Executive Summary
In September 2026, cybersecurity researchers discovered DoppelCart, the largest documented fake e-commerce network comprising over 119,000 fraudulent domains, primarily using the .SHOP TLD. The operation impersonates 44,182 legitimate brands by copying product catalogs and branding, then uses WebSocket connections to steal payment card data, CVV codes, and personal information in real-time during checkout. The network affects 2.72% of all .SHOP domains and significantly surpasses previous operations like BogusBazaar's 75,000 sites, with over 105,000 shops remaining active at discovery.
This incident highlights the evolving sophistication of financial fraud networks and their ability to operate at unprecedented scale through automated domain generation and brand impersonation, representing a critical threat to consumer trust and e-commerce security.
Why This Matters Now
The DoppelCart network represents a new scale of e-commerce fraud that threatens consumer confidence during peak online shopping periods, while demonstrating how attackers exploit domain registrars and hosting providers to create massive fraud infrastructures faster than traditional detection methods can identify them.
Attack Path Analysis
The DoppelCart fraud network operates 119,000 fake e-commerce sites that impersonate legitimate brands to harvest payment card data. Attackers establish fake shops using shared infrastructure and commerce backends, then collect victim payment information in real-time via WebSocket connections to command-and-control servers, resulting in widespread financial fraud across multiple brands and regions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers registered 119,000 fraudulent domains primarily in .SHOP TLD, creating fake e-commerce sites that impersonate 44,182 legitimate brands by copying product catalogs, descriptions, and branding materials
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Acquire Infrastructure: Domains
Stage Capabilities: Link Target
Masquerading: Match Legitimate Name or Location
Exfiltration Over C2 Channel
Browser Session Hijacking
Input Capture: Web Portal Capture
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong cryptography and security protocols safeguard PAN during transmission
Control ID: Requirement 4.2.1
PCI DSS 4.0 – Web applications are protected from skimming attacks
Control ID: Requirement 6.4.3
CISA Zero Trust Maturity Model 2.0 – Data classification and protection controls
Control ID: Data Security - Advanced
NYDFS 23 NYCRR 500 – Penetration testing and vulnerability assessments
Control ID: Section 500.15
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
GDPR – Security of processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Retail Industry
DoppelCart's 119,000 fake e-shops directly target retail by impersonating 44,182 brands, stealing customer payment data and damaging legitimate retailer trust and reputation.
Financial Services
Mass credit card theft through fraudulent checkouts creates significant financial liability, requiring enhanced egress security and real-time fraud detection capabilities for payment processors.
Internet
E-commerce platforms face brand impersonation risks requiring zero trust segmentation, encrypted traffic monitoring, and anomaly detection to prevent fraudulent shop operations and protect customers.
Computer Software/Engineering
Payment processing systems need enhanced security controls including inline IPS, threat detection capabilities, and secure connectivity to prevent WebSocket-based data exfiltration attacks.
Sources
- DoppelCart fraud network uses 119,000 fake shops to steal credit cardshttps://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/Verified
- Nebty DoppelCart Fake Shop Network Investigation Reporthttps://nebty-id.com/en/doppelcart-fake-shop-network/Verified
- DoppelCart Investigation Databasehttps://investigations.nebty-id.com/doppelcart?verdict=fleet_confirmedVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF segmentation and egress controls would likely constrain the DoppelCart operation's ability to scale across shared infrastructure and exfiltrate payment data in real-time. Zero trust workload isolation could reduce the blast radius of this fraudulent e-commerce network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust fabric visibility would likely detect anomalous infrastructure patterns and unusual traffic flows associated with the massive fraudulent domain registration and site deployment activities
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies would likely constrain administrative access scope across the 27 commerce backends, reducing the attackers' ability to manage the fraudulent network at scale through shared administrative privileges
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain lateral connectivity between the shared infrastructure components, reducing the attackers' ability to efficiently manage and coordinate operations across 105,000+ fraudulent sites through common backend systems
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely detect and constrain the real-time WebSocket communications patterns between fraudulent sites and centralized command-and-control infrastructure, reducing the efficiency of coordinated data collection operations
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain real-time transmission of sensitive payment data by blocking or inspecting unauthorized outbound connections, reducing the volume and speed of data exfiltration to attacker-controlled infrastructure
Residual financial fraud impact would likely be reduced in scope due to constrained infrastructure scalability and limited data exfiltration capabilities, though individual compromised transactions may still result in financial losses for affected consumers
Impact at a Glance
Affected Business Functions
- Brand reputation and trust
- Customer acquisition and retention
- Legal and compliance management
- Customer support operations
Estimated downtime: N/A
Estimated loss: N/A
Credit card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses of consumers who made purchases on fake e-commerce sites. Banking one-time confirmation codes were also intercepted to bypass security protections. Estimated to affect hundreds of thousands of consumers based on the scale of 119,000 fraudulent domains with over 105,000 still active.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to detect and block suspicious outbound WebSocket connections to unauthorized destinations that could indicate payment data exfiltration
- • Deploy multicloud visibility and control systems to identify anomalous traffic patterns and repeated malformed requests across distributed fake shop infrastructure
- • Establish encrypted traffic inspection capabilities to monitor data in transit and detect unencrypted payment card information being transmitted to external servers
- • Utilize threat detection and anomaly response systems to baseline normal e-commerce behavior and alert on suspicious automation patterns indicative of fraudulent shop networks
- • Apply cloud firewall controls with URL filtering and AI-driven traffic discovery to block access to known fraudulent domains and identify new fake shop patterns



