For Windows users, the practical risk is familiar: a convincing store can appear in a search result, social-media advertisement, browser recommendation, or message, then guide a customer through a checkout that looks routine. The more serious allegation is about what happens at that checkout. The WebSocket, one-time-code, active-shop, shared-build-file, and backend claims discussed below are nebty findings—or a nebty executive statement—reported by BleepingComputer. They are not the result of independently reproduced testing in this article.
That distinction matters. It lets shoppers take a credible warning seriously without treating every entry in a large technical dataset as a court-proven fraud case.
What the 119,012 figure actually counts
nebty’s published statistics list 119,012 confirmed members of what it calls the DoppelCart cluster, alongside 153,943 total database domains, 44,783 attributed brands, 106,095 archived pages, and 2,494 exposed contacts. These are large figures, but they measure different things and should not be combined into one broader claim.
Most importantly, the 119,012 total is a count of confirmed domain entries, not necessarily a count of unique domain names. When entries with and without the www prefix are merged, nebty says the number becomes 118,996 distinct domains. That 16-entry difference does not materially change the scale of the finding, but it shows why exact wording matters.
The figures also describe a capture period rather than a permanent live view of the internet. The recorded dataset cutoff was September 4, 2026, with a published export dated September 5. Domains can be registered, suspended, moved, repurposed, or taken offline quickly. A listed site may no longer resolve, while a new clone may emerge after the capture date.
nebty’s methodology adds another important limitation. A “confirmed member” is classified through shared infrastructure and recurring shop-software characteristics. That label does not mean every site was manually reviewed, reachable at the same time, or conclusively proven to have accepted a payment. It is a technical-cluster finding.
This prevents two opposite mistakes: dismissing a large and patterned body of evidence because it is not a list of individually adjudicated cases, or treating every database entry as a permanently live and conclusively established scam.
A cluster is not proof of a single operator
DoppelCart appears to be a useful label for a pattern of sites with technical similarities. It should not be presented as the name of a proven single organization.
nebty cautions that common technical traits do not establish common control. Shared templates, infrastructure, checkout components, or deployment practices could result from a common service provider, a reused kit, affiliates, copied code, or multiple operators using the same system. The available material does not identify who operates the cluster, where they are located, or whether every listed store is controlled by one party.
BleepingComputer reported a statement attributed to nebty’s chief executive that 96% of confirmed shops shared identical build files and resolved to 27 commerce backends. If accurate, that helps explain how a large number of storefronts could be deployed and maintained through a comparatively small number of shared systems. It does not, however, establish who controls those systems or that all associated domains have the same operator or purpose.
There is also a small numerical inconsistency in the reported brand count. nebty’s public statistics list 44,783 attributed brands, while BleepingComputer reported a figure of 44,182 attributed to the company’s chief executive. The available material does not reconcile the difference. The cautious conclusion is that the reported impersonation set is very large and may be revised, rather than that either number is a final total.
What the checkout allegation means
The investigation describes sites that copied legitimate companies’ product names, descriptions, and original materials. In at least one archived example, the page HTML reportedly referenced files on the impersonated brand’s image server. Reusing familiar product photography and polished descriptions is an effective way to make an imitation shop feel authentic.
The key security issue comes at checkout. According to BleepingComputer’s reporting on nebty’s testing of several DoppelCart payment pages, card and personal-data fields were transmitted in real time through WebSockets to command-and-control infrastructure. The report also said the code could relay a bank-issued one-time confirmation code.
If that behavior is present on a particular store, the harm may extend beyond an undelivered purchase. A shopper could pay for goods that never arrive while also exposing payment and personal information during the transaction. A one-time code deserves particular caution because it may be used in a bank’s transaction-verification process.
But the evidence has clear boundaries. The reported observation concerns several tested checkout pages, not every domain in the dataset. It is not established that every DoppelCart-listed site used the same payment-data collection mechanism, requested a one-time code, or was live when a shopper attempted to buy something.
Likewise, BleepingComputer’s report that nebty’s scans found more than 105,000 shops still active is a time-specific scan result, not a stable network total. In this context, “active” can mean a domain resolved or served content during a scan. It does not necessarily prove that checkout was functional, that advertised goods were available, or that the site remained online later.
