Fake retail sites are collecting payment details and bank confirmation codes

BRIEF
The DoppelCart campaign is reported to operate more than 100,000 fake online stores that imitate real retailers. The sites are designed to collect shoppers’ card information and one-time confirmation codes used by banks. A convincing storefront can therefore turn a routine purchase into both payment-card theft and an attempt to defeat an additional banking check. The number of stores is a reported campaign figure, not an independently established measure of successful victims or losses in the supplied material. Attacker-controlled pages may claim to offer genuine products, discounts, or a normal checkout; those claims are not evidence that the merchant is real. The available research supports the fake-store network and the collection of payment details and one-time codes, but it does not identify every affected retailer or explain how each stolen code is used. Consumers and businesses should treat unexpected payment prompts and unfamiliar domains as potential fraud signals.
WHY IT MATTERS
A fake store can capture more than a card number. If a shopper enters a bank-delivered confirmation code into the counterfeit checkout, the attacker may gain information intended to authorize or verify a separate transaction. This makes ordinary anti-phishing advice relevant to shopping sites, payment pages, text messages, and bank alerts. The reported network size indicates substantial opportunity for exposure, but it does not show that every listed site is active or that every visitor loses money. Banks, card issuers, merchants, and customers should combine payment monitoring with domain, merchant, and customer-education controls.