German cybersecurity startup Nebty documented "DoppelCart", the largest publicly known fake-shop cluster by domain count, using over 119,000 domains (mostly under .SHOP, accounting for 2.72% of all sites on that TLD) to run counterfeit e-commerce stores that imitate 44,182 brands and harvest payment card details at checkout. The fake sites, more than 105,000 still active, copy product catalogues, descriptions, branding and images (sometimes loading assets directly from the real company's servers), advertise discounts of up to 65%, and transmit card numbers, expiry dates, security codes, cardholder names and contact data live over WebSockets to command-and-control, with some able to relay one-time bank confirmation codes to bypass protections. The cluster far surpasses the prior "BogusBazaar" network (75,000 sites), which recorded an estimated 850,000 fraudulent transactions.
| Attribute | Detail |
|---|---|
| Date | Reported 2026-09-08 |
| Type | Large-scale fake-shop / card-fraud network |
| Scale | 119,000+ domains; 44,182 imitated brands |
| Breach label | Probable breach (card-harvesting) |
| Source | Nebty โ Tier 2/4 |