THE TELL

119,000 fake shops, 44,000 copied brands — and they steal the code your bank just sent you

A German security firm found almost 119,000 lookalike online stores. The nastiest part isn't the fake logo. It's what happens after you type in the code from your bank.

You click an ad, land on a store that looks exactly like a brand you know, see 65% off, and buy. The product photos are real — sometimes loaded straight from the actual company's servers. The logo is real. The padlock in the address bar is real. Everything is real except the shop.

Researchers at the German cybersecurity company Nebty call this cluster DoppelCart: 118,787 .shop domains, which they say is 2.72% of all the .shop addresses they looked at. That's the largest publicly documented fake-shop network by number of domains. It copies more than 44,000 brands, usually two clones per brand — but SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS each got more than 30 fakes.

What it means

Here's the part that matters more than the numbers. When you pay on one of these checkout pages, the form doesn't just quietly save your card number for later. It streams what you type to the criminals' servers in real time, over a connection that stays open the whole session. Card number, expiry date, the three digits on the back, your billing address — and the one-time confirmation code your bank sends you.

That last one changes the game. Most of us have been trained to think the code from the bank is the seatbelt: even if someone steals the card, they can't finish a payment without it. But if the code lands in the criminal's hands the second you type it, they can push through their own payment while you're still staring at the "processing" spinner. The seatbelt only works if the person holding it is your bank.

The code is not a second lock. On a fake site, it's a second thing to steal.
Share this

And this isn't 119,000 hand-built scams. BleepingComputer reports that 96% of confirmed DoppelCart shops shared identical build files and ran on just 27 ecommerce backends. Twenty-seven. That's the economics of it: someone built the machine once, and cloning a brand now costs about as much as registering a domain. Nebty is careful here, and so are we — their findings are based on shared website and infrastructure characteristics, not proof that one identified group runs every domain.

Who it matters to

Anyone who buys from links in Instagram or TikTok ads instead of typing the address themselves — which is most people under 35, and that's exactly the traffic these shops are built to catch. Anyone chasing a 65%-off deal on a gadget or a pair of boots when the paycheck hasn't landed yet: the discount isn't a bonus, it's the hook that stops you checking the address bar. And anyone who's ever thought "my bank sends me a code, so I'm covered" — a group that includes almost everybody with a phone.

What's next

Nebty hasn't said who runs this, and neither has anyone else — the research links the domains by shared build files and infrastructure, not by naming an operator. So the thing to watch is whether the 27 ecommerce backends and the .shop registrar do anything about it, and whether that 2.72% share of the .shop namespace goes down. If it doesn't, the network is still hiring. No timeline was announced by anyone.

One detail to hold on to

44,000 brands were copied, with a median of just two clones each. That's not a targeted attack on big retail — it's a dragnet that scraped almost every store worth copying. Which means the brand you trust most has a twin out there, and it probably looks better than the original.

Sources: Malwarebytes Labs, "More than 100,000 fake stores are out to steal your card details" by Pieter Arntz, September 9, 2026, citing research by Nebty and reporting by BleepingComputer.

Why we ran this8/10

Почти 119 тысяч поддельных магазинов копируют 44 тысячи известных брендов и перехватывают не только номер карты, но и одноразовый код из банковского СМС в реальном времени — то есть привычная «защита по коду» больше не спасает при покупке на незнакомом сайте.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: 350 ads, 29,000 accounts, under $5,000 — a… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X