Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, fraud, fake-shops, card-skimming, ecommerce, nebty] ยท confidence: reported ยท affected_sectors: [retail-and-entertainment-and-sport, financial-services] ยท au_impact: true

German cybersecurity startup Nebty documented "DoppelCart", the largest publicly known fake-shop cluster by domain count, using over 119,000 domains (mostly under .SHOP, accounting for 2.72% of all sites on that TLD) to run counterfeit e-commerce stores that imitate 44,182 brands and harvest payment card details at checkout. The fake sites, more than 105,000 still active, copy product catalogues, descriptions, branding and images (sometimes loading assets directly from the real company's servers), advertise discounts of up to 65%, and transmit card numbers, expiry dates, security codes, cardholder names and contact data live over WebSockets to command-and-control, with some able to relay one-time bank confirmation codes to bypass protections. The cluster far surpasses the prior "BogusBazaar" network (75,000 sites), which recorded an estimated 850,000 fraudulent transactions.

Attribute Detail
Date Reported 2026-09-08
Type Large-scale fake-shop / card-fraud network
Scale 119,000+ domains; 44,182 imitated brands
Breach label Probable breach (card-harvesting)
Source Nebty โ€” Tier 2/4

Source