October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

BogusBazaar fraud network used 75,000 fake webshops to target more than 850,000 shoppers

BogusBazaar was a scalable fake-webshop network—not proof that 850,000 cards were stolen. Here is what SRLabs found and what shoppers should do after using a suspicious store.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security Research Labs (SRLabs) identified BogusBazaar, a criminal ecommerce network linked to more than 75,000 fake-shop domains since 2021. Its May 2024 findings describe more than 850,000 affected customers, over one million orders and estimated aggregate order volume above $50 million, mainly in the United States and Western Europe.

Those figures do not prove that 850,000 unique credit-card numbers were stolen. SRLabs documented both payment-card harvesting and orders for merchandise that usually never arrived. The evidence is best understood as a large-scale fake-shopping operation, not a confirmed count of stolen cards or total consumer losses.

What BogusBazaar was

BogusBazaar was SRLabs’ name for a scalable criminal network of online stores. The shops mainly advertised shoes, clothing and supposedly branded goods at unusually low prices. They often looked like ordinary WordPress and WooCommerce stores rather than crude phishing pages. Custom logos, product catalogs and checkout flows helped create the appearance of legitimate retail businesses.

The network reused expired domains, apparently taking advantage of search-engine reputation that those domains had accumulated before being repurposed. Storefronts could be created or replaced semi-automatically, allowing operators to move quickly when a domain or payment route was blocked. SRLabs’ technical account is available at its BogusBazaar report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How large was the operation?

Measure What the evidence says Important qualification
Domains More than 75,000 associated with the network since 2021 A cumulative total over time, not 75,000 simultaneous shops
Active domains About 22,500 in April 2024 A dated snapshot, not a current 2026 count
Customers More than 850,000 affected Not a confirmed count of stolen cards or people who all lost money
Orders More than one million Not every order was successfully paid
Order volume Estimated above $50 million Estimated aggregate order volume, not confirmed criminal revenue or total losses

SRLabs said victims were concentrated in Western Europe and the United States. Some sites were offline after researchers shared findings with relevant stakeholders, so the 2024 figures should not be presented as proof that the same network remains active today.

How the fake shops took money or card data

  1. Attraction: A shopper found a heavily discounted product, often through search results or a reused domain.
  2. Checkout: The site collected contact and payment information through a page designed to resemble a normal retailer’s checkout.
  3. Card harvesting: The page could retain card details while showing an error or redirecting the shopper elsewhere.
  4. Fake selling: The store could accept payment for expensive goods that never arrived. Some victims reportedly received cheap counterfeit or unrelated products.
  5. Payment completion: In some cases, a shopper first entered details into a spoofed form and was then sent to a functioning gateway to complete a charge.

SRLabs identified payment flows involving PayPal, Stripe and card processors. That does not mean those companies’ core systems were breached or that a familiar payment logo validates the merchant.

Rank #2
Sale
Mastering Internal Controls and Fraud Prevention
  • 78 pages (45 self-teaching + 33 quizzes/answers)

Why the scheme scaled

A platform-and-franchise structure

Rather than one shop run by one group, SRLabs described a fraud-as-a-service or infrastructure-as-a-service model. A core team maintained backend systems, software and customized WordPress plugins, while decentralized “franchisees” operated individual storefronts. Stores, payment gateways and management applications were hosted separately, allowing domains and payment pages to be rotated when blocked.

Shared technology

Newer stores primarily used WordPress and WooCommerce; earlier versions also used Zen Cart and OpenCart. Servers commonly hosted roughly 200 shops, with some hosting more than 500. Many systems sat behind Cloudflare. SRLabs identified most servers in the United States and assessed China as the likely operational hub; server location alone does not establish where individuals physically operated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Separate signals across providers

Search engines, registrars, hosting companies, content-delivery networks and payment providers each see different parts of the operation. Shared plugins, repeated infrastructure and rotating payment pages can help investigators connect storefronts that appear unrelated. Removing one domain therefore may not remove the underlying platform.

