Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

BogusBazaar: How a Fake-Shop Network Defrauded More Than 850,000 Customers

By TheFinanceBase Team7 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

BogusBazaar was a criminal network of fake online shops that used counterfeit checkout pages and bogus sales to steal payment details or take money without delivering genuine goods. SRLabs reported more than 850,000 affected customers by April 2024, but that is a dated estimate—not a verified live count or a count of confirmed card thefts.

What was BogusBazaar?

BogusBazaar was not one fake store. Security firm SRLabs described a large, organized e-commerce fraud operation built around shared infrastructure, automated tools and separate operators running individual storefronts. The researchers characterized it as an infrastructure-as-a-service model: a core group supplied technology and services that let others deploy and operate shops.

“Franchise” is a useful analogy for that division of work, not evidence that BogusBazaar was a legally registered franchise or a single confirmed company. SRLabs identified China as the operation’s main hub, but that does not establish the identities or nationality of every operator. The researchers also found that much of the hosting infrastructure was in the United States; server location does not show where a shop’s operators are based.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The core findings were published by SRLabs on May 8, 2024. Dark Reading reported on them the following day. The headline’s “& Counting” wording should not be read as a current, continually updated total: the figures below describe SRLabs’ findings at that time.

How large was the operation?

SRLabs’ figures describe an identified network and estimated activity, not an audited account of confirmed losses. In particular, order volume is not the same as successful payments or criminal profit.

Measure SRLabs finding What it means
Associated domains More than 75,000 Domains linked to the network; not all were active at once.
Active domains Approximately 22,500 as of April 2024 A point-in-time estimate, not a current count.
Orders More than 1 million since 2021 Not every order resulted in a successful payment.
Aggregate order volume Estimated above $50 million Not confirmed proceeds, retained criminal profit, or total consumer losses.
Customers affected More than 850,000 Reported as primarily in the United States and Western Europe. The available findings do not establish that every record was a unique person or that each person lost money or had card details harvested.
Hosting and infrastructure Mostly U.S.-hosted servers; China identified as the main operating hub Technical infrastructure location does not establish operator location.

All figures in the table are from SRLabs’ May 2024 research. The $50 million estimate should not be described as money the operators necessarily received or kept. SRLabs said not every order produced a successful payment, so actual primary financial damage was lower than aggregate order volume; the published figures do not establish the total loss from later misuse of stolen cards.

How did the fake shops attract shoppers?

Branded goods at tempting prices

The stores mainly advertised shoes and apparel associated with well-known brands, often at unusually low prices. Counterfeit branding and steep discounts could make a listing attractive, but a low price or unfamiliar domain by itself is not proof of fraud.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Expired domains and borrowed credibility

SRLabs said operators often reused expired domains with favorable Google reputations. An expired domain may retain an older history, backlinks or search visibility even after a different person takes it over and puts up a new shop. Shoppers can mistake that inherited reputation—or a prominent search result—for a recommendation. Neither domain age nor search placement verifies the current seller.

Shared tools, many storefronts

Current shops in SRLabs’ analysis primarily used WooCommerce on WordPress; earlier examples also used Zen Cart and OpenCart. Customized WordPress plugins supported the stores. SRLabs reported that a typical server hosted roughly 200 shops and some hosted more than 500; servers could be associated with more than 100 IP addresses. Cloudflare was used to expose or front shops, and payment pages could be changed separately from storefronts.

These details describe how criminals abused common web and payment infrastructure. They are not evidence that WordPress, WooCommerce, Cloudflare, PayPal, Stripe or card processors participated in the fraud. Legitimate services can be misused by fraudulent merchants.

What happened during checkout?

