Over 119,000 Fake Stores Are Stealing Credit Cards Before You Click Buy

Cybersecurity researchers uncovered a network of over 119,000 counterfeit storefronts capturing credit card data in real time as users type.

Author: Senja Arunka
Date: Sunday, September 13, 2026 at 05:00 PM
Graphic representation of online e-commerce fraud and fake web stores stealing payment credentials
Security researchers have uncovered a massive network of over 119,012 fake shopping domains impersonating brands like Dreame and FRITZ!Box.
Over

Cybersecurity researchers at Munich-based firm nebty have uncovered a massive cybercrime network comprising over 119,000 counterfeit online store domains. Operating largely under the .shop top-level domain suffix, this criminal operation impersonates popular tech manufacturers including robot vacuum maker Dreame, networking brand FRITZ!, EcoFlow, Roborock, Keychron, and Sennheiser to steal customer credit card credentials.

Unlike typical phishing pages that require users to hit a final submit button, these fake outlets deploy real-time WebSocket scripts that capture payment card numbers, security codes, and contact details the moment they are typed into a form field.

A Scale Unprecedented in E-Commerce Fraud

The newly documented cluster, tracked as Doppelcart, represents one of the largest fraudulent e-commerce networks ever recorded. With 119,012 confirmed domains, it far exceeds the 75,000 fake storefronts identified during the BogusBazaar campaign in 2024. Remarkably, 118,787 of these domains leverage the .shop suffix alone, representing roughly 2.72 percent of the 4.36 million .shop web addresses registered worldwide.

To construct an authentic facade, the attackers hotlink product photography and layout assets directly from the official content delivery servers of target brands. When prospective buyers search for deals on home routers or automated vacuums, they land on pages that look identical to official regional outlets. In some cases, domains masquerade as dedicated national hubs across Germany, Italy, France, Spain, and Belgium.

Real-Time Keylogging and Customer Support Spoofing

What makes this network particularly deceptive is its sophisticated manipulation of buyer trust. Many of the counterfeit sites display genuine customer support email addresses belonging to the victimized brands, such as embedding real manufacturer support channels directly on the fake checkout page. When orders inevitably fail to arrive, defrauded shoppers send complaints directly to the legitimate brand, forcing real customer support teams to manage complaints for purchases they never processed.

Underneath the polished design lies an aggressive payment capture mechanism. Technical analyses show that as soon as a victim enters their name, credit card number, expiration date, CVV, or shipping address, the site transmits each character individually over an open WebSocket connection back to attacker-controlled infrastructure. The transaction data is compromised long before the user clicks a purchase confirmation button. Furthermore, the underlying code is built to relay bank one-time authorization passcodes, tricking users into manually authorizing fraud directly with their financial provider.

Spotting Fake Outlets Before Making a Purchase

Despite the scale of the campaign, structural patterns make these malicious storefronts identifiable. Nebty Chief Executive Benedikt Scheungraber noted that 96 percent of the confirmed fraudulent pages utilize identical build files linked to just 27 shared commerce backends.

Shoppers should watch for distinct red flags when hunting for hardware deals online:

• Suspiciously uniform discounts ranging between 40 to 65 percent off retail pricing across entire product catalogs.

• Web addresses following rigid structural patterns, typically combining official brand names with filler words like store, direct, global, or hub under a .shop domain.

• Payment forms that lack standard third-party payment options such as PayPal, Apple Pay, or established banking processors.

With over 105,000 of these malicious domains remaining active as hosting providers ignore takedown requests, consumers are advised to navigate directly to manufacturer websites or verify sellers against official authorized dealer listings before checking out.

💬

FAQ: Frequently Asked Questions about Over 119,000 Fake Stores Are Stealing Credit Cards Before You Click Buy

Quick answers to key questions regarding pricing, specs, release date, and value.

Q1How does the Doppelcart fake shop network steal credit card data?
The scam sites embed real-time WebSocket keylogging scripts in payment forms that transmit your credit card number, CVV, and personal information directly to attacker servers as you type, even if you never click submit.
Q2Which brands are affected by these counterfeit online stores?
The database lists fake storefronts impersonating Dreame, FRITZ! (AVM), EcoFlow, Bluetti, Roborock, Narwal, Jackery, Keychron, HyperX, and Sennheiser, among others.
Q3How can I avoid buying from a fake shopping domain?
Always verify that you are on the manufacturer's official domain, double-check authorized seller lists, and be wary of stores offering heavy discounts across all items with web addresses ending in .shop.
RELATED

RELATED