Researchers uncovered a massive network of over 119,000 fake online stores that copy real brands to trick shoppers into entering payment details. The cloned sites look legitimate and use big discounts to create urgency, but the checkout pages capture card and personal data that criminals can reuse for fraud.
How the DoppelCart Attack Worked
DoppelCart is a large-scale fake-shopping operation identified by researchers as spanning more than 119,000 domains. Rather than targeting a single retailer, the operators built a network of cloned storefronts that copy branding, product catalogs, descriptions, and images from real brands. Researchers found 44,182 impersonated brands within the network, with some brands targeted far more heavily than others.
The cloned sites are built to feel routine. Visitors land on a page offering discounts of up to 65 percent, a familiar brand name, and a checkout flow that looks like any other online store. When a shopper enters payment information to complete a purchase, the fake checkout page captures card numbers, expiration dates, security codes, billing details, and in some cases bank-issued confirmation codes. Other collected data includes email addresses, phone numbers, and physical addresses. That data is then relayed to a command-and-control server via WebSockets, and if a victim runs into an issue, some fake sites redirect them to the real brand's actual support address, which can deepen the confusion about whether anything was wrong at all.
Why It Succeeds
The operation relies on a simple combination of pressure and familiarity: a steep discount creates urgency, a familiar brand creates trust, and a polished checkout page makes the purchase feel routine. Because the sites mimic legitimate retailers closely, including product images and descriptions, shoppers have little visual reason to doubt what they're seeing. The scale of the network, spread across tens of thousands of domains, also makes it harder for any single brand or shopper to recognize a pattern.
What to Watch For
- Discounts that seem unusually generous compared to the retailer's normal pricing
- A store domain that doesn't match the brand's official site
- Checkout pages requesting unusually sensitive details, such as bank-issued confirmation codes
- Arriving at a store through an ad or link rather than a direct search
Building Resistance
The most effective defense is simply slowing down before entering payment details. Shoppers should check the domain carefully, search for the retailer independently rather than clicking an ad, and compare pricing with other established sellers before trusting an unfamiliar checkout page. Employees making purchases on behalf of finance or procurement teams should apply the same scrutiny to corporate card purchases as they would to personal ones.
For retailers and brand owners, the takeaway extends beyond their own network security. Protecting customers also means actively watching for fake domains, cloned storefronts, and other signs that criminals are abusing their brand identity elsewhere on the web.
Key findings
- Nebty identified a fake-shopping operation (“DoppelCart”) spanning more than 119,000 domains.
- The fake shops mimic legitimate retailers by copying branding, product catalogs, descriptions, and images.
- Checkout pages capture card numbers, expiration dates, security codes, billing details, and sometimes bank-issued confirmation codes.
- Researchers identified 44,182 impersonated brands; some brands were impersonated far more frequently than others.
- Victim data is relayed to a command-and-control server via WebSockets.
- If a victim has an issue, the fake site may redirect them to the real brand’s support address to deepen confusion.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Procurement, E-commerce/Brand protection teams, Customer support teams.
- Affected industries: Retail / e-commerce, Consumer goods / branded merchandise.
- Attack channels: website.
- Impersonated: Legitimate retailers/brands (cloned storefront).
Red flags to watch for
- Unusually large discount meant to create urgency
- Domain/storefront may not match the real brand’s official domain
- Checkout asks for unusually sensitive details (e.g., bank-issued confirmation codes)
Frequently asked questions
What is DoppelCart?
DoppelCart is a fake-shopping operation identified by researchers that spans more than 119,000 domains, cloning legitimate retailers to trick shoppers at checkout.
What data do the fake DoppelCart sites steal?
The fake checkout pages capture card numbers, expiration dates, security codes, billing details, and sometimes bank-issued confirmation codes, along with email, phone, and physical addresses.
How can shoppers spot a DoppelCart-style fake store?
Watch for unusually generous discounts, domains that don't match the real brand's official site, and checkout forms asking for unusually sensitive details.
What can retailers do about brand-cloning scams like this?
Retailers and brand owners should actively monitor for fake domains and cloned storefronts abusing their brand, rather than focusing only on their own network defenses.
Read the video transcript
You see “discounts of up to 65%” on your favorite brand and a slick, familiar-looking online store. Behind that page might be DoppelCart, a fake-shopping network with over 119,000 cloned stores copying real brands and catalogs just to steal your card details. The checkout looks normal, but it quietly captures your card number, expiration, security code, billing details, even bank confirmation codes, then streams it off to a remote server. If a deal feels too good, stop and type the retailer’s name into your browser yourself, only enter payment details on the brand’s real domain.