DoppelCart fraud network uses 119,000 fake shops to steal credit cards

A massive online scam, dubbed “DoppelCart,” has been uncovered by cybersecurity startup Nebty, which uses over 119,000 fake e-shops to steal payment card details. These shops are cleverly designed to mimic legitimate businesses, often copying product catalogs, descriptions, branding, and images directly from the real company’s servers.

The scammers behind DoppelCart have created an impressive network of fake stores that impersonate a staggering 44,182 different brands. Some of these brands, such as SodaStream and Daniel Wellington, are particularly targeted, with over 30 shops created to mimic each one. The fake sites offer enticing discounts of up to 65% in an attempt to lure bargain-hunting shoppers into parting with their sensitive information.

When a victim attempts to checkout on one of these fake stores, the scammers use code that collects payment card details, including numbers, expiration dates, security codes, and more. This data is transmitted in real-time over WebSockets to a command-and-control (C2) server, allowing the attackers to access the stolen information. What’s even more concerning is that some of these fake stores display the legitimate support address of the impersonated brand, leading victims who didn’t receive their purchases to contact the real company.

Nebty has been tracking DoppelCart for a while and estimates that over 105,000 of its shops are still active. The company’s CEO, Benedikt Scheungraber, notes that all these sites share identical build files and resolve to just 27 commerce backends. This suggests that the scammers behind DoppelCart are using a centralized system to manage their operations.

The discovery of DoppelCart highlights the ongoing threat of online scams and the need for businesses and individuals to be vigilant about protecting themselves from such attacks. Nebty has created a searchable database to help companies identify DoppelCart impersonation and brand abuse, allowing them to take action against these fake stores.

For consumers, it’s essential to remain cautious when shopping online, especially during sales or promotions that seem too good to be true. Verify the authenticity of any website by checking its URL, looking for misspellings or generic names, and being wary of excessive discounts. Always make sure you’re on a secure connection (HTTPS) and avoid sharing sensitive information unless you’re confident in the site’s legitimacy.

As the cybersecurity landscape continues to evolve, it’s clear that scammers will stop at nothing to exploit vulnerabilities and steal valuable data. By staying informed and taking proactive steps to protect ourselves, we can reduce our risk of falling victim to such attacks.


Source: Bleeping Computer — 2026-09-08