Security Research Labs (SRLabs) identified BogusBazaar, a criminal ecommerce network linked to more than 75,000 fake-shop domains since 2021. Its May 2024 findings describe more than 850,000 affected customers, over one million orders and estimated aggregate order volume above $50 million, mainly in the United States and Western Europe.
Those figures do not prove that 850,000 unique credit-card numbers were stolen. SRLabs documented both payment-card harvesting and orders for merchandise that usually never arrived. The evidence is best understood as a large-scale fake-shopping operation, not a confirmed count of stolen cards or total consumer losses.
What BogusBazaar was
BogusBazaar was SRLabs’ name for a scalable criminal network of online stores. The shops mainly advertised shoes, clothing and supposedly branded goods at unusually low prices. They often looked like ordinary WordPress and WooCommerce stores rather than crude phishing pages. Custom logos, product catalogs and checkout flows helped create the appearance of legitimate retail businesses.
The network reused expired domains, apparently taking advantage of search-engine reputation that those domains had accumulated before being repurposed. Storefronts could be created or replaced semi-automatically, allowing operators to move quickly when a domain or payment route was blocked. SRLabs’ technical account is available at its BogusBazaar report.
Recommended Free Tools
#1 Best Overall
How large was the operation?
| Measure | What the evidence says | Important qualification |
|---|---|---|
| Domains | More than 75,000 associated with the network since 2021 | A cumulative total over time, not 75,000 simultaneous shops |
| Active domains | About 22,500 in April 2024 | A dated snapshot, not a current 2026 count |
| Customers | More than 850,000 affected | Not a confirmed count of stolen cards or people who all lost money |
| Orders | More than one million | Not every order was successfully paid |
| Order volume | Estimated above $50 million | Estimated aggregate order volume, not confirmed criminal revenue or total losses |
SRLabs said victims were concentrated in Western Europe and the United States. Some sites were offline after researchers shared findings with relevant stakeholders, so the 2024 figures should not be presented as proof that the same network remains active today.
How the fake shops took money or card data
- Attraction: A shopper found a heavily discounted product, often through search results or a reused domain.
- Checkout: The site collected contact and payment information through a page designed to resemble a normal retailer’s checkout.
- Card harvesting: The page could retain card details while showing an error or redirecting the shopper elsewhere.
- Fake selling: The store could accept payment for expensive goods that never arrived. Some victims reportedly received cheap counterfeit or unrelated products.
- Payment completion: In some cases, a shopper first entered details into a spoofed form and was then sent to a functioning gateway to complete a charge.
SRLabs identified payment flows involving PayPal, Stripe and card processors. That does not mean those companies’ core systems were breached or that a familiar payment logo validates the merchant.
Rank #2
- 78 pages (45 self-teaching + 33 quizzes/answers)
Why the scheme scaled
A platform-and-franchise structure
Rather than one shop run by one group, SRLabs described a fraud-as-a-service or infrastructure-as-a-service model. A core team maintained backend systems, software and customized WordPress plugins, while decentralized “franchisees” operated individual storefronts. Stores, payment gateways and management applications were hosted separately, allowing domains and payment pages to be rotated when blocked.
Shared technology
Newer stores primarily used WordPress and WooCommerce; earlier versions also used Zen Cart and OpenCart. Servers commonly hosted roughly 200 shops, with some hosting more than 500. Many systems sat behind Cloudflare. SRLabs identified most servers in the United States and assessed China as the likely operational hub; server location alone does not establish where individuals physically operated.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Separate signals across providers
Search engines, registrars, hosting companies, content-delivery networks and payment providers each see different parts of the operation. Shared plugins, repeated infrastructure and rotating payment pages can help investigators connect storefronts that appear unrelated. Removing one domain therefore may not remove the underlying platform.
Warning signs of a fake webshop
- Prices far below normal market levels for popular branded products.
- An unrelated, recently repurposed or otherwise inconsistent domain name.
