German cybersecurity and brand protection startup Nebty says it has identified what it describes as the largest known network of fake online stores, a sprawling operation it calls DoppelCart. In the company’s September 2026 snapshot, the network accounted for 2.72% of all .shop domains, according to Nebty’s findings.
The firm says the campaign is built to imitate legitimate ecommerce brands while harvesting customer information during checkout. Nebty reported that the stores collect personal and payment data and transmit it to attackers in real time.
A large, linked storefront network
Nebty estimates that DoppelCart operates across roughly 119,000 domains. The company says the sites are connected through shared infrastructure and repeated features in the shopping software used across the network.
According to Nebty CEO Benedikt Scheungraber, 96% of the confirmed sites use identical build files and point to only 27 commerce backends. Nebty says those common technical patterns helped tie the domains together as part of one coordinated operation rather than isolated scam sites.
More than 44,000 brands reportedly imitated
Nebty says the fake stores mimic 44,182 brands by reproducing product catalogs, descriptions, logos, branding elements and images. In some cases, the company says, the fraudulent stores load assets directly from legitimate company servers.
The copied material appears central to how the shops gain credibility. Nebty said examples it reviewed displayed real product names, detailed descriptions and other original material from the brands being impersonated, making the storefronts look familiar to shoppers already aware of those products.
Checkout pages designed to capture sensitive data
According to Nebty, the fake checkout flows are used to collect card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers and physical addresses. The company also says attackers receive one-time bank confirmation codes entered by victims during the payment process.
Nebty reported that the stolen information is sent in real time over WebSockets. That would allow attackers to receive details as they are submitted, rather than relying on delayed batch collection.
Copied listings and deep discounts as lures
Nebty said one store it examined had lifted product descriptions word for word from a legitimate online seller. The archived HTML, according to the company, showed how extensively the original content had been reproduced.
The firm also found that fake listings paired copied brand material with steep advertised discounts, including offers of 65% off. Nebty said the combination of familiar product presentation and unusually low pricing appears intended to make the sites look both trustworthy and attractive.
What is confirmed so far
The claims about DoppelCart come from Nebty’s own investigation, and the company has framed the operation as the largest fake-shop network it has seen. Based on the information released so far, the key confirmed details are the scale Nebty observed in its September 2026 .shop snapshot, the repeated technical infrastructure it says links the domains, and the kinds of customer data the checkout pages were built to capture.
Nebty has not, in the material released, provided additional public details about the operators behind the network. For now, the most concrete next step is likely to be further analysis of the domains, backends and impersonated brands identified in the company’s findings.
Source: dailyhodl.com