DoppelCart Network of 119,000 Fake Stores Targets Shoppers for Card Details
A vast network of nearly 119,000 cloned online stores, dubbed DoppelCart, has been identified by researchers, aiming to steal payment card information from unsuspecting shoppers.

Cybersecurity researchers have uncovered a massive operation involving nearly 119,000 domains hosting cloned online stores, collectively named "DoppelCart." This network represents the largest publicly documented fake-shop infrastructure by domain count, with researchers identifying 118,787 .shop domains alone, constituting a significant portion of that top-level domain's population. The operation's modus operandi involves meticulously copying legitimate retailers' product catalogs, descriptions, branding, and even images, often directly pulling assets from the original companies' servers. This sophisticated cloning is facilitated by modern AI-powered website builders, making it easier for malicious actors to create convincing replicas.
The DoppelCart network mimics over 44,000 distinct brands, with many brands having multiple cloned sites. While most brands have a few associated fake stores, some, including SodaStream, Velasca, CurrentBody, and Daniel Wellington, have seen over 30 individual clones created. This widespread replication aims to cast a wide net and capitalize on brand recognition.
A key tactic employed by these fraudulent sites is the advertisement of deep discounts, sometimes up to 65% off. These attractive offers are designed to lure shoppers into making quick purchasing decisions without thoroughly vetting the legitimacy of the website, its company details, or its checkout process. The urgency created by seemingly too-good-to-be-true deals is a common psychological trigger used in such scams.
Once a victim proceeds to checkout, the fake stores employ a sophisticated method to capture sensitive payment information. Fraudulent checkout pages are configured to collect card numbers, expiry dates, CVVs, billing details, and critically, even one-time bank confirmation codes in real-time. This data is transmitted to attacker-controlled servers using WebSockets, a technology that allows for continuous, bidirectional communication.
The real-time capture of one-time authentication codes is particularly concerning. This capability allows criminals to complete fraudulent transactions while the victim is still engaged in the checkout flow, potentially bypassing multi-factor authentication mechanisms that rely on these codes for verification. This significantly increases the success rate of the card-skimming attacks.
Researchers emphasize that a professional appearance, the use of HTTPS, and familiar logos are no longer reliable indicators of a legitimate website. Shoppers are urged to exercise extreme caution. Before entering any payment details, it is crucial to meticulously check the web address, verify contact information, and compare company details against known legitimate retailers. Reaching a retailer through official apps or known bookmarks, rather than relying on search ads, is also a safer practice.
Consumers are advised to be wary of unusually large discounts and to search for reviews of the website address. Paying with credit cards or services offering buyer protection is recommended over methods like cryptocurrency or bank transfers, which are harder to reverse. If a transaction requires a one-time bank verification code, users should carefully confirm the merchant and amount before proceeding, and never share such codes with unsolicited contacts.
To combat these threats, users should employ up-to-date anti-malware solutions with web protection. Tools like Malwarebytes Browser Guard can automatically block phishing and malicious sites. In the event of a compromise, victims should act swiftly by contacting their card issuer, reporting the fraud, and saving all relevant transaction details for investigation.