DoppelCart Fake Shops Steal Payment Details

eSecurity Planet · Medium sophistication
Last updated September 11, 2026

Researchers uncovered a massive network of over 119,000 fake online stores that copy real brands to trick shoppers into entering payment details. The cloned sites look legitimate and use big discounts to create urgency, but the checkout pages capture card and personal data that criminals can reuse for fraud.

How the DoppelCart Attack Worked

DoppelCart is a large-scale fake-shopping operation identified by researchers as spanning more than 119,000 domains. Rather than targeting a single retailer, the operators built a network of cloned storefronts that copy branding, product catalogs, descriptions, and images from real brands. Researchers found 44,182 impersonated brands within the network, with some brands targeted far more heavily than others.

The cloned sites are built to feel routine. Visitors land on a page offering discounts of up to 65 percent, a familiar brand name, and a checkout flow that looks like any other online store. When a shopper enters payment information to complete a purchase, the fake checkout page captures card numbers, expiration dates, security codes, billing details, and in some cases bank-issued confirmation codes. Other collected data includes email addresses, phone numbers, and physical addresses. That data is then relayed to a command-and-control server via WebSockets, and if a victim runs into an issue, some fake sites redirect them to the real brand's actual support address, which can deepen the confusion about whether anything was wrong at all.

Why It Succeeds

The operation relies on a simple combination of pressure and familiarity: a steep discount creates urgency, a familiar brand creates trust, and a polished checkout page makes the purchase feel routine. Because the sites mimic legitimate retailers closely, including product images and descriptions, shoppers have little visual reason to doubt what they're seeing. The scale of the network, spread across tens of thousands of domains, also makes it harder for any single brand or shopper to recognize a pattern.

What to Watch For

  • Discounts that seem unusually generous compared to the retailer's normal pricing
  • A store domain that doesn't match the brand's official site
  • Checkout pages requesting unusually sensitive details, such as bank-issued confirmation codes
  • Arriving at a store through an ad or link rather than a direct search

Building Resistance

The most effective defense is simply slowing down before entering payment details. Shoppers should check the domain carefully, search for the retailer independently rather than clicking an ad, and compare pricing with other established sellers before trusting an unfamiliar checkout page. Employees making purchases on behalf of finance or procurement teams should apply the same scrutiny to corporate card purchases as they would to personal ones.

For retailers and brand owners, the takeaway extends beyond their own network security. Protecting customers also means actively watching for fake domains, cloned storefronts, and other signs that criminals are abusing their brand identity elsewhere on the web.

Key findings

  • Nebty identified a fake-shopping operation (“DoppelCart”) spanning more than 119,000 domains.
  • The fake shops mimic legitimate retailers by copying branding, product catalogs, descriptions, and images.
  • Checkout pages capture card numbers, expiration dates, security codes, billing details, and sometimes bank-issued confirmation codes.
  • Researchers identified 44,182 impersonated brands; some brands were impersonated far more frequently than others.
  • Victim data is relayed to a command-and-control server via WebSockets.
  • If a victim has an issue, the fake site may redirect them to the real brand’s support address to deepen confusion.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Procurement, E-commerce/Brand protection teams, Customer support teams.
  • Affected industries: Retail / e-commerce, Consumer goods / branded merchandise.
  • Attack channels: website.
  • Impersonated: Legitimate retailers/brands (cloned storefront).

Red flags to watch for

  • Unusually large discount meant to create urgency
  • Domain/storefront may not match the real brand’s official domain
  • Checkout asks for unusually sensitive details (e.g., bank-issued confirmation codes)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is DoppelCart?

DoppelCart is a fake-shopping operation identified by researchers that spans more than 119,000 domains, cloning legitimate retailers to trick shoppers at checkout.

What data do the fake DoppelCart sites steal?

The fake checkout pages capture card numbers, expiration dates, security codes, billing details, and sometimes bank-issued confirmation codes, along with email, phone, and physical addresses.

How can shoppers spot a DoppelCart-style fake store?

Watch for unusually generous discounts, domains that don't match the real brand's official site, and checkout forms asking for unusually sensitive details.

What can retailers do about brand-cloning scams like this?

Retailers and brand owners should actively monitor for fake domains and cloned storefronts abusing their brand, rather than focusing only on their own network defenses.

Read the video transcript

You see “discounts of up to 65%” on your favorite brand and a slick, familiar-looking online store. Behind that page might be DoppelCart, a fake-shopping network with over 119,000 cloned stores copying real brands and catalogs just to steal your card details. The checkout looks normal, but it quietly captures your card number, expiration, security code, billing details, even bank confirmation codes, then streams it off to a remote server. If a deal feels too good, stop and type the retailer’s name into your browser yourself, only enter payment details on the brand’s real domain.

Categories

Similar attacks

119,000 Fake Shops Clone Brands to Steal Cards

119,000 Fake Shops Clone Brands to Steal Cards

Researchers found a massive network of nearly 119,000 look‑alike online stores that copy real retailers’ branding and product pages. These fake shops lure buyers with big discounts and then capture payment card details (and sometimes bank one‑time codes) during checkout, sending the data to…

September 9, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Phishing Uses Google Links to Steal Microsoft Logins

Phishing Uses Google Links to Steal Microsoft Logins

Researchers reported an active, large-scale phishing campaign that starts with links hosted on legitimate Google services, then redirects victims to attacker-controlled sites. The final pages mimic Microsoft sign-in or “identity verification” flows to steal credentials/MFA codes or trick targets…

September 9, 2026
X Users Hit by Password Reset Email Flood

X Users Hit by Password Reset Email Flood

Users reported getting repeated, unsolicited password-reset emails from X after the launch of X Money. The emails appear legitimate, but attackers may be using them to confuse users and then send follow-up phishing messages that lead to fake X login pages to steal credentials. There is no confirmed…

September 3, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026