- Missing, vague or implausible company contact details.
- Poorly written shipping, refund, privacy or company-information pages.
- Different company names, addresses, currencies or payment descriptors during checkout.
- A checkout page that suddenly looks unrelated to the storefront.
- Requests for gift cards, wire transfers, cryptocurrency or payment-app transfers.
- No credible independent reviews, or reviews that appear copied or manufactured.
- Social accounts with little history, engagement or evidence of real customers.
- Pressure to pay immediately or refusal to explain delivery and returns.
The Federal Trade Commission recommends researching a seller and its URL with terms such as “review,” “complaint” or “scam,” checking refund terms, using a credit card where possible, and keeping receipts and confirmation emails. See the FTC’s online-shopping guidance and its holiday scam guidance.
Rank #4
An HTTPS padlock only means the connection is encrypted. It does not prove who owns the domain, that the seller has inventory, or that the business will honor a refund. The FDIC recommends checking the URL, monitoring account statements and using official retailer apps or reputable marketplaces when appropriate: FDIC consumer guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do if you used one of these sites
If you entered card details
- Call the card issuer immediately using the number on the physical card or its official app.
- Explain that the card details may have been submitted to a fraudulent online store.
- Ask whether the card should be locked or replaced.
- Check recent and pending transactions for unfamiliar activity.
- Dispute unauthorized or problematic charges through the issuer.
- Save the URL, order confirmation, emails, screenshots, receipts and unusual checkout behavior.
- Report the incident at ReportFraud.ftc.gov.
Do not wait for a fraudulent charge before notifying the issuer. Even a failed checkout may have exposed the number for later testing, resale or misuse. BleepingComputer also reported that millions of stolen card details were resold on dark-web marketplaces, but that report should not be converted into a confirmed BogusBazaar victim count: BleepingComputer’s coverage.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
If you were charged but nothing arrived
- Contact the seller once, if a credible contact channel exists, but do not send additional card details or identity documents to obtain a refund.
- Dispute the transaction with your credit-card issuer for non-delivery or material misrepresentation.
- Keep every email, receipt, tracking message and screenshot.
- For a U.S. purchase, report the seller to the FTC and your state consumer-protection office or attorney general.
- For a foreign seller, consider USA.gov’s complaint guidance, including Econsumer.gov.
If you reused a password
Change it anywhere else it was used and enable multifactor authentication. This is a precaution against account takeover; it does not establish that BogusBazaar obtained your password.
If you submitted identity information
If the site collected a Social Security number, identity document or other sensitive information, use the FTC’s identity-theft resources and follow the relevant recovery steps. The core SRLabs findings focus on card harvesting and fraudulent sales, not every category of identity theft.
Credit card, debit card and pending-charge decisions
- Credit card: FTC guidance generally indicates stronger dispute protections for online purchases. Contact the issuer promptly and keep evidence; a successful chargeback is not guaranteed.
- Debit card: Call the bank immediately because funds may have left a deposit account directly.
- Pending authorization: It may disappear without settling, but exposed card details still warrant an issuer call.
- Completed charge: Dispute it promptly through the issuer’s official channel.
Use contact details from the card or official app, never a number supplied by the suspicious shop.
What this incident does—and does not—show
BogusBazaar demonstrates industrialized online-shopping fraud: expired domains, automated storefront deployment, shared infrastructure and rotating payment paths can make many fake shops look independent. It does not establish that every affected customer lost money, that every order was paid, that 850,000 cards were stolen, or that the network is still operating at the 2024 scale.
Free tools Windows power users keep installed
One-click scans. No signup required.
Optional tools such as virtual cards, identity monitoring, password managers and multifactor authentication can reduce future risk, but none replaces calling the issuer, replacing an exposed card or disputing a charge. A professional design, HTTPS and a recognizable payment brand are not substitutes for independently verifying the seller.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




