119,000 Fake Shops Clone Brands to Steal Cards

Malwarebytes · Medium sophistication
Last updated September 10, 2026

Researchers found a massive network of nearly 119,000 look‑alike online stores that copy real retailers’ branding and product pages. These fake shops lure buyers with big discounts and then capture payment card details (and sometimes bank one‑time codes) during checkout, sending the data to attacker‑controlled servers in real time.

How the Attack Worked

Researchers uncovered a cluster of nearly 119,000 domains, almost all on .shop, tied to a scheme dubbed DoppelCart. These sites clone the catalogs, branding, and images of real retailers, in some cases even loading images directly from the legitimate companies' own infrastructure. The network mimics more than 44,000 brands, with some brands cloned across 30 or more separate fake shops. Despite the scale, the operation is technically simple: 96% of confirmed shops shared identical build files and relied on only 27 ecommerce backends, suggesting a repeatable template rather than bespoke development for each site.

Shoppers land on these sites through search results or ads promoting steep discounts, up to 65% off. The pressure to grab a deal before it disappears is the core social engineering hook. Once a shopper proceeds to checkout, the page collects card number, expiry date, CVV, and billing information, and in some cases also prompts for a bank one-time confirmation code. That data is sent to attacker-controlled servers over WebSockets in real time, meaning stolen details can be used almost immediately.

Why It Succeeded

The scheme succeeds because it exploits visual trust signals that shoppers rely on every day. A polished storefront, HTTPS padlock, authentic-looking product photos, and a familiar logo all suggest legitimacy, but none of these actually confirm a site is real. Combined with urgency from steep discounts, shoppers are pushed to act before scrutinizing the domain name, company details, or payment flow.

What to Watch For

  • A discount that feels too large or too good to be true, especially on a well-known brand
  • A web address that looks slightly off from the retailer's real domain
  • A checkout process that asks for a bank one-time confirmation code, which legitimate merchants should never need
  • Payment pages that feel rushed or pressure quick completion

Building Resistance

Anyone who shops online, including procurement, finance staff handling corporate cards, and executive assistants making purchases on behalf of leaders, should slow down before entering payment details on an unfamiliar site. Verify the web address carefully rather than relying on appearance alone. Treat unusually large discounts as a signal to double-check legitimacy first. Never share a one-time bank verification code with a retailer or anyone who contacts you unexpectedly. If a payment has already been made to a suspicious site, contact the card issuer immediately and preserve screenshots, order confirmations, web addresses, and any correspondence as evidence for dispute or investigation.

Key findings

  • Nebty identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores (118,787 .shop domains).
  • The operation clones legitimate retailers’ catalogs, branding, and images, sometimes loading images from the real companies’ infrastructure.
  • BleepingComputer reports 96% of confirmed shops shared identical build files and used only 27 ecommerce backends.
  • The network mimics more than 44,000 brands; some brands had 30+ cloned shops.
  • Fake stores advertise steep discounts (up to 65%) to rush victims into buying.
  • Checkout pages collect card data (card number, expiry, CVV, billing info) and may also capture bank one-time codes, transmitting data to attacker servers in real time via WebSockets.

Who’s being targeted

  • Commonly targeted roles: All staff (personal and corporate online purchases), Procurement, Finance/AP (corporate card users), Executive assistants (often purchase on behalf of leaders).
  • Affected industries: Retail/ecommerce, Consumer commerce (general public), Brands/merchants being impersonated.
  • Attack channels: website.
  • Impersonated: A legitimate retailer/brand (cloned store).

Red flags to watch for

  • Unusually large discount used to rush a decision
  • Domain/website is a look-alike clone of a real brand
  • Checkout requests or captures a bank one-time code in a way that feels unusual
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is DoppelCart?

DoppelCart is the name researchers at Nebty gave to a cluster of almost 119,000 domains linked to copied online stores that clone legitimate retailers' branding and product pages.

How do these fake stores steal payment information?

The fraudulent checkout pages collect card number, expiry, CVV, and billing details, and sometimes capture bank one-time codes, transmitting the data to attacker-controlled servers over WebSockets in real time.

How can shoppers tell a fake store from a real one?

A professional look, HTTPS, authentic product images, and a familiar logo do not prove a site is legitimate, so shoppers should check the web address carefully and be wary of unusually large discounts.

What should someone do if they already paid a fake store?

Contact your card issuer right away and save screenshots, order confirmations, web addresses, and correspondence as evidence.

Read the video transcript

You see your favorite brand with a “65% OFF – today only” banner. Looks real, right? It might be a DoppelCart fake shop. Researchers found about 119,000 of these cloned stores, DoppelCart copies real brands’ logos, catalogs, even images loaded from the real site, just to grab your card and bank one-time codes at checkout. Here’s the trap: the logo, padlock, and product photos all look perfect, but the web address is off, like brandname-sale.shop instead of the brand’s real .com, and the checkout oddly asks for a bank code. If a sale looks huge, pause. Before you pay, read the address bar and only enter card or bank codes on the brand’s exact, official domain you know is right.

Categories

Similar attacks

Deepfake Catfish Scam Hits OnlyFans Fans

Deepfake Catfish Scam Hits OnlyFans Fans

Criminals are impersonating OnlyFans creators using AI-generated deepfake videos and cloned voices to trick fans into paying for “exclusive” chats or content. The scam typically starts on TikTok, moves victims into direct messages on Snapchat, then pushes instant Cash App payments, after which the…

August 6, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how…

July 29, 2026
Fake $149.99 Apple/Amazon Charge Popup Scam

Fake $149.99 Apple/Amazon Charge Popup Scam

A scam campaign uses full-screen browser popups impersonating Apple Support or Amazon to claim an “unauthorized” $149.99 charge and pressure victims to call a phone number. Callers reach a live scammer posing as support who tries to gain remote access or steal payment/account details, sometimes…

August 6, 2026
TikTok Resin Art “DM to Order” Scam

TikTok Resin Art “DM to Order” Scam

Scammers on TikTok are impersonating resin artists by reposting stolen videos and telling viewers to “DM to order.” After moving the conversation into direct messages (and sometimes off-platform), they request deposits or full payment and then disappear, or they try to extract personal/banking…

July 24, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Fake “Support” Listing Pushes Tech Scam Calls

Fake “Support” Listing Pushes Tech Scam Calls

A fake “Malwarebytes Support” listing was found on BuzzFeed, apparently designed to trick people into calling a scam phone number. The likely goal is to socially engineer callers into granting remote access and/or paying for bogus support, using the credibility of a trusted platform and well-known…

August 27, 2026