Shoppers are being lured into polished-looking clone stores that promise big savings, mimic trusted brands, and quietly scoop up payment data at checkout. Researchers say one especially large fake-shop network, tied to the name DoppelCart, has spread across a massive number of domains and even shown signs of capturing one-time bank verification codes, turning a routine purchase into a fast-moving security risk.
Picture a site offering the exact item you wanted at 65% off, with the branding looking spot on and the page layout feeling familiar. That kind of setup is exactly what makes these scams dangerous, because they lean on trust before the buyer even notices anything is off.
Nebty says it has connected roughly 119,000 domains to DoppelCart, a fake shopping operation that imitates real businesses and can steal payment details during checkout. In the latest scans, more than 105,000 of those shops were still active, showing just how much of the network remains online.
The scale is eye-catching, but the bigger issue is how the operation works. Researchers say the fake stores share technical traits, and many of them appear to be built from the same underlying materials, even if that does not prove one group controls every single site.
What makes the scheme especially slick is how normal the pages can look. Instead of the clunky scam sites people expect, these storefronts can copy product catalogs, brand logos, and descriptions from legitimate companies, which makes the whole thing feel safe right up until checkout.
In some cases, fake shops were even found pulling assets from the real company’s own servers. That creates a nasty illusion because the page may look authentic enough to pass a quick glance, especially when the product photos and text match what shoppers are used to seeing.
Researchers say the cluster imitates more than 44,000 brands, with some names getting hit over and over again. A few companies were targeted by dozens of clone stores, which shows the attackers are not just casting a wide net, they are leaning hard into brands people already know.
The bait often comes down to price. A huge discount can trigger the same snap judgment that happens on any good sale, but that rush to save money is exactly what these sites exploit, especially when the seller is unfamiliar and the deal seems too good to be true.
The risk does not stop at card numbers either. Nebty’s testing showed checkout pages that could collect card details, expiration dates, security codes, names, email addresses, phone numbers, and physical addresses, then pass that information along in real time.
That is where the scam gets really ugly. Some of these pages can also capture one-time bank verification codes, which many people assume are a final safety net, and then relay them to the attackers as part of the fraud.
The fallout can spill over to the real businesses being copied. Fake stores sometimes show legitimate customer support details, so buyers who never received a product may end up yelling at the wrong company and creating a mess the honest retailer never asked for.
Spotting trouble starts with slowing down before paying. The web address matters, the discount matters, and the merchant name matters, because a polished storefront can still be a trap if the domain looks odd or the price gap is absurd.
Reading bank messages carefully is another simple but powerful habit. If a verification code arrives and the merchant details do not match the purchase, that is a red flag, not a step to rush through.
Strong account protection helps too, especially when a fake shop is trying to bait a careless checkout. Credit card protections, transaction alerts, and smart security tools can all add friction for scammers, but none of them replace a cautious eye when a brand-new store suddenly looks like a bargain paradise.
If card information already went into a suspicious checkout, speed matters. The next move is to contact the card issuer through an official app, the number on the card, or the bank’s website, then watch the account closely for anything unfamiliar.
Passwords deserve attention too, especially if the same one was reused anywhere else. A fake store can become the first domino in a wider mess, and the people behind it may already have enough personal information to keep trying new tricks through follow-up emails, refund bait, or phony bank alerts.
That is why these fake-shop campaigns keep working. They do not need flashy malware or loud warnings when a convincing storefront, a huge discount, and a split-second checkout decision can do most of the damage for them.
