Executive Summary

In September 2026, cybersecurity researchers discovered DoppelCart, the largest documented fake e-commerce network comprising over 119,000 fraudulent domains, primarily using the .SHOP TLD. The operation impersonates 44,182 legitimate brands by copying product catalogs and branding, then uses WebSocket connections to steal payment card data, CVV codes, and personal information in real-time during checkout. The network affects 2.72% of all .SHOP domains and significantly surpasses previous operations like BogusBazaar's 75,000 sites, with over 105,000 shops remaining active at discovery.

This incident highlights the evolving sophistication of financial fraud networks and their ability to operate at unprecedented scale through automated domain generation and brand impersonation, representing a critical threat to consumer trust and e-commerce security.

Why This Matters Now

The DoppelCart network represents a new scale of e-commerce fraud that threatens consumer confidence during peak online shopping periods, while demonstrating how attackers exploit domain registrars and hosting providers to create massive fraud infrastructures faster than traditional detection methods can identify them.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

DoppelCart uses malicious checkout code that captures credit card numbers, CVV codes, expiration dates, and personal information via WebSocket connections to command-and-control servers in real-time.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF segmentation and egress controls would likely constrain the DoppelCart operation's ability to scale across shared infrastructure and exfiltrate payment data in real-time. Zero trust workload isolation could reduce the blast radius of this fraudulent e-commerce network.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust fabric visibility would likely detect anomalous infrastructure patterns and unusual traffic flows associated with the massive fraudulent domain registration and site deployment activities

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation policies would likely constrain administrative access scope across the 27 commerce backends, reducing the attackers' ability to manage the fraudulent network at scale through shared administrative privileges

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely constrain lateral connectivity between the shared infrastructure components, reducing the attackers' ability to efficiently manage and coordinate operations across 105,000+ fraudulent sites through common backend systems

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely detect and constrain the real-time WebSocket communications patterns between fraudulent sites and centralized command-and-control infrastructure, reducing the efficiency of coordinated data collection operations

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely constrain real-time transmission of sensitive payment data by blocking or inspecting unauthorized outbound connections, reducing the volume and speed of data exfiltration to attacker-controlled infrastructure

Impact (Mitigations)

Residual financial fraud impact would likely be reduced in scope due to constrained infrastructure scalability and limited data exfiltration capabilities, though individual compromised transactions may still result in financial losses for affected consumers

Impact at a Glance

Affected Business Functions

  • Brand reputation and trust
  • Customer acquisition and retention
  • Legal and compliance management
  • Customer support operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Credit card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses of consumers who made purchases on fake e-commerce sites. Banking one-time confirmation codes were also intercepted to bypass security protections. Estimated to affect hundreds of thousands of consumers based on the scale of 119,000 fraudulent domains with over 105,000 still active.

Recommended Actions

  • Implement egress security and policy enforcement to detect and block suspicious outbound WebSocket connections to unauthorized destinations that could indicate payment data exfiltration
  • Deploy multicloud visibility and control systems to identify anomalous traffic patterns and repeated malformed requests across distributed fake shop infrastructure
  • Establish encrypted traffic inspection capabilities to monitor data in transit and detect unencrypted payment card information being transmitted to external servers
  • Utilize threat detection and anomaly response systems to baseline normal e-commerce behavior and alert on suspicious automation patterns indicative of fraudulent shop networks
  • Apply cloud firewall controls with URL filtering and AI-driven traffic discovery to block access to known fraudulent domains and identify new fake shop patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image