> Back to All Posts

DoppelCart Fake Shops: 119,000 Sites Stealing Card Data

DoppelCart fake shops

Online shopping fraud has outgrown the clumsy knockoff sites of a decade ago. Researchers have now mapped a network of more than 119,000 domains that sell nothing at all. DoppelCart fake shops make up the whole cluster, and they copy real brands closely. Most buyers never spot the difference. German security startup Nebty found the network and ranks it as the largest fake shop cluster ever mapped in public. More than 105,000 of those sites are still live.

A fraud network with 119,000 front doors

Nebty’s scans put the network at over 119,000 domains. Most of them sit on the .SHOP top-level domain. There, DoppelCart fake shops account for 2.72% of every site on the TLD. That one number shows how much of an address space a single crime crew can take over.

The old record holder, a cluster called BogusBazaar, ran about 75,000 sites. It logged an estimated 850,000 fraud transactions. DoppelCart passes it with room to spare.

Scale like this comes from code, not effort. Nebty CEO Benedikt Scheungraber said 96% of confirmed shops share the same build files. They also point back to just 27 shared backends. So the crew spins up new shops from a template and moves on. Takedowns barely dent the network, because a replacement costs almost nothing.

How DoppelCart fake shops mimic real brands

These sites do not invent products. They lift whole catalogs from real retailers instead, including text, photos, logos, and page layout. Some pull images straight from the brand’s own servers, so the cloned page loads real assets in real time.

Nebty counted 44,182 copied brands across the network, with a median of two clones each. However, a smaller group drew far more focus. SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS each had more than 30 clones running at once.

Pricing does the rest of the work. Many shops offer cuts of up to 65%. That is deep enough to tempt bargain hunters, but shallow enough to look real. Buyers click through, the checkout looks normal, and the trap closes.

What the checkout pages actually collect

Nebty tested checkout flows across the cluster and found skimming code waiting there. The scripts grab card numbers, expiry dates, and security codes. They also take names, email addresses, phone numbers, and home addresses.

The way that data travels matters as much as the list. Each field goes to a command-and-control server over WebSockets the moment a shopper types it. So quitting the checkout halfway protects nobody. The crew already holds whatever you entered.

One-time bank codes travel too

That same checkout code goes further. It can also relay the one-time code a bank sends during payment. That hands the crew a way around the extra check many shoppers treat as a safety net. Card data plus a live bank code is often enough for a charge to clear.

The complaints land on the wrong desk

Some clones show the copied brand’s genuine support address. Buyers who never get their order then contact the real company. That firm holds no record of the sale and cannot help. Real brands absorb the anger and the damage to their name, while the crew keeps the money.

Nebty tried to reach the main host behind DoppelCart but got no reply. The firm also built a searchable database, so brands can find shops copying them and act on what they find.

How to avoid DoppelCart fake shops while you shop

Visual checks no longer help much, because these pages are pixel copies of real ones. Good habits work better than instinct here.

  • Type brand addresses by hand or use a saved bookmark instead of following ads and social posts.
  • Read the domain closely. A .SHOP address for a brand you know at .com deserves a second look.
  • Treat a cut of more than 50% on current-season stock as a warning sign.
  • Pay with a virtual or single-use card number if your bank offers one.
  • Choose a credit card over a debit card, because chargeback rules protect you better.
  • Check the domain age with a WHOIS lookup. Most of these shops are only weeks old.
  • Two more habits help. Never reuse one card across new sites, and switch on instant alerts with your bank.

Where privacy tools fit in

A VPN cannot tell a real shop from a cloned one. Still, several providers bundle filters that block known scam and malware domains before the page loads. NordVPN ships Threat Protection, Surfshark includes CleanWeb, and Windscribe offers R.O.B.E.R.T. These tools pull from threat feeds, so a freshly flagged shop gets stopped at the DNS level.

Encryption solves a second problem. Shopping on public Wi-Fi leaks your traffic to anyone else on that network, and a VPN closes the gap. Neither feature replaces care at the checkout. Still, layers catch the mistakes that care alone misses.

Final Thoughts

The sheer size of this network changes the odds for normal shoppers. More than 105,000 shops are live, and the template spits out more on demand. So running into one of the DoppelCart fake shops takes no bad luck at all. One search for a cheap deal can lead you there.

Defence now rests on process, not gut feeling. Check the domain, use payment methods you can reverse, keep your filters on, and read your statements after any buy from a new site. Those habits cost a few seconds each, but they save a lot of trouble later.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.