The operation combined two related but distinct harms: card harvesting and fake selling. A shopper might encounter one or both.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. The shopper found a store through a search result, advertisement, link or expired domain.
  2. The store offered branded-looking merchandise, often at an unusually attractive price.
  3. At checkout, the shopper might enter a name, address, email and payment details into a counterfeit payment page. That page could capture the card information even if the transaction failed.
  4. In another flow, the shop accepted an order and payment but did not ship the goods, or sent cheap counterfeit merchandise instead.
  5. Some shoppers first entered card details into a fraudulent interface, received an error, and were then redirected to a genuine payment gateway to complete another transaction. A successful second payment did not undo the earlier exposure.

Stolen card details could later be used for unrelated fraud. But the network-wide estimate does not mean every visitor had a card number stolen, every order succeeded, or every customer experienced the same sequence. A failed checkout is not proof that no sensitive information was captured.

How can you assess an unfamiliar online store?

No single check reliably proves a shop is safe. These steps can reduce risk, but they are not a guaranteed detection system.

  • Verify the seller’s business name, physical address and customer-service details independently; do not rely only on information displayed on the shop itself.
  • Search the business name alongside terms such as “scam,” “complaint,” “counterfeit” and “non-delivery.” Look for consistent, independent information rather than relying on one rating.
  • Check whether the domain appears newly registered, redirected or unrelated to the business it claims to represent. An older domain can change hands, and a new domain is not automatically fraudulent.
  • Compare prices with the brand and established retailers. A dramatic discount merits scrutiny, but price alone is not proof.
  • Read shipping, return, refund and privacy policies. Copied, contradictory or incomplete wording is a warning sign, not conclusive evidence.
  • Be wary when a generic email address is the only way to contact the seller.
  • Avoid payment links in unsolicited messages or social-media ads. Navigate to a seller independently when possible.
  • Where available, a credit card generally offers a clearer route to dispute a charge than a bank transfer, cryptocurrency or gift card. Check your issuer’s procedures; protections vary by payment method and circumstances.
  • Do not treat HTTPS or a padlock as a trust mark. HTTPS encrypts the connection; it does not verify the seller’s honesty, authorization to sell a brand or ability to deliver.
  • Do not treat Google placement or a familiar payment logo as proof. A fraudulent storefront can appear in search, and a genuine payment gateway at the end of checkout does not validate what happened earlier in the flow.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if you entered payment or account details?

If you entered card details

  1. Contact the card issuer immediately using the number on the physical card or in the issuer’s official app. Explain that the card details were entered on a suspected fake shop and ask whether to block and replace the card.
  2. Review pending as well as completed transactions. Dispute unauthorized charges through the issuer, and do not wait for a suspicious charge to appear before reporting the exposure.
  3. Save the store URL, order confirmation, messages, screenshots and transaction details. These can help when speaking with the issuer or making a report.

If you paid by bank transfer, debit card or another method, contact the bank or payment provider promptly and ask what recovery or dispute options apply. The available options depend on the method and provider.

If you reused a password

Change it on the affected account and everywhere else you used it. Turn on multifactor authentication where available. Be alert to follow-up emails, texts and calls: details submitted to a fake shop can make later phishing attempts more convincing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you submitted identity information

If you provided a Social Security number, driver’s-license number or other sensitive identity information, consult the FTC’s consumer guidance and consider whether a fraud alert or credit freeze is appropriate. A freeze primarily restricts access to credit files for new-credit applications; it does not prevent every kind of fraud.

Report the incident in the United States

You can report suspected fraud to the Federal Trade Commission and internet-enabled crime to the FBI’s Internet Crime Complaint Center. Reporting does not replace contacting your card issuer or bank about exposed payment details.

What remains uncertain?

SRLabs’ public findings provide a substantial snapshot of the operation, but they do not settle several questions: the precise number of unique victims, the exact consumer loss, how many people had card data harvested, the total downstream losses from card misuse, the identities of individual operators, or the network’s current status and active-domain count. SRLabs described takedowns alongside tools for rapidly rotating domains and payment pages; takedowns therefore do not establish that the entire operation was dismantled. The 2024 measurements should not be presented as a verified 2026 count.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.