Warning signs of a fake webshop

  • Prices far below normal market levels for popular branded products.
  • An unrelated, recently repurposed or otherwise inconsistent domain name.
  • Missing, vague or implausible company contact details.
  • Poorly written shipping, refund, privacy or company-information pages.
  • Different company names, addresses, currencies or payment descriptors during checkout.
  • A checkout page that suddenly looks unrelated to the storefront.
  • Requests for gift cards, wire transfers, cryptocurrency or payment-app transfers.
  • No credible independent reviews, or reviews that appear copied or manufactured.
  • Social accounts with little history, engagement or evidence of real customers.
  • Pressure to pay immediately or refusal to explain delivery and returns.

The Federal Trade Commission recommends researching a seller and its URL with terms such as “review,” “complaint” or “scam,” checking refund terms, using a credit card where possible, and keeping receipts and confirmation emails. See the FTC’s online-shopping guidance and its holiday scam guidance.

An HTTPS padlock only means the connection is encrypted. It does not prove who owns the domain, that the seller has inventory, or that the business will honor a refund. The FDIC recommends checking the URL, monitoring account statements and using official retailer apps or reputable marketplaces when appropriate: FDIC consumer guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you used one of these sites

If you entered card details

  1. Call the card issuer immediately using the number on the physical card or its official app.
  2. Explain that the card details may have been submitted to a fraudulent online store.
  3. Ask whether the card should be locked or replaced.
  4. Check recent and pending transactions for unfamiliar activity.
  5. Dispute unauthorized or problematic charges through the issuer.
  6. Save the URL, order confirmation, emails, screenshots, receipts and unusual checkout behavior.
  7. Report the incident at ReportFraud.ftc.gov.

Do not wait for a fraudulent charge before notifying the issuer. Even a failed checkout may have exposed the number for later testing, resale or misuse. BleepingComputer also reported that millions of stolen card details were resold on dark-web marketplaces, but that report should not be converted into a confirmed BogusBazaar victim count: BleepingComputer’s coverage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you were charged but nothing arrived

  • Contact the seller once, if a credible contact channel exists, but do not send additional card details or identity documents to obtain a refund.
  • Dispute the transaction with your credit-card issuer for non-delivery or material misrepresentation.
  • Keep every email, receipt, tracking message and screenshot.
  • For a U.S. purchase, report the seller to the FTC and your state consumer-protection office or attorney general.
  • For a foreign seller, consider USA.gov’s complaint guidance, including Econsumer.gov.

If you reused a password

Change it anywhere else it was used and enable multifactor authentication. This is a precaution against account takeover; it does not establish that BogusBazaar obtained your password.

If you submitted identity information

If the site collected a Social Security number, identity document or other sensitive information, use the FTC’s identity-theft resources and follow the relevant recovery steps. The core SRLabs findings focus on card harvesting and fraudulent sales, not every category of identity theft.

Credit card, debit card and pending-charge decisions

  • Credit card: FTC guidance generally indicates stronger dispute protections for online purchases. Contact the issuer promptly and keep evidence; a successful chargeback is not guaranteed.
  • Debit card: Call the bank immediately because funds may have left a deposit account directly.
  • Pending authorization: It may disappear without settling, but exposed card details still warrant an issuer call.
  • Completed charge: Dispute it promptly through the issuer’s official channel.

Use contact details from the card or official app, never a number supplied by the suspicious shop.

What this incident does—and does not—show

BogusBazaar demonstrates industrialized online-shopping fraud: expired domains, automated storefront deployment, shared infrastructure and rotating payment paths can make many fake shops look independent. It does not establish that every affected customer lost money, that every order was paid, that 850,000 cards were stolen, or that the network is still operating at the 2024 scale.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Optional tools such as virtual cards, identity monitoring, password managers and multifactor authentication can reduce future risk, but none replaces calling the issuer, replacing an exposed card or disputing a charge. A professional design, HTTPS and a recognizable payment brand are not substitutes for independently verifying the seller.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.