Online shoppers should be on high alert. A recent investigation by cybersecurity company Nebty revealed a massive network of counterfeit e‑commerce sites—dubbed “DoppelCart”—that impersonate legitimate retailers and harvest payment information at checkout.
Scale of the operation
Nebty’s scans identified about 119,000 domains linked to the DoppelCart cluster. More than 105,000 of those sites were active at the time of the latest scan, and the company believes the majority remain online. The cluster appears to be the largest publicly documented fake‑shop operation measured by associated domains.
Most of the fraudulent sites use the .shop top‑level domain. In Nebty’s September 2026 snapshot, 118,787 distinct .shop domains were tied to DoppelCart, representing roughly 2.72% of all .shop domains in that data set—about one in every 37.
How the scams work
Researchers found that DoppelCart stores copy product catalogs, branding, and even images from real companies. In some cases, the fake sites load assets directly from the legitimate retailer’s servers, making the counterfeit pages look indistinguishable from the genuine article.
The sites typically advertise steep discounts—often 65% off or more—to lure price‑sensitive shoppers. While real retailers do run clearance sales, a discount that dramatically undercuts the market should trigger a second look.
When a shopper proceeds to checkout, malicious code can capture every keystroke, including credit‑card numbers and one‑time bank verification codes. Nebty’s testing showed that this data can be transmitted in real time via WebSockets to a command‑and‑control server, allowing attackers to use the information while the victim is still on the checkout page.
Potential impact on consumers and businesses
Victims may see unauthorized charges on their cards, and the stolen verification codes can help fraudsters bypass additional security layers. Even if the payment is blocked, shoppers often endure the hassle of disputing charges and dealing with their bank.
Legitimate businesses suffer as well. Nebty reports that many of the counterfeit stores list the real company’s customer‑support address, leading confused customers to contact the brand about orders that never existed. This creates unnecessary workload for honest merchants and can damage their reputation.
What you can do to protect yourself
1. Check the URL carefully. A recognizable brand name in a completely different domain (especially one ending in .shop) is a red flag.
2. Beware of extreme discounts. If a price seems too good to be true, verify it on the retailer’s official website.
3. Do not enter one‑time bank codes unless you are absolutely certain the site is legitimate. Banks typically send those codes only after you initiate a transaction through a trusted channel.
4. Look for the padlock icon, but remember it only indicates encryption, not legitimacy. Scammers can obtain HTTPS certificates for their fake sites.
5. Use a credit card rather than a debit card for online purchases. Credit cards often provide stronger fraud protection.
Industry response
Nebty has reached out to the .shop registry operator, GMO Registry, for comment but has not received a response. The company also attempted to contact the primary hosting provider for the DoppelCart sites without success.
While the exact perpetrators remain unidentified, the technical overlap among the sites is striking—96% of confirmed shops share identical build files and resolve to 27 common commerce back‑ends, according to Nebty CEO Benedikt Scheungraber.
Conclusion
The proliferation of fake online stores underscores the need for vigilance in today’s digital marketplace. By taking a few extra seconds to verify a site’s authenticity, shoppers can protect their finances and help honest businesses stay trustworthy.
Original reporting: Fox News (HLL/CB) — read the source article.