A convincing copy of a real brand's website steals your card details at checkout
A network of 119,000 fake storefronts clones real brands at 40–65% discounts. At checkout, your card number, CVV, and bank OTP are stolen in real time — sometimes a cheap knockoff ships to delay discovery.
Also known as: DoppelCart scam, fake brand website card skimming, brand clone checkout fraud, fake storefront skimmer
Already happened to you? Do this in the next few minutes
- 1 Call your bank or card's fraud line right now. Use the number on the back of your card — not any number from the message or caller. Ask them to stop or reverse the payment and freeze the account.
- 2 If you paid by gift card, wire, or an app (Zelle, Venmo, Cash App): contact that company immediately and report it as fraud. Acting fast sometimes recovers the money.
- 3 Report to the FBI at ic3.gov and the FTC at reportfraud.ftc.gov. The sooner, the better.
What to do right now
- 1 Always verify a brand's official domain before buying — search the brand name + 'official site' in a separate tab
- 2 Never enter a one-time bank code on a shopping site — legitimate stores do not ask for OTP
- 3 If you entered card details, call your bank immediately to freeze the card and dispute any charges
- 4 Monitor your bank and card statements for the next 30–90 days even if you received a package
- 5 Check the site's domain at a WHOIS lookup; if registered in the last 12 months, treat with caution
- 6 Report to the FTC at https://reportfraud.ftc.gov and the FBI's IC3 at https://www.ic3.gov.
Red flags
- ⚠ Price is 40–65% below the brand's own website — steep discount with no obvious sale event
- ⚠ Domain ends in .shop, .store, or .online and was registered within the last 12 months
- ⚠ Site loads the brand's own product images from the real brand's servers (look at image URLs)
- ⚠ Checkout page asks for your card number, expiry, CVV, and then a one-time bank code
- ⚠ No phone number or physical address listed; support email is a generic Gmail or similar
- ⚠ The URL doesn't match the official brand domain but looks similar (e.g. sodastream-official.shop)
A new large-scale fake-shopping infrastructure called DoppelCart, documented by German cybersecurity firm Nebty in September 2026, runs over 119,000 fake brand storefronts across .shop, .store, and similar domains. The sites mimic 44,182 real brands by copying product catalogs, images, and descriptions — sometimes loading assets directly from the real brand’s own servers — and advertising discounts of 40–65% to draw buyers.
Unlike older fake shops that simply take your money and ship nothing, DoppelCart sites run a live card-skimmer during checkout: as you type your card number, expiry, CVV, and any bank one-time code, that data is transmitted in real time to attackers via WebSockets. Some victims receive a cheap counterfeit, which delays their realization that their card was also compromised. By the time the fraudulent charges appear — sometimes weeks later — many victims don’t connect them to the fake brand site.
The network accounts for 2.72% of all .shop domains as of Nebty’s September 2026 snapshot. Brands with confirmed heavy impersonation include SodaStream, Daniel Wellington, CurrentBody, Dreame, Horze, and MOVA, but any consumer brand can be a target.
Sources
- Bleeping Computer / Nebty — DoppelCart fraud network uses 119,000 fake shops to steal credit cards (Sep 2026)
- eSecurity Planet — 119,000 Fake Shops Are Mimicking Real Brands to Steal Card Details (Sep 2026)
- Daily Hodl — Network of 118,996 Fake Shops Impersonating Legitimate Brands Stealing Card Data (Sep 9, 2026)
- SC Media — DoppelCart operation uses over 119,000 fake domains to steal payment card details (Sep 2026)
- Nebty — DoppelCart: 119,000 Domains in the Largest Documented Fake-Shop Network (Sep 2026)
- Doppel — Vibe phishing in retail: AI clones brand websites and storefront voice overnight (2026)
- Cyble / PRWeb — AI-driven brand threats grew 16x in Q1 2026; fake website detections up 47x (Sep 2026)