Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

0
High
News
Published: 09/08/2026 (09/08/2026, 20:35:14 UTC)
Source: Bleeping Computer

Description

The DoppelCart fraud network operates over 119,000 fake e-commerce shops, primarily in the .SHOP domain, to steal payment card details. These fake shops impersonate legitimate brands by copying their catalogs, branding, and images, often offering large discounts to lure victims. The checkout pages collect sensitive payment information including card numbers, expiration dates, security codes, cardholder names, and even one-time bank confirmation codes, transmitting this data in real time to attackers. Over 105,000 of these fake shops remain active, making DoppelCart the largest publicly documented fake-shop cluster by domain count. Victims who do not receive purchases may contact the legitimate brands, which are impersonated in the scam. The main hosting provider for these sites did not respond to takedown requests. A searchable database has been created to help companies identify and respond to DoppelCart impersonations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 20:37:22 UTC

Technical Analysis

DoppelCart is a large-scale fraud operation using more than 119,000 domains, mostly under the .SHOP TLD, to run fake online stores that steal payment card data. Discovered by German cybersecurity startup Nebty, the network mimics over 44,000 brands with cloned shops that share identical build files and resolve to a limited set of commerce backends. The fake shops collect detailed payment card information and personal data during checkout, transmitting it via WebSockets to attacker-controlled command-and-control servers. Some shops also capture one-time bank confirmation codes, potentially bypassing additional security measures. Despite attempts to contact hosting providers, no takedown response was received. Nebty provides a database to assist brands in detecting DoppelCart impersonations and mitigating brand abuse.

Potential Impact

The DoppelCart network enables attackers to steal comprehensive payment card details and personal information from victims through fake e-commerce shops. This can lead to fraudulent transactions, financial loss, and identity theft. The ability to capture one-time bank confirmation codes increases the risk of bypassing security protections such as two-factor authentication. The large scale and persistence of the network, with over 105,000 active fake shops, amplify the potential impact on consumers and legitimate brands whose identities are impersonated.

Defensive Guidance

No official fix or takedown has been confirmed as the main hosting provider did not respond to contact attempts. Organizations affected by DoppelCart impersonation should use the searchable database provided by Nebty to identify fraudulent sites and take appropriate actions such as reporting to domain registrars and hosting providers, issuing public warnings, and monitoring for brand abuse. Consumers should be advised to verify the legitimacy of e-commerce sites before making purchases and to be cautious of unusually large discounts. Patch status is not applicable as this is a fraud network rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/","fetched":true,"fetchedAt":"2026-09-08T20:37:14.057Z","wordCount":671}

Threat ID: 6aa071faacd9273b4931ed69

Added to database: 09/08/2026, 20:37:14 UTC

Last enriched: 09/08/2026, 20:37:22 UTC

Last updated: 09/08/2026, 21:35:03 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses