← News·MarketsMarkets

DoppelCart fake-shop cluster reaches 119,000 domains, researchers find

A fake-shopping operation called DoppelCart has been linked by cybersecurity firm Nebty to roughly 119,000 domains. The sites impersonate legitimate businesses and can steal payment details at checkout, including…

NM
NewsMV Markets Desk
3 min read
18 September 2026Markets desk
Share this dispatch

Key takeaways

  • Cybersecurity firm Nebty has linked a fake-shopping operation called DoppelCart to roughly 119,000 domains, with more than 105,000 stores active in its latest scans.
  • DoppelCart sites impersonate legitimate businesses and can steal payment details at checkout, including one-time bank verification codes, transmitting them via WebSockets to command-and-control infrastructure in real time.
  • Nebty found that 96% of confirmed DoppelCart shops shared identical build files and resolved to 27 commerce backends, and the cluster mimics 44,182 different brands.
  • Nebty's September 2026 snapshot captured 118,787 distinct .shop domains tied to the operation, or 2.72% (about one in 37) of the 4,361,908 .shop domains in the dataset.
  • Nebty published a searchable database of affected domains and received no response from the primary hosting provider or GMO Registry, operator of the .shop top-level domain.

A fake-shopping operation called DoppelCart has been linked by cybersecurity firm Nebty to roughly 119,000 domains. The sites impersonate legitimate businesses and can steal payment details at checkout, including one-time bank verification codes. More than 105,000 of those stores were active in Nebty's latest scans, and the company says the majority of the cluster remains online.

The operation's scale sets it apart from prior documented networks. Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of confirmed DoppelCart shops shared identical build files and resolved to 27 commerce backends, pointing to a shared technical foundation across the cluster. Nebty's September 2026 snapshot captured 118,787 distinct .shop domains tied to the operation out of 4,361,908 .shop domains in the dataset. That works out to 2.72%, or roughly one in every 37 domains in that particular scan. Nebty cautions the snapshot reflects domains listed in the .shop DNS zone and does not measure how many legitimate or fraudulent stores were operating at the same moment.

The cluster mimics 44,182 different brands, with a median of two clone stores per brand. Some companies drew heavier targeting. Researchers found more than 30 shops apiece impersonating SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS. Fake shops have advertised discounts as high as 65%. For comparison, a previously documented fake-shop operation called BogusBazaar involved more than 75,000 domains. Nebty says observation periods and counting methods differ between the two investigations, so direct comparison is limited.

How the checkout capture works

When a shopper enters payment details on a DoppelCart page, code on the site can transmit card numbers, billing addresses, and one-time bank verification codes through WebSockets to command-and-control infrastructure in real time. Researchers found that some fake stores load product images and descriptions directly from legitimate company servers, which is why the brand presentation can appear credible. Nebty says legitimate businesses have received customer complaints about orders those companies never processed.

Nebty has published a searchable database of affected domains at investigations.nebty-id.com/doppelcart. The company tried to contact the primary hosting provider associated with DoppelCart but received no response. GMO Registry, which operates the .shop top-level domain, did not respond to requests for comment before the reporting deadline. The Federal Trade Commission recommends using a credit card for online purchases and contacting the card issuer immediately if payment information was entered on a suspected fraudulent site.

Related reading

Categoryregulatory

Filed via foxnews.com

Keep reading

More from the markets desk

Frequently asked

How do DoppelCart fake shops steal payment information?

When a shopper enters payment details, code on the site transmits card numbers, billing addresses, and one-time bank verification codes through WebSockets to command-and-control infrastructure in real time.

Which brands were most heavily targeted by DoppelCart?

Researchers found more than 30 shops each impersonating SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS, out of 44,182 total brands mimicked.

How does DoppelCart compare to the earlier BogusBazaar operation?

BogusBazaar involved more than 75,000 domains compared to DoppelCart's roughly 119,000, but Nebty says observation periods and counting methods differ, so direct comparison is limited.

What can shoppers do to protect themselves from fraudulent shopping sites?

The Federal Trade Commission recommends using a credit card for online purchases and contacting the card issuer immediately if payment information was entered on a suspected fraudulent site.

Why do DoppelCart shops appear credible to shoppers?

Some fake stores load product images and descriptions directly from legitimate company servers, which makes the brand presentation appear authentic.