119,000 fake shops, and the checkout asks for the code your bank just texted you
In July we wrote about 120 fake Walmart shops selling whiskey that did not exist. That now looks like a cottage industry. Researchers at the German security firm Nebty have published details of a network they call DoppelCart: almost 119,000 fake shop domains, of which more than 105,000 are still trading. It accounts for 2.72 percent of every .shop address they examined, which makes it the largest fake-shop cluster anyone has documented by domain count.
The shops clone real businesses. Product catalogues, descriptions, logos and photographs, sometimes pulled straight off the genuine company's own servers. Nebty counted 44,182 brands copied, roughly two fake shops apiece, though some got far more attention than that: SodaStream, Daniel Wellington, CurrentBody, Dreame, Horze, Velasca, MOVA and SPARK PAWS each have over 30 clones. Discounts run up to 65 percent, which is the whole point. Underneath, 96 percent of the sites share identical build files and report to just 27 back ends, so this is one operation, not thousands.
Here is the part worth remembering. The checkout does not simply harvest your card number, expiry date and security code and store them for later. It streams everything to the operators as you type, over WebSockets, and it will also ask for the verification code your bank sends by text. Someone is on the other end pushing a real payment through in real time. So a code arriving from your bank mid-checkout is not proof the shop is genuine. It may be proof that it is not.
The defence is boring and it works: do not arrive at a shop from an advert. Type the retailer's name yourself, or search for the exact web address plus the word reviews before you buy. Pay by credit card, where a fraudulent charge can be reversed. And if one of these sites also talked you into installing something or added a browser extension along the way, Tendvane's "browser hijacked" repair wizard is the quickest way to put your browser back the way it was.