All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Researchers at German cybersecurity company Nebty have identified what they describe as the largest publicly documented fake-shop network by associated domain count, with almost 119,000 domains linked to copied online stores. The network, dubbed “DoppelCart,” includes 118,787 .shop domains, roughly one in every 37 domains examined by Nebty.[1]
When you reach the checkout page, these sites can collect your card details, name, email address, phone number, and physical address, as well as one-time confirmation codes from your bank, and send them to the attacker in real time. This information could then be used for identity theft, financial fraud, and highly targeted phishing attacks.
Here’s everything you should know about DoppelCart and the steps you can take to stay safe while shopping online.
What information can DoppelCart steal
How could attackers use your data
How to stay safe while shopping online
The bottom line
How DoppelCart makes fake shops look legitimate
According to Nebty, DoppelCart reportedly includes 118,787 .shop domains, which together impersonate more than 44,000 brands, including SodaStream, CurrentBody, Dreame, MOVA, and Velasca, to lure users into giving away their payment and personal information.
These websites copy everything from their legitimate counterparts, including product names, descriptions, brand material, website logos, product features, and even customer support details. Some fake shops also load product images and icons directly from the real brand's servers.
Researchers found advertised discounts of up to 65% on these fake stores. Familiar products, recognizable branding, and seemingly huge discounts are designed to make shoppers act before they carefully check the website or payment process. It’s how phishing attacks work.
Many of the fake shops also share the same technical infrastructure and website code. In fact, Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the confirmed DoppelCart shops reportedly share identical build files and resolve to just 27 commerce backends, showing the extent of automation behind the network.
Victims may only discover the fraud when their order never arrives and they contact customer support. Since the attackers have copied the actual company's customer support details onto their fake websites, those complaints can end up going directly to the legitimate company.
Nebty has made its database public so that brands can search for their own names and domains and take action against any impersonating websites.
What information can DoppelCart steal
Nebty found code on several DoppelCart checkout pages that collected sensitive payment and personal information, including:
- Card numbers
- Expiration dates
- Security codes
- Cardholder names
- Email addresses
- Phone numbers
- Physical addresses
The checkout data is transmitted to attacker-controlled servers over WebSockets in real time. The code can also relay one-time confirmation codes issued by a victim's bank, which attackers may use to bypass security protections.
This means a fake shopping site isn't simply trying to take your money without sending you a product. It could also collect enough personal and financial information to make follow-up attacks far more convincing.
How could attackers use your data
Scammers could use your personally identifiable information to try to commit identity theft, open new lines of credit in your name, or commit other forms of financial fraud.
Your phone number could also be used in a SIM-swapping attack, where criminals try to convince your carrier to transfer your number to a device they control, potentially giving them access to one-time passwords and two-factor authentication (2FA) codes for other accounts.
Your email address could also make you a more convincing target for follow-up phishing attacks. An attacker could pretend to be your bank, credit card provider, delivery company, or the retailer you thought you had purchased from and use information from the fake transaction to make the message look legitimate.
For example, you might receive a message claiming your card was compromised or that there's an issue with your order. The link could then take you to another phishing page designed to steal your login credentials or trick you into installing malware.
How to stay safe while shopping online
Earlier this year, 120 fake Walmart websites were found using huge discounts to lure shoppers into handing over their personal and financial information. Add DoppelCart’s 119,000 domains to the mix, and it’s clear that fake shopping websites are a widespread problem.
That's why it's increasingly important to adopt a few safe online shopping practices before entering your information on any website.
- Check the website you are visiting: Pay close attention to the web address in the address bar, as fake websites can use slightly altered versions of a legitimate brand's domain that are easy to miss at first glance. Whenever possible, visit shopping websites through their official apps, saved bookmarks, or web addresses you already know rather than clicking random links in ads or on social media.
- Beware of huge discounts: Legitimate brands do run discount offers, but an unusually large discount should make you stop and check the website more carefully. DoppelCart shops advertised discounts of up to 65%, so don't let an apparently great deal pressure you into making an impulsive purchase. Remember, phishing thrives on creating urgency.
- Use a third-party antivirus program: A reliable antivirus with real-time web protection can flag suspicious websites and links before you interact with them, adding another layer of protection if a malicious website slips past your own checks.
- Pay with a protected payment method: Where possible, use a credit card or another payment service that offers buyer protection. Avoid payment methods such as cryptocurrency, bank transfers, and gift cards, which can be difficult to reverse if something goes wrong.
- Contact your credit card issuer: If you have already shopped on a bogus website and entered your credit card details, contact your card issuer immediately and explain the situation. Ask about blocking or replacing your card and monitor it for any suspicious transactions.
- Use an identity theft protection service: These services can help you keep tabs on whether your personal information has surfaced in known breaches or on the dark web, while some also provide identity theft restoration services if your identity is compromised.
The bottom line
The DoppelCart network copies legitimate shopping websites to make fake stores look authentic, luring you into making a payment and handing over your personal and financial information. This can cause both financial and privacy harm.
This is why it's important to stay vigilant whenever you shop online. Don't click on random shopping links, carefully verify the web address, and don't let huge discounts pressure you into buying something without checking first. Much of avoiding fake shops comes down to due diligence, but tools such as antivirus software can help flag suspicious websites.
If you’ve already entered your details on a suspicious website, contact your card issuer immediately, monitor your accounts, and consider placing a credit freeze. An identity theft protection service, meanwhile, can help you monitor for signs that your stolen data is being misused.
[1] DoppelCart: 119,000 domains in what is probably the largest documented fake shop network