A cybersecurity company says it has linked roughly 119,000 domains to a single fake-shopping operation, one of the largest such networks ever documented.
Nebty, the firm behind the discovery, calls the cluster DoppelCart. The sites impersonate real businesses and, at checkout, can capture shoppers’ payment details, including the one-time verification codes banks send to confirm purchases. BleepingComputer reports more than 105,000 of the DoppelCart shops were still active in Nebty’s latest scans, and Nebty says most of the cluster remains online.
Nebty found DoppelCart while looking into fake shops targeting its own customers. Investigators noticed that stores copying different companies shared the same technical fingerprints, and pulling on that thread led them to roughly 119,000 associated domains. Nebty says that, as far as it knows, this is the largest publicly documented fake-shop cluster measured by number of domains involved. The company is careful to note that shared infrastructure doesn’t prove one group controls every site in the cluster, but the overlap is significant: Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the confirmed shops shared identical build files and resolved to 27 commerce backends.
Most of the domains use the .shop web address ending. Nebty’s September 2026 data counted 118,787 .shop domains tied to the cluster out of 4,361,908 .shop domains in its snapshot — about 2.72%, or roughly one in every 37. Nebty cautions that figure only reflects domains listed in the .shop system at a given moment, not how many were actually running as live scam stores at the same time. For comparison, an earlier fake-shop operation called BogusBazaar involved more than 75,000 domains, though Nebty says the two investigations used different methods and aren’t directly comparable.
Convincing copies of real stores
These aren’t crude, obviously fake websites. DoppelCart sites can copy a legitimate company’s product catalog, descriptions and branding, and in some cases researchers found fake stores pulling images and other material directly from the real company’s own servers. That means a shopper can land on a scam site where the brand, products and photos all look correct, because much of it was lifted from the genuine business.
Scheungraber says DoppelCart shops mimic 44,182 different brands, with a median of two fake versions per brand. Some brands were hit far harder — researchers found more than 30 fake shops apiece impersonating SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS. Some of the fake listings advertised discounts as steep as 65%.
How the theft happens
Nebty tested checkout pages tied to DoppelCart and found code designed to collect payment card information as it’s typed in. According to the researchers, that data can be sent through WebSockets to remote servers in real time, meaning an attacker could receive a shopper’s card details while the shopper is still on the checkout page.
More troubling, Nebty found the code can also relay the one-time verification code a bank sends to approve a transaction — the same code many people are trained to treat as a security safeguard. Attackers may use that code to push a fraudulent charge through.
Some fake shops even display the real company’s genuine customer service contact information. Nebty says this has led shoppers who never received their orders to contact the legitimate business demanding answers — a business that has no record of the order because it never received the money or the purchase. Nebty says it tried to reach the main hosting provider linked to DoppelCart sites but got no response. Nebty has published a searchable database of the domains at investigations.nebty-id.com/doppelcart.
Protecting yourself
Security researchers and the Federal Trade Commission recommend a few basic precautions:
- Check the actual web address before entering payment information — a fake site can use a familiar brand name inside an unrelated domain.
- Don’t assume a padlock icon or




