SodaStream, Velasca and Daniel Wellington: DoppelCart fraud network uses 119,000 fake shops to steal credit cards

SodaStream, Velasca and Daniel Wellington: DoppelCart fraud network uses 119,000 fake shops to steal credit cards

DoppelCart: Massive Fake E-Shop Network Steals Payment Data via 119,000 Domains

German cybersecurity firm Nebty has uncovered DoppelCart, a sprawling network of over 119,000 fake e-commerce sites designed to steal payment card details. The operation, identified as the largest publicly documented fake-shop cluster by domain count, dwarfs the previous record-holder, BogusBazaar (75,000 sites), which logged an estimated 850,000 fraudulent transactions.

Most of DoppelCart’s domains (2.72% of the entire .SHOP top-level domain) remain active, with over 105,000 still operational. Analysis reveals that 96% of the confirmed shops share identical build files and resolve to just 27 commerce backends, suggesting centralized control. The sites impersonate legitimate brands by replicating product catalogs, branding, and even loading assets directly from real company servers.

DoppelCart mimics 44,182 brands, with a median of two clones per brand. However, high-profile targets like SodaStream, Velasca, and Daniel Wellington face over 30 fake shops each. The fraudulent stores lure victims with discounts of up to 65%, then harvest sensitive data including card numbers, CVV codes, cardholder names, emails, and physical addresses via real-time WebSocket transmissions to command-and-control (C2) servers. Some checkout pages even relay one-time bank confirmation codes, potentially enabling attackers to bypass security protections.

Notably, some fake shops display the impersonated brand’s legitimate support contact, redirecting frustrated victims to the real company when orders fail to arrive. Nebty’s attempts to engage the network’s primary hosting provider went unanswered. To aid brands in identifying abuse, the firm has released a searchable database for detecting DoppelCart impersonations.

Source: https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/

SodaStream TPRM report: https://www.rankiteo.com/company/sodastream-international-ltd-

Velasca TPRM report: https://www.rankiteo.com/company/velasca

Daniel Wellington TPRM report: https://www.rankiteo.com/company/danieli

"id": "sodveldan1788906339",
"linkid": "sodastream-international-ltd-, velasca, danieli",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Consumer Goods',
                        'name': 'SodaStream',
                        'type': 'Brand'},
                       {'industry': 'Fashion',
                        'name': 'Velasca',
                        'type': 'Brand'},
                       {'industry': 'Fashion',
                        'name': 'Daniel Wellington',
                        'type': 'Brand'}],
 'attack_vector': 'Fake e-commerce websites',
 'data_breach': {'data_exfiltration': 'Yes (via WebSocket transmissions to C2 '
                                      'servers)',
                 'personally_identifiable_information': 'Cardholder names, '
                                                        'emails, physical '
                                                        'addresses',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Payment card details, personally '
                                             'identifiable information (PII), '
                                             'one-time bank confirmation '
                                             'codes'},
 'description': 'German cybersecurity firm Nebty has uncovered *DoppelCart*, a '
                'sprawling network of over 119,000 fake e-commerce sites '
                'designed to steal payment card details. The operation '
                'impersonates legitimate brands by replicating product '
                'catalogs, branding, and even loading assets directly from '
                'real company servers. The fraudulent stores lure victims with '
                'discounts of up to 65%, then harvest sensitive data including '
                'card numbers, CVV codes, cardholder names, emails, and '
                'physical addresses via real-time WebSocket transmissions to '
                'command-and-control (C2) servers. Some checkout pages even '
                'relay one-time bank confirmation codes, potentially enabling '
                'attackers to bypass security protections.',
 'impact': {'brand_reputation_impact': 'High (impersonation of 44,182 brands)',
            'data_compromised': 'Payment card details (card numbers, CVV '
                                'codes, cardholder names, emails, physical '
                                'addresses), one-time bank confirmation codes',
            'identity_theft_risk': 'High',
            'operational_impact': 'Brand impersonation leading to customer '
                                  'distrust and potential financial fraud',
            'payment_information_risk': 'High',
            'systems_affected': '119,000+ fake e-commerce domains'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'corrective_actions': 'Brands should proactively '
                                                  'monitor for impersonation '
                                                  'and educate customers on '
                                                  'identifying fake shops.',
                            'root_causes': 'Centralized control of fake '
                                           'e-commerce sites, impersonation of '
                                           'legitimate brands, social '
                                           'engineering via discounts'},
 'recommendations': 'Brands should monitor for impersonation using tools like '
                    "Nebty's searchable database, enhance customer awareness "
                    'of fake shops, and implement stronger verification for '
                    'online transactions.',
 'references': [{'source': 'Nebty'}],
 'response': {'remediation_measures': 'Nebty released a searchable database '
                                      'for detecting DoppelCart impersonations',
              'third_party_assistance': 'Nebty (cybersecurity firm)'},
 'title': 'DoppelCart: Massive Fake E-Shop Network Steals Payment Data via '
          '119,000 Domains',
 'type': 'Payment Data Theft',
 'vulnerability_exploited': 'Impersonation of legitimate brands, social '
                            'engineering (discounts)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.