:

DOPPELCART FRAUD NETWORK RUNS 119,000 FAKE SHOPS

INDUSTRY DESK1 MIN READ
TUE, SEP 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A large-scale fraud operation dubbed DoppelCart uses over 119,000 domains to operate counterfeit e-commerce sites designed to steal payment card details from unsuspecting customers.

Security researchers identified the DoppelCart network after tracking the sophisticated operation's infrastructure and attack patterns. The fake shops mimic legitimate retailers, creating convincing storefront experiences to capture customer credit card information during checkout. The scale of the operation underscores the growing challenge of payment fraud in e-commerce. With over 119,000 domains involved, the network demonstrates significant resources and coordination among threat actors. Victims enter payment details believing they are purchasing from real vendors, but their card information flows directly to the fraud network operators. The domains are distributed across multiple hosting providers and registrars, making takedown efforts difficult. Experts recommend customers verify website URLs before entering payment information, use credit monitoring services, and opt for payment methods offering fraud protection. E-commerce platforms and payment processors continue developing detection mechanisms to identify and block fraudulent storefronts.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cisco's President Jeetu Patel joined executives from OpenAI, Anthropic, and others in signing an open letter warning that AI-enabled cyberattacks will likely become more widespread and sophisticated. The same AI capabilities that boost productivity can be weaponized by malicious actors.

JUST NOWAI Desk

Anthropic has warned users about unauthorized token theft after discovering hackers accessing Claude accounts. The breach prompted the AI company to alert subscribers about potential account compromises.

JUST NOWAI Desk

Attackers have breached F5 BIG-IP APM devices to deploy a Linux rootkit capable of injecting malicious code directly into memory. The attack bypasses disk-based detection by intercepting PHP file loading.

1H AGODev Desk

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, requiring software vendors to disclose actively exploited flaws within 24 hours. Vendors must now prove exactly what shipped and when vulnerabilities were discovered.

1H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.