Scams & Phishing News More than 100,000 fake stores are out to steal your card details

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,119
6,100
2,168
Germany
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.

The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.

The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.

As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.

BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.

The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.

“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”
Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.

The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.

Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.
 
Last edited by a moderator:


Hi, this is a useful warning because these shops are built to look ordinary right through checkout. The practical lesson is not that every .shop site is fraudulent, but that a polished design, HTTPS padlock, familiar product photos, or even a successful bank verification prompt does not establish that the merchant is genuine.

What shoppers should check​

Before entering payment details:

  1. Navigate to the retailer independently. Use a saved bookmark, official app, or manually verified address rather than a social-media advertisement or unusually cheap search result.
  2. Inspect the exact domain. Extra words, odd hyphens, misspellings, and a brand name placed elsewhere in the address are warning signs. The TLD alone neither proves nor disproves fraud.
  3. Check the business identity. Compare the company name, physical address, contact details, returns policy, and domain with the brand’s established site. Copied legal pages are common, so merely having an imprint or policy page proves little.
  4. Treat extreme discounts and countdown pressure as risk signals. They are not proof by themselves, but they justify stopping and checking elsewhere.
  5. Do not approve an unexpected banking request. Read the amount and merchant shown by the bank. An authentication code or approval confirms a transaction; it does not certify the shop as legitimate.

If card details were already entered​

Contact the card issuer through the number on the card or its official app and explain that the details were submitted to a suspected fake merchant. Ask whether the card should be frozen or replaced, and review pending and completed transactions. Do not rely on the absence of an immediate charge: stolen card data may be used later.

If a one-time code or in-app approval was also supplied, say so explicitly and mention any amount or merchant name displayed. That raises the urgency because it may have authorized a transaction in real time.

Also save the domain, order page, confirmation messages, transaction information, and screenshots before the site disappears. Avoid sending full card numbers or authentication codes in a public report. If an account password was created and reused elsewhere, change it on those other services and enable MFA.

One important limit of the report​

The quoted figures and checkout details are attributed to the linked reporting, but no primary-source evidence is included here to verify them independently. The wording already makes an important distinction: shared infrastructure and identical build files can identify a coordinated cluster, but do not by themselves prove that every domain belongs to one known operator.

Likewise, the reported concentration under .shop should not become “.shop equals scam.” Criminals use many TLDs, and legitimate sellers use .shop. Domain reputation is a clue; merchant verification is the decision point.