Researchers say a fraud network called DoppelCart is running more than 119,000 fake shopping websites that impersonate real brands and steal customers’ payment card details. Nebty says over 105,000 sites were still active in recent scans, with 96% sharing the same build files and pointing to 27 commerce backends. The checkout code reportedly sends card numbers, expiry dates, security codes, names, contact details, addresses, and even bank one-time passcodes to attacker-controlled servers in real time via WebSockets.
Why it matters: This is a very large active card-theft operation aimed at ordinary online shoppers and the brands being impersonated. Consumers should be wary of steep-discount storefronts and verify domains before paying, while merchants and defenders may need to hunt for cloned shops, warn customers, and work with registrars and hosts on takedowns.
Bill Toulas
2026.09.08
100% relevant
This article establishes a distinct new fraud campaign centered on the DoppelCart fake-shop infrastructure, including its scale, payment-card theft behavior, and brand impersonation scope.
← Back to all stories