Familiar branding is not seller verification
The broader lesson does not depend on any one brand name or individual record. A familiar logo, product catalogue, or manufacturer name is not evidence that an unfamiliar seller is legitimate. Impersonation works precisely because a copied store can borrow the appearance of a business that shoppers already trust.
For purchases involving routers, smart-home gear, robot vacuums, PCs, gaming hardware, or other electronics, start from a manufacturer’s known official website or a retailer whose identity you can independently establish. Do not let a search result, sponsored listing, unusually steep discount, or polished product page become the whole basis for trust.
Practical checks include:
- Check the complete domain name in the address bar, rather than only the brand name displayed in the page design. Misspellings, extra words, strange subdomains, and unexpected domain endings warrant closer attention.
- Research an unfamiliar seller before paying. Look for a business identity and customer-service route that can be independently verified, rather than relying solely on reviews or testimonials hosted by the shop.
- Be skeptical of prices far below normal market pricing, especially for high-demand or expensive electronics.
- Compare the retailer named in the address bar with the business name on the checkout page, receipt, contact details, and return policy.
- Treat countdown timers, scarcity claims, and demands to pay immediately as reasons to pause rather than reasons to rush.
None of these checks is a perfect detector. A sophisticated impersonation operation can register plausible domains, copy policies, and build convincing support pages. The aim is to replace an impulsive decision with verification that does not come from the seller alone.
The padlock protects the connection, not the merchant
A deceptive shop can use HTTPS. The padlock indicates that the connection between the browser and the website is encrypted. It does not establish that the party running the site is honest, that the domain belongs to the brand shown on the page, or that an order will be fulfilled.
The Federal Trade Commission makes the same distinction: the “s” in https indicates encryption, not legitimacy. Encryption remains important—shoppers should not enter payment information on an unencrypted page—but it is not merchant authentication.
Keeping Windows, browsers, and security software current is sensible baseline protection. Browser and endpoint security tools can help flag known malicious destinations and reduce exposure to other threats, but shoppers should still independently verify an unfamiliar seller before entering payment information. A technically secure connection can lead directly to a dishonest merchant.
Payment choices and action after a suspect purchase
For an unfamiliar merchant, the FTC recommends using a credit card where possible. If an item does not arrive, card charges can be disputed. That does not guarantee reimbursement, and it does not reverse any exposure of personal information, but it can provide a meaningful recovery path that other payment methods may lack.
If you suspect that you entered details into a lookalike shop, act promptly:
- Contact the card issuer using the number on the physical card or in the issuer’s official app or website. Do not rely on a phone number or link supplied by the suspected seller.
- Clearly distinguish the problem. If an unrecognized transaction appears, or you believe card details were captured, report possible unauthorized card use and ask the issuer how to secure the account. If you knowingly placed an order but it does not arrive, ask about disputing the charge as an undelivered-order problem.
- If you entered a bank verification or one-time code during checkout, tell the issuer that specifically. It may help the issuer understand the transaction sequence.
- Retain receipts, order confirmations, communications, screenshots, the site address, and account statements. These records can help with a dispute and with a fraud report.
- After contacting the card issuer, U.S. readers should report a suspected shopping scam to the FTC. Reporting does not itself resolve a card dispute, but it helps document the scam and can support broader enforcement work.
- Watch for unexpected transactions and follow-up messages seeking more codes, passwords, or personal information. A second contact may be part of the same attempt.
- Change any password reused on the suspect shop, especially if it was also used for email, financial services, or other retailers.
A large finding with real limits
DoppelCart’s reported scale is notable even beside earlier large-scale shop-imitation investigations. In August 2024, SRLabs described BogusBazaar as involving more than 75,000 domains, with roughly 22,500 active as of April that year. The methodologies are not identical, so those numbers are not a direct ranking. They do show that mass-produced deceptive storefronts are not isolated events.
The most defensible reading of nebty’s figures is that they identify a vast, technically related set of suspected lookalike commerce sites. The checkout behavior reported from testing of several pages raises the potential stakes beyond an ordinary bargain-hunting mistake. Yet neither the entry count nor the shared technical footprint proves one operator, universal live status, universal payment-data theft, total victim losses, or responsibility for every listed domain.
For shoppers, uncertainty is not a reason for complacency. It is a reason to use disciplined habits: reach sellers through known official routes, independently verify unfamiliar merchants, understand that HTTPS is encryption rather than proof of legitimacy, preserve records, and use payment methods with a meaningful dispute process.