through ordinary search results after looking for a specific product. Matching product language helps the fake pages appear relevant and professional.

Step 4: The checkout collects cardholder information
The victim adds a real product to a cart and enters shipping and billing details. The checkout then requests the card number, expiration date, and CVV, just as a legitimate shop would.
The difference is where the data goes. In confirmed DoppelCart shops, the information was transmitted to attacker-controlled infrastructure rather than processed solely for a genuine retail order.
Step 5: A bank code may be captured in real time
The fake checkout can ask for a one-time confirmation code sent by the victim’s bank. While the victim sees a loading message, the criminals can attempt another card transaction and use the submitted code to complete it.
This step can make a fraudulent charge appear to have passed the bank’s normal security check. The victim supplied the code, but the transaction being authorized may not match the fake store order.
Step 6: The store disappears or sends meaningless updates
After payment, the page may show a confirmation number, send a copied receipt, or claim that the order is being prepared. No real inventory needs to exist behind those screens.
The victim may receive nothing, a worthless item, or repeated shipping excuses. Meanwhile, the payment data can be used, sold, or combined with the captured contact and address information for additional fraud.
How to Check an Unfamiliar Store Before Paying
Start with the exact domain, not the store name displayed in the header. Search that full address in quotation marks and add words such as scam, reviews, returns, and contact. A brand may have a good reputation while the copycat domain has none.
Find the retailer through a saved bookmark, official social profile, or manufacturer-authorized seller list. Compare the official domain, price, catalog, contact details, and sale language with the site you found.
Check when the domain was registered and whether the company has a consistent history. A new domain is not automatically fraudulent, but a brand outlet claiming years of experience should not have appeared last week.
Read the returns page closely. Look for a real return address, clear time limits, who pays shipping, and a support channel on the same domain. Copied policies often mention a different store or legal jurisdiction.
Use a credit card or payment service with buyer protection when the seller is unfamiliar. Avoid bank transfers, cryptocurrency, gift cards, and debit methods that provide weaker recovery options.
Warning Signs of a DoppelCart-Style Store
- The domain is a variation of a known brand rather than its official address.
- Nearly every product is marked down by the same dramatic percentage.
- A countdown or stock warning resets when the page is refreshed.
- Contact details are missing, copied, or unrelated to the displayed company.
- The returns policy names another website or sends returns overseas unexpectedly.
- The store asks for a one-time bank code inside its own checkout form.
- The bank alert shows a different merchant or amount.
- Social media links are decorative, broken, or lead to empty profiles.
- The domain is new despite claims of a long retail history.
- The only payment options are difficult to reverse.
A single clue may have an innocent explanation. Several of them together are a reason to abandon the purchase and locate the retailer independently.
What to Do if You Have Fallen Victim to This Scam
- Contact the card issuer now. Explain that the card details were entered into a suspected fake shop. Ask whether the card should be frozen or replaced and whether pending charges can be stopped.
- Report any mismatched verification. Tell the bank if a one-time code was entered or approved. Provide the merchant and amount shown in the bank’s message if you saved it.
- Dispute the transaction. Do not wait indefinitely for shipping promises. Ask the issuer about the deadline and evidence needed for a chargeback or fraud claim.
- Change reused passwords. If the store account used a password found anywhere else, change those accounts, beginning with email and financial services.
- Watch for follow-up scams. Criminals may impersonate the bank, courier, or fraud department using details from the order. End the call and contact the organization through its official number.
- Preserve the evidence. Save the domain, product page, checkout screenshots, confirmation email, bank messages, receipts, and correspondence before the site disappears.
- Report the domain and advertisement. Notify the impersonated retailer, the advertising platform, the hosting provider, and the appropriate consumer protection or cybercrime authority.
- Scan if anything was downloaded. Malwarebytes can check installers or files received from the store. AdGuard can block known fraudulent pages and malicious ads, but it cannot cancel a card transaction.
- Monitor identity misuse. If the checkout collected extensive personal information, review credit reports and consider a fraud alert or credit freeze where available.
Frequently Asked Questions
Is every .shop website part of DoppelCart?
No. The suffix is used by legitimate and fraudulent businesses. DoppelCart refers to domains connected by specific shared website and infrastructure characteristics, not every .shop address.
Are all 119,000 domains active stores?
No. Nebty states that the count covers domains associated with the cluster and does not mean every site was reachable or active at the same time.
Does authentic product photography prove the store is real?
No. Cloned stores copy images from legitimate retailers and may load them directly from the original company’s server. Verify the seller and domain separately.
Why would a fake checkout ask for a bank code?
The criminals may be attempting a card transaction in real time. The code can help authorize that transaction, even when it differs from the order shown on screen.
Will I always receive nothing?
Outcomes vary. A victim may receive nothing, a low-value item, or only fake tracking updates. The confirmed risk is that sensitive payment data is collected by fraudulent infrastructure.
Can HTTPS make a fake store safe?
No. HTTPS encrypts the connection to the domain. It does not verify the seller’s identity, inventory, return policy, or intention to protect card data.
The Bottom Line
DoppelCart shows why a polished storefront is no longer meaningful evidence of a real seller. A fake shop can borrow genuine products, photographs, and branding while sending the checkout data somewhere entirely different.
Verify the exact domain, company, and payment request before entering a card. If a merchant page asks for a bank code, compare the bank’s message with the order and stop at the first mismatch.
If you already paid, contact the issuer immediately. The faster the card is protected and the transaction is challenged, the better the chance of limiting the damage.