Skip to main content
Blog Threat Intelligence

DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network

One network of copied stores accounts for nearly 3 percent of the .shop domains in our snapshot. We are publishing the database so affected brands can find themselves in it.

A printing press reproduces a storefront into a long row of identical online shops, illustrated in blue and coral

Around 119,000 domains, connected by shared infrastructure and recurring features in their shop software. Product catalogs from real businesses, copied descriptions and original images. And customers whose complaints end up with the legitimate store. We investigated a fake-shop network whose scale surprised even us. We call it DoppelCart.

To our knowledge, DoppelCart is the largest fake-shop cluster publicly documented to date, measured by the number of associated domains. Its .shop domains alone account for 2.72 percent of the .shop domain population in our snapshot. That is roughly one in every 37 domains.

We are publishing the complete investigation database so businesses can search for their own brand. Companies that need help with takedowns can contact us. Journalists and security researchers can also request the underlying raw data.

119,000

domains associated with the cluster, rounded

2.72%

of the .shop domain population in our snapshot

106,095

HTML pages archived in the investigation

From individual customer cases to 119,000 domains

The investigation began in our day-to-day work. We found fake shops targeting several customers and arranged for their removal. During those takedowns, the providers involved kept showing the same patterns. We also encountered them in ongoing monitoring and audits for customers.

The cases involved different businesses but had striking similarities. We began asking how many more stores belonged to this infrastructure. Using publicly accessible website scans from urlscan, we quickly connected several thousand domains.

The full scale only became apparent as the investigation progressed. A trail that began with individual customer cases grew into around 119,000 associated domains. Behind the different shop names, a recurring system emerged: different brand identities built on the same technical foundation.

How large this network really is

A six-figure domain count is hard to put in perspective. The share of .shop makes it more tangible: our comparison places 118,787 distinct .shop domains belonging to the cluster against a population of 4,361,908 .shop domains. Both figures refer to the data examined in September 2026. This is a zone snapshot: a directory of domains listed in DNS under .shop. It does not tell us how many legitimate or fraudulent stores are open at the same time.

The scale is also exceptional alongside other publicly documented networks. The best-known comparison is BogusBazaar, for which SRLabs reported more than 75,000 domains in 2024. More recent investigations have documented other large networks:

Published figures; observation periods and counting methods differ.
InvestigationReported scaleWhat was counted
DoppelCart · nebty, September 2026Around 119,000 domainsAssociated with the cluster
BogusBazaar · SRLabs, 202475,000+ domainsAcross several years; about 22,500 active in April 2024
FraudWear · CTM360, 202630,000+ domainsOver time; about 8,000 simultaneously active
Malwarebytes, March 202620,000+ domainsCluster with shared infrastructure
Fibergrid · Netcraft, April 202616,700 active fake shopsOn connected hosting infrastructure

Real products, real images, fake stores

Much of these stores’ credibility comes from the businesses they copy. In the examples we examined, visitors see real product names, detailed descriptions and original material from the affected brands. Shoppers who already know the products encounter plenty that looks familiar.

In one fake shop we examined, product descriptions had been copied word for word from the legitimate online store. The copy even included detailed explanations of product features and construction. Comparing the archived HTML with the original store shows how thoroughly this content was reproduced.

In another examined storefront, the archived HTML references numerous files on the affected brand’s own image server, including product graphics and icons. Some of the material is therefore embedded directly from the legitimate store’s infrastructure.

It is a persuasive combination: known products, familiar images and an apparent special offer. The examples show how the deception works.

The real business receives the complaints

Our customers report complaints about orders they never received. Buyers expect a delivery or an explanation and turn to the real business. They first have to learn that they ordered from a different website that was misusing its identity.

Fake shops contribute to this by listing the legitimate store’s support address on their pages. To a buyer, that contact address looks like another sign of an official store. When problems arise, it sends the complaint directly to the company whose content was copied.

For the affected brand, that creates work. Support teams have to establish what happened, distinguish someone else’s order from their own business and respond to disappointed people. Trust in the legitimate store can suffer even though it received neither the order nor the payment.

Why we are publishing the database

Businesses should be able to find out whether their brand is affected without first having to contact a vendor. That is why we are making the complete investigation dataset accessible. The database supports searches for brand names and domains, with classifications and available evidence for individual entries.

The linked view starts with confirmed entries that have a detected brand name. Filters also provide access to the rest of the dataset. This includes further suspected cases, domains that no longer resolve and entries already ruled out. The total number of database rows is therefore higher than the number of confirmed cluster members.

Is your brand in the database?

Search for your brand name or domain. Try alternative spellings and the names of individual stores where relevant.

Search the DoppelCart database →

Journalists and security researchers can request an export and the underlying raw data, including archived HTML pages, at [email protected]. We also welcome reports of incorrect associations there. A dataset of this size needs to be open to scrutiny and correction.

What affected brands can do now

A database match gives you a concrete starting point. Review the listed site and any available captures: which content comes from your store, and whose identity is being used? Websites change, so a takedown needs to reflect the current state. Our website scanner can create a fresh capture for review.

The takedowns we have carried out for customers against stores in this cluster have worked: so far, the removed stores have stayed offline in our observations. At the same time, we observe that the majority of the cluster remains online. Its scale is a reason to search for your own brand and act on specific findings.

We help affected businesses review findings and pursue website and domain takedowns. The discovered domains and the address of your legitimate store are particularly useful for identifying the copied material.

Found a fake shop using your brand?

Send us the relevant domains and a link to your legitimate store. We can help you take the next steps.

Request a takedown →

Or email [email protected].

Further reading: How to remove a fake shop and how to safely investigate suspicious websites.

About the author

Benedikt Scheungraber

Benedikt Scheungraber

Co-Founder & CEO, nebty

Benedikt founded nebty to make professional brand protection accessible to businesses of all sizes. He writes about digital threats, domain abuse, and how companies can defend their online identity.