type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, e-commerce, fraud, fake-shops, card-theft, scam-network] ยท confidence: high ยท affected_sectors: [retail, finance, technology] ยท au_impact: true
'DoppelCart' Fraud Network Runs 119,000 Fake Shops
German cybersecurity startup Nebty documented "DoppelCart", the largest publicly known fake-shop cluster by domain count, using over 119,000 domains โ mostly under the .SHOP TLD, accounting for 2.72% of all sites on that TLD โ to run counterfeit e-commerce stores that imitate 44,182 brands and harvest payment-card details at checkout.
| Attribute | Detail |
|---|---|
| Scale | 119,000+ domains (~105,000 still active) |
| Brands imitated | 44,182 |
| Mechanism | Copy catalogues, branding, images (sometimes loading assets from the real company's servers); discounts up to 65% |
| Data exfil | Card numbers, expiry, security codes, cardholder names, contact data โ transmitted live over WebSockets to C2 |
| Advanced capability | Some sites relay one-time bank confirmation codes to bypass protections |
| Source | Nebty (via The Hacker News) โ Tier 2/4 |
The cluster far surpasses the prior "BogusBazaar" network. The large-scale brand impersonation and live over-the-wire card theft make this a first-order retail/e-commerce consumer-fraud and payment-fraud threat with direct implications for card-issuing banks and shoppers in Australia and New Zealand.