Google general counsel addresses the rise of AI-fueled phishing
Halimah Delaine Prado, who serves as Google’s General Counsel, has shed light on the surge of AI-based phishing scams that are emerging from what she’s termed as China’s “outsider enterprise.” These scammers are leveraging artificial intelligence to craft incredibly realistic fake websites that impersonate well-known brands like T-Mobile, thereby deceiving countless Americans and resulting in substantial financial losses. Prado also outlines how Google plans to tackle these increasingly sophisticated threats.
You might come across an online product that’s 65% off, and at first glance, it seems like an irresistible bargain. The site looks sleek, the brand name feels familiar, and you might think, “Why not?” But that could very well be a trap.
A cybersecurity firm named Nebty found around 119,000 domains related to a deceptive shopping scheme dubbed DoppelCart. These sites seem to mimic authentic businesses, making it easy to swipe payment information at checkout, including one-time bank verification codes.
According to BleepingComputer, over 105,000 DoppelCart stores were observed during Nebty’s recent scans, and the majority of these sites are reportedly still active. So, before you get hooked by what seems like an incredible discount from an unfamiliar store, it’s wise to investigate who’s truly behind that checkout page.
What is DoppelCart?
Nebty stumbled upon DoppelCart while scrutinizing fake online shops that were targeting their clients. As researchers delved deeper, they noticed shared technical traits among stores that were impersonating various businesses. Their investigation eventually linked roughly 119,000 domains to this cluster. Nebty claims that DoppelCart is possibly the largest collection of fake shops documented, at least in terms of associated domains.
However, it’s vital to consider that the common infrastructure doesn’t necessarily indicate that a single individual or group controls every tramp website under the DoppelCart name.
Despite this, the technical similarities are hard to overlook. Nebty’s CEO, Benedikt Scheungraber, shared with BleepingComputer that 96% of the confirmed shops utilized identical build files and resolved to just 27 different commerce backends.
DoppelCart’s extensive reach in the .shop domain
Most of the domains tied to DoppelCart utilize the .shop top-level domain. Nebty’s data from September 2026 indicated that out of 4,361,908 .shop domains, approximately 118,787 distinct ones were associated with this scam cluster. This translates to around 2.72%, or roughly one in every 37 domains in their dataset.
Still, context matters. Nebty pointed out that this snapshot reflects domains active in the .shop DNS zone, and it doesn’t account for how many genuine or fraudulent stores were operational simultaneously.
Previously, researchers documented a fraudulent operation named BogusBazaar, which involved over 75,000 domains. It’s worth noting that differences in observation periods and counting methods may lead to discrepancies in these numbers.
What makes DoppelCart so convincing?
Gone are the days when scam websites were obviously poorly made. Now, DoppelCart sites can swipe product catalogs, descriptions, branding, and other content directly from legitimate companies.
In some instances, investigators discovered that fake stores load assets from the legitimate companies’ servers directly. This, of course, complicates matters for unsuspecting consumers.
You may recognize the brand name. The products look spot on. And nothing about the site screams scam because much of the material originated from the real business.
According to Scheungraber, DoppelCart shops clone a staggering 44,182 brands, typically averaging two clones for each brand. Some brands, like SodaStream and Velasca, attract more attention, with researchers finding over 30 shops targeting them.
The allure of a steep discount
This is where the trap closes in. Most of us tend to shop around online, and finding the same item for a fraction of the price can feel impossible to resist. DoppelCart shops are capitalizing on this reaction.
Researchers have spotted fake stores advertising discounts as steep as 65%. Sure, a heavy discount doesn’t instantly indicate you’re dealing with a scam. Genuine retailers have clearance sales all the time.
But if you’re unfamiliar with the retailer, and their price significantly undercuts everyone else’s, it’s worth taking an extra moment to check who’s behind the sale.
How DoppelCart traps customers
When you hit the checkout, that’s where the trouble really begins. Nebty examined several checkout pages linked to the DoppelCart network and found malicious code collecting:
- Card numbers
- Expiration dates
- Security codes
- Cardholder names
- Email addresses
- Phone numbers
- Physical addresses
The researchers highlighted that in real-time, this information can be sent via WebSockets to command-and-control systems, enabling attackers to capture sensitive details while you’re still on the checkout page.
This method resembles web skimming attacks, where malicious code intercepts payment details as they are entered into an online checkout form. Previously, I’ve discussed how such attacks function and why you might not notice anything askew.
Verification codes can be compromised too
This part really gives me pause. Many of us have been conditioned to view a verification code from our bank as a safety measure. However, DoppelCart has the potential to turn this security measure against you.
It turns out, that the checkout process can also relay the one-time confirmation code generated by a user’s bank. Scammers then attempt to exploit this code to circumvent security measures for a fraudulent transaction.
