Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
BogusBazaar was a criminal network of fake online shops that used counterfeit checkout pages and bogus sales to steal payment details or take money without delivering genuine goods. SRLabs reported more than 850,000 affected customers by April 2024, but that is a dated estimate—not a verified live count or a count of confirmed card thefts.
What was BogusBazaar?
BogusBazaar was not one fake store. Security firm SRLabs described a large, organized e-commerce fraud operation built around shared infrastructure, automated tools and separate operators running individual storefronts. The researchers characterized it as an infrastructure-as-a-service model: a core group supplied technology and services that let others deploy and operate shops.
“Franchise” is a useful analogy for that division of work, not evidence that BogusBazaar was a legally registered franchise or a single confirmed company. SRLabs identified China as the operation’s main hub, but that does not establish the identities or nationality of every operator. The researchers also found that much of the hosting infrastructure was in the United States; server location does not show where a shop’s operators are based.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →The core findings were published by SRLabs on May 8, 2024. Dark Reading reported on them the following day. The headline’s “& Counting” wording should not be read as a current, continually updated total: the figures below describe SRLabs’ findings at that time.
#1 Best Overall
How large was the operation?
SRLabs’ figures describe an identified network and estimated activity, not an audited account of confirmed losses. In particular, order volume is not the same as successful payments or criminal profit.
| Measure | SRLabs finding | What it means |
|---|---|---|
| Associated domains | More than 75,000 | Domains linked to the network; not all were active at once. |
| Active domains | Approximately 22,500 as of April 2024 | A point-in-time estimate, not a current count. |
| Orders | More than 1 million since 2021 | Not every order resulted in a successful payment. |
| Aggregate order volume | Estimated above $50 million | Not confirmed proceeds, retained criminal profit, or total consumer losses. |
| Customers affected | More than 850,000 | Reported as primarily in the United States and Western Europe. The available findings do not establish that every record was a unique person or that each person lost money or had card details harvested. |
| Hosting and infrastructure | Mostly U.S.-hosted servers; China identified as the main operating hub | Technical infrastructure location does not establish operator location. |
All figures in the table are from SRLabs’ May 2024 research. The $50 million estimate should not be described as money the operators necessarily received or kept. SRLabs said not every order produced a successful payment, so actual primary financial damage was lower than aggregate order volume; the published figures do not establish the total loss from later misuse of stolen cards.
How did the fake shops attract shoppers?
Branded goods at tempting prices
The stores mainly advertised shoes and apparel associated with well-known brands, often at unusually low prices. Counterfeit branding and steep discounts could make a listing attractive, but a low price or unfamiliar domain by itself is not proof of fraud.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Expired domains and borrowed credibility
SRLabs said operators often reused expired domains with favorable Google reputations. An expired domain may retain an older history, backlinks or search visibility even after a different person takes it over and puts up a new shop. Shoppers can mistake that inherited reputation—or a prominent search result—for a recommendation. Neither domain age nor search placement verifies the current seller.
Shared tools, many storefronts
Current shops in SRLabs’ analysis primarily used WooCommerce on WordPress; earlier examples also used Zen Cart and OpenCart. Customized WordPress plugins supported the stores. SRLabs reported that a typical server hosted roughly 200 shops and some hosted more than 500; servers could be associated with more than 100 IP addresses. Cloudflare was used to expose or front shops, and payment pages could be changed separately from storefronts.
These details describe how criminals abused common web and payment infrastructure. They are not evidence that WordPress, WooCommerce, Cloudflare, PayPal, Stripe or card processors participated in the fraud. Legitimate services can be misused by fraudulent merchants.
What happened during checkout?
The operation combined two related but distinct harms: card harvesting and fake selling. A shopper might encounter one or both.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches- The shopper found a store through a search result, advertisement, link or expired domain.
- The store offered branded-looking merchandise, often at an unusually attractive price.
