The store looks real, the product is the one you were looking for, and the checkout asks for the same details as any e-commerce site. The problem is that no store exists. A fraud network dubbed DoppelCart is using over 119,000 domains to set up fake shops designed to harvest payment card data, according to analysis reported by BleepingComputer.

The scale changes the way we need to think about phishing. We are no longer dealing merely with makeshift pages set up by individual scammers, but with infrastructures capable of producing and managing thousands of storefronts.

E-commerce is an easy interface to clone

A modern online store follows very standard conventions: catalog, cart, address, payment. This uniformity improves the user experience, but it also makes it simple to create convincing templates. Logos, images, and descriptions can be scraped automatically from legitimate websites.

Cheap domains and distributed hosting complete the model. When a site is blocked, the network can shift traffic to another address.

Scale is the real criminal innovation

A single fake store needs to convince many victims. One hundred thousand domains can afford minuscule conversion rates. It is the same economic logic as spam: sufficient automation makes even an extremely rare success profitable.

Generative artificial intelligence can further lower the cost of copy, translations, imagery, and fraudulent support, even if invoking AI is not necessary to explain an already heavily automated network.

The padlock is not enough

HTTPS indicates that the connection to the site is encrypted, not that the merchant is trustworthy. TLS certificates are now easily available even for criminal domains. Users must therefore assess the address, reputation, payment method, and deals that seem too good to be true.

For banks and card networks, the issue calls for behavioral detection: identifying transaction patterns and suspicious merchants before the fraud is monetized on a broad scale.

Consumer cybersecurity becomes a platform issue

It is unrealistic to ask every person to technically investigate every site they visit. Browsers, search engines, domain registries, hosting providers, and payment systems hold signals that can break the chain before reaching the user.

DoppelCart thus illustrates a broader principle: when attacks become industrialized, defense must follow suit. Against one hundred thousand fake shops, individual vigilance is helpful, but it cannot be the only firewall.

Sources