Thus, don’t just plug in a bank code when prompted without thinking. Carefully read your bank’s message. Pay attention to the merchant and transaction specifics included. If anything seems off, halt the transaction and contact your bank through their official app or the phone number on the back of your card.
Legitimate businesses may also get caught up
After the transaction, a new issue arises. Some fake shops promote genuine companies’ customer service contact information.
Imagine ordering something that never arrives. You search for the support info on the site and reach out to the business, expecting answers.
The legitimate company might be completely oblivious to your order because, well, you didn’t actually purchase anything from them. Nebty noted that authentic businesses often receive complaints from frustrated shoppers over orders they never processed.
While the scammer benefits from your payment details, the legitimate brand ends up dealing with the angry customer trying to sort out what happened.
Nebty attempted to reach out to the primary hosting service associated with DoppelCart sites but didn’t get a response.
How to identify a fake online store
A polished website alone isn’t a solid indicator of a retailer’s reliability these days. So, slow down a bit when shopping on unfamiliar sites.
1) Verify the web address
Check the domain in your browser before entering any payment details. A fraudulent site may integrate a recognizable company name within an entirely different domain. When purchasing from a well-known brand, find its official site independently. And don’t let the HTTPS or padlock icons mislead you. While HTTPS indicates an encrypted connection, it doesn’t mean the seller behind the site is legitimate—scammers can secure their websites too.
2) Be wary of extraordinary discounts
A 65% discount might push you to make a purchase before the offer vanishes. This is when it’s crucial to hold back. Look for the product on the official website or compare prices with known retailers. If the price is drastically lower, further investigate.
3) Research unfamiliar retailers
Before you buy, search the store’s name online. Look beyond reviews that might appear on the website itself. Seek independent complaints or reports linking the domain to scams. Verify the retailer’s contact information as well; a cloned site may seem impressive but lack real credibility.
4) Pay with a credit card whenever possible
The Federal Trade Commission suggests using credit cards for online purchases, as they provide better protection when things go awry. Some issuers even allow you to use virtual card numbers, which can keep your main card number hidden from merchants.
5) Read bank verification messages closely
Don’t treat verification codes as routine. Carefully read any message your bank sends. If the merchant or transaction details seem unfamiliar, steer clear from entering the code, and instead, contact your card issuer through a trusted method.
6) Set up transaction alerts
Check if your bank offers notifications for account activity. Alerts can help you quickly identify any unfamiliar transactions. Don’t dismiss a small charge just because it looks innocuous—any unrecognized transaction warrants a second look.
7) Use effective security software
Strong antivirus software can warn you of harmful websites and links. However, no software will catch every newly created fake shopping site, which is why your judgment remains crucial when an unknown store presents an enticing bargain.
Steps to take if you’ve entered payment on a suspicious site
If you think you may have purchased from a DoppelCart or a similar fraudulent site, act quickly. The FTC recommends reaching out to your financial institution as soon as possible.
Contact your card issuer immediately
Use the contact number on the back of your card or access your bank’s official app. Inform the issuer that you may have entered your card details on a potentially fraudulent website. Ask whether you should lock your card or get a new number, and mention if you also provided a one-time verification code.
Audit your account for suspicious activity
Review your recent transactions and keep an eye on your account. If you made a purchase at a fake store, inform your issuer that it likely involved a scam, and report any other unfamiliar charges. The FTC suggests contacting your card issuer or bank to discuss the possibility of reversing fraudulent transactions.
Change passwords if reused
If the fake store prompted you to create an account and you used a password from another site, update that password on all original accounts. Utilize unique passwords for important accounts. A password manager can assist in generating and securely storing robust passwords without the need to memorize them.
Be cautious of follow-up scams
Keep in mind, DoppelCart’s checkout pages can harvest your contact and payment information. Be wary of unexpected messages from your bank, as well as delivery notifications or refund offers. Scammers often target individuals who have already lost money, presenting themselves as helpers for recovery. Always go directly to your bank or the business’s official site instead of clicking on unexpected links.
Run a security scan if something was downloaded
If you downloaded files, installed software, or provided a suspicious site access to your device, update your security software and run a thorough scan. If you only entered card information, focus on securing your payment account and monitoring for any fraudulent charges.
Report the fake store
Report suspected scamming to the Federal Trade Commission via ReportFraud.ftc.gov. Your reports can assist authorities in identifying trends and investigating fraudulent operations.
Key takeaways
What truly troubles me about DoppelCart is its capability to create deceptively convincing fake stores. You might recognize the brands and products because they replicate them from real businesses. Personally, it changes how I feel about a bargain from unfamiliar stores. If a price appears unusually low, I want to verify who I’m buying from before giving any card info. Taking that little extra moment to check the web address could save you from the trouble of replacing cards or dealing with unauthorized charges later.
Have you ever come across an online store that seemed completely legitimate but raised your suspicions? What clued you in? Share your experience at Cyberguy.com.