- At checkout, the shopper might enter a name, address, email and payment details into a counterfeit payment page. That page could capture the card information even if the transaction failed.
- In another flow, the shop accepted an order and payment but did not ship the goods, or sent cheap counterfeit merchandise instead.
- Some shoppers first entered card details into a fraudulent interface, received an error, and were then redirected to a genuine payment gateway to complete another transaction. A successful second payment did not undo the earlier exposure.
Stolen card details could later be used for unrelated fraud. But the network-wide estimate does not mean every visitor had a card number stolen, every order succeeded, or every customer experienced the same sequence. A failed checkout is not proof that no sensitive information was captured.
How can you assess an unfamiliar online store?
No single check reliably proves a shop is safe. These steps can reduce risk, but they are not a guaranteed detection system.
- Verify the seller’s business name, physical address and customer-service details independently; do not rely only on information displayed on the shop itself.
- Search the business name alongside terms such as “scam,” “complaint,” “counterfeit” and “non-delivery.” Look for consistent, independent information rather than relying on one rating.
- Check whether the domain appears newly registered, redirected or unrelated to the business it claims to represent. An older domain can change hands, and a new domain is not automatically fraudulent.
- Compare prices with the brand and established retailers. A dramatic discount merits scrutiny, but price alone is not proof.
- Read shipping, return, refund and privacy policies. Copied, contradictory or incomplete wording is a warning sign, not conclusive evidence.
- Be wary when a generic email address is the only way to contact the seller.
- Avoid payment links in unsolicited messages or social-media ads. Navigate to a seller independently when possible.
- Where available, a credit card generally offers a clearer route to dispute a charge than a bank transfer, cryptocurrency or gift card. Check your issuer’s procedures; protections vary by payment method and circumstances.
- Do not treat HTTPS or a padlock as a trust mark. HTTPS encrypts the connection; it does not verify the seller’s honesty, authorization to sell a brand or ability to deliver.
- Do not treat Google placement or a familiar payment logo as proof. A fraudulent storefront can appear in search, and a genuine payment gateway at the end of checkout does not validate what happened earlier in the flow.
What should you do if you entered payment or account details?
If you entered card details
- Contact the card issuer immediately using the number on the physical card or in the issuer’s official app. Explain that the card details were entered on a suspected fake shop and ask whether to block and replace the card.
- Review pending as well as completed transactions. Dispute unauthorized charges through the issuer, and do not wait for a suspicious charge to appear before reporting the exposure.
- Save the store URL, order confirmation, messages, screenshots and transaction details. These can help when speaking with the issuer or making a report.
If you paid by bank transfer, debit card or another method, contact the bank or payment provider promptly and ask what recovery or dispute options apply. The available options depend on the method and provider.
If you reused a password
Change it on the affected account and everywhere else you used it. Turn on multifactor authentication where available. Be alert to follow-up emails, texts and calls: details submitted to a fake shop can make later phishing attempts more convincing.
If you submitted identity information
If you provided a Social Security number, driver’s-license number or other sensitive identity information, consult the FTC’s consumer guidance and consider whether a fraud alert or credit freeze is appropriate. A freeze primarily restricts access to credit files for new-credit applications; it does not prevent every kind of fraud.
Best Value
Report the incident in the United States
You can report suspected fraud to the Federal Trade Commission and internet-enabled crime to the FBI’s Internet Crime Complaint Center. Reporting does not replace contacting your card issuer or bank about exposed payment details.
What remains uncertain?
SRLabs’ public findings provide a substantial snapshot of the operation, but they do not settle several questions: the precise number of unique victims, the exact consumer loss, how many people had card data harvested, the total downstream losses from card misuse, the identities of individual operators, or the network’s current status and active-domain count. SRLabs described takedowns alongside tools for rapidly rotating domains and payment pages; takedowns therefore do not establish that the entire operation was dismantled. The 2024 measurements should not be presented as a verified 2026 count.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

