← Blog · · df00tech

DoppelCart Fraud Network: 119,000 Fake Online Stores Used to Harvest Payment Card Data

security-news campaign

According to a report from BleepingComputer, researchers have identified a large-scale e-commerce fraud operation dubbed "DoppelCart" that reportedly uses more than 119,000 domains to operate a network of fake online storefronts designed to steal payment card details from shoppers. Details of the technical infrastructure and specific attribution remain limited at this stage.

Why It Matters

Fake e-commerce sites at this scale represent a significant consumer and brand-abuse threat. Victims who enter payment information into these storefronts risk direct card fraud, and the sheer domain count suggests a highly automated, likely templated deployment process — meaning takedowns of individual sites are unlikely to meaningfully disrupt the broader network. Organizations whose brands or product listings are being spoofed by these fake shops may also face reputational and customer-trust fallout, even though they are not the direct target of the credential/card theft.

What Defenders Should Watch For

  • Monitor for typosquatted or lookalike domains referencing your brand, product names, or common e-commerce keywords, particularly bulk domain registrations following similar naming patterns.
  • Watch outbound traffic and DNS logs for connections to newly registered or recently observed e-commerce-themed domains, especially from users who may have clicked ads or search results promoting deep discounts.
  • Card issuers and payment processors should consider correlating fraud reports and chargebacks against clusters of newly seen merchant domains rather than treating each fraudulent site as an isolated incident.
  • Security awareness efforts should reinforce caution around unfamiliar online storefronts, particularly those advertised via social media or search ads with unusually low prices.
  • Threat intel and brand-protection teams should consider tracking indicators (domains, hosting infrastructure, registrar patterns) as they are published, since a network of this size likely reuses infrastructure providers or templates that could enable broader detection.

This is developing intelligence based on a single report, and further technical details (infrastructure, actor attribution, specific indicators) may emerge as researchers continue to analyze the campaign. For the original reporting, see BleepingComputer's coverage of DoppelCart.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.