Researchers found a massive network of nearly 119,000 look‑alike online stores that copy real retailers’ branding and product pages. These fake shops lure buyers with big discounts and then capture payment card details (and sometimes bank one‑time codes) during checkout, sending the data to attacker‑controlled servers in real time.
How the Attack Worked
Researchers uncovered a cluster of nearly 119,000 domains, almost all on .shop, tied to a scheme dubbed DoppelCart. These sites clone the catalogs, branding, and images of real retailers, in some cases even loading images directly from the legitimate companies' own infrastructure. The network mimics more than 44,000 brands, with some brands cloned across 30 or more separate fake shops. Despite the scale, the operation is technically simple: 96% of confirmed shops shared identical build files and relied on only 27 ecommerce backends, suggesting a repeatable template rather than bespoke development for each site.
Shoppers land on these sites through search results or ads promoting steep discounts, up to 65% off. The pressure to grab a deal before it disappears is the core social engineering hook. Once a shopper proceeds to checkout, the page collects card number, expiry date, CVV, and billing information, and in some cases also prompts for a bank one-time confirmation code. That data is sent to attacker-controlled servers over WebSockets in real time, meaning stolen details can be used almost immediately.
Why It Succeeded
The scheme succeeds because it exploits visual trust signals that shoppers rely on every day. A polished storefront, HTTPS padlock, authentic-looking product photos, and a familiar logo all suggest legitimacy, but none of these actually confirm a site is real. Combined with urgency from steep discounts, shoppers are pushed to act before scrutinizing the domain name, company details, or payment flow.
What to Watch For
- A discount that feels too large or too good to be true, especially on a well-known brand
- A web address that looks slightly off from the retailer's real domain
- A checkout process that asks for a bank one-time confirmation code, which legitimate merchants should never need
- Payment pages that feel rushed or pressure quick completion
Building Resistance
Anyone who shops online, including procurement, finance staff handling corporate cards, and executive assistants making purchases on behalf of leaders, should slow down before entering payment details on an unfamiliar site. Verify the web address carefully rather than relying on appearance alone. Treat unusually large discounts as a signal to double-check legitimacy first. Never share a one-time bank verification code with a retailer or anyone who contacts you unexpectedly. If a payment has already been made to a suspicious site, contact the card issuer immediately and preserve screenshots, order confirmations, web addresses, and any correspondence as evidence for dispute or investigation.
Key findings
- Nebty identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores (118,787 .shop domains).
- The operation clones legitimate retailers’ catalogs, branding, and images, sometimes loading images from the real companies’ infrastructure.
- BleepingComputer reports 96% of confirmed shops shared identical build files and used only 27 ecommerce backends.
- The network mimics more than 44,000 brands; some brands had 30+ cloned shops.
- Fake stores advertise steep discounts (up to 65%) to rush victims into buying.
- Checkout pages collect card data (card number, expiry, CVV, billing info) and may also capture bank one-time codes, transmitting data to attacker servers in real time via WebSockets.
Who’s being targeted
- Commonly targeted roles: All staff (personal and corporate online purchases), Procurement, Finance/AP (corporate card users), Executive assistants (often purchase on behalf of leaders).
- Affected industries: Retail/ecommerce, Consumer commerce (general public), Brands/merchants being impersonated.
- Attack channels: website.
- Impersonated: A legitimate retailer/brand (cloned store).
Red flags to watch for
- Unusually large discount used to rush a decision
- Domain/website is a look-alike clone of a real brand
- Checkout requests or captures a bank one-time code in a way that feels unusual
Frequently asked questions
What is DoppelCart?
DoppelCart is the name researchers at Nebty gave to a cluster of almost 119,000 domains linked to copied online stores that clone legitimate retailers' branding and product pages.
How do these fake stores steal payment information?
The fraudulent checkout pages collect card number, expiry, CVV, and billing details, and sometimes capture bank one-time codes, transmitting the data to attacker-controlled servers over WebSockets in real time.
How can shoppers tell a fake store from a real one?
A professional look, HTTPS, authentic product images, and a familiar logo do not prove a site is legitimate, so shoppers should check the web address carefully and be wary of unusually large discounts.
What should someone do if they already paid a fake store?
Contact your card issuer right away and save screenshots, order confirmations, web addresses, and correspondence as evidence.
Read the video transcript
You see your favorite brand with a “65% OFF – today only” banner. Looks real, right? It might be a DoppelCart fake shop. Researchers found about 119,000 of these cloned stores, DoppelCart copies real brands’ logos, catalogs, even images loaded from the real site, just to grab your card and bank one-time codes at checkout. Here’s the trap: the logo, padlock, and product photos all look perfect, but the web address is off, like brandname-sale.shop instead of the brand’s real .com, and the checkout oddly asks for a bank code. If a sale looks huge, pause. Before you pay, read the address bar and only enter card or bank codes on the brand’s exact, official domain you know is right.