The dangerous moment is not when the shopper hands over a card number. It is a few seconds later, when the bank sends a confirmation code to their phone and the fake checkout asks for it. That code reaches the criminals over a live connection while it is still valid, so a payment they control can be approved while the victim watches a loader spin.
Researchers at the German security company Nebty have documented a cluster of nearly 119,000 domains built to run exactly that sequence. They call it DoppelCart, and describe it as the largest publicly documented fake shop network by associated domain count. The findings were summarised for consumers this week, and Nebty's own write up carries the detail.
Two point seven percent of an entire domain space
The precise count is 118,787 .shop domains, which Nebty says is 2.72 percent of the .shop top level domain population it examined. That is one in every thirty seven addresses in a retail namespace.
Nebty is careful about what the number means, and so should anyone repeating it be. The cluster was assembled from shared website and infrastructure fingerprints. That is strong evidence the sites were built from the same kit or by the same operation, but not proof that every one of the 118,787 domains is run by a single identified group.
They copy the shop, including the pictures
Each site lifts a real retailer's catalog, descriptions, branding and images. In some cases the fakes do not even rehost the photographs, loading them straight from the real company's servers, which is why the pages look right down to the pixel. Nebty counted clones of more than 44,000 brands, a median of two copies each. A handful attracted far more, with over thirty shops apiece: SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS.
Advertised discounts ran as deep as 65 percent, which is the part of the design doing the real work. A price that good encourages a shopper to move fast and check the address, the company details and the payment flow slowly, or not at all.
The checkout is the payload
The fraudulent checkout pages push cardholder data to attacker controlled servers over WebSockets, a connection that stays open and delivers each field as it is typed rather than waiting for a form submission. Nebty says the harvested data can include card numbers, expiry dates, CVV security codes, billing information and the one time codes issued by banks. Real time capture is what turns stolen card details into a completed transaction, because the bank's code is good for only a few minutes.
Checking the padlock proves nothing
A professional storefront, a valid HTTPS certificate, real product photography and a familiar logo are all trivially cheap now, and none is evidence that a shop is genuine. The advice that still works is boring: reach a retailer through its own app, a bookmark or an address already known to be correct, not through a sponsored search result or a social media ad. Treat an unusually large discount as a reason to look harder, and search the exact address alongside the word scam. Pay with a credit card or another method carrying buyer protection, never a bank transfer, gift card or cryptocurrency. Above all, read the bank's verification message instead of copying the digits out of it, and check that the merchant and the amount are the ones expected. Anyone who has already paid should call their card issuer and keep the confirmations and screenshots.
IntelFusions reported on a smaller European fake shop wave in June that leaned on Samsung and World Cup lures. What has changed is not the trick but its industrial scale, and the fact that the checkout now goes after the bank's confirmation code rather than settling for the card.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.