FRITZ! and Dreame: 119,000 fake shops take your card at checkout

A search for a robot vacuum or a new FRITZ!Box can land you on a copy. Security firm nebty, based in Munich, has documented a network of 119,012 confirmed shop domains. The full database is now public. The pages take product photos, descriptions and the whole look of real retailers. In some cases they load the graphics straight from the copied company’s own image server. Under the .shop suffix alone nebty counts 118,787 such addresses. That is 2.72 percent of the 4,361,908 .shop domains it examined. The largest comparable network documented in public until now was BogusBazaar, which reached about 75,000 domains in 2024.
German shoppers are not a side note here. The database lists 12 shops that name FRITZ! as the brand. Among them are avmonline.shop, fritzstore.shop and fritzdirect.shop. All 12 were classed as probably live when we checked on Sept. 13. Robot vacuum maker Dreame accounts for 72 entries. We reviewed its L10s Ultra Gen 3 vacuum earlier this year. On some of those shops the page title reads DREAME Stores Deutschland. Others pose as country outlets for Italy, France, Spain and Belgium. EcoFlow, Bluetti, Roborock, Narwal, Jackery, Keychron, HyperX and Sennheiser appear in the record as well.
The support address belongs to the real manufacturer
The one detail buyers check does not separate these shops from the real ones. Many of them give the support address of the brand they copy. dreametechpro.shop gives support.it@dreame.com as its contact, an address on the real maker’s own domain. A buyer whose order never arrives complains to a company that never saw the order. That company’s support staff then has to explain where the money and the goods went. nebty counts 2,494 such exposed contact addresses in the record.
The same pattern showed up last week at Trezor, where the phishing email went out from the maker’s own sending address. The sign that is supposed to prove a shop is real gets copied too. The fake shops add a second layer. Some pages use invented addresses such as support@dreame-store.com, which look just as plausible at a glance.
The checkout collects your card before you click buy
Payment is where the damage happens. nebty tested several checkout pages in the network. It found code that collects the card number, expiration date, security code, name, email address, phone number and postal address. The report the company shared with BleepingComputer says those fields travel one by one over a WebSocket connection to the attackers’ server. They go the moment they are typed. Submitting the form is not required.
The same report says the code can also relay the one-time code a bank sends to approve the payment. That approval protects you from someone using your stolen card data somewhere else. It does not protect you from confirming a payment to the fraudster. That is what you do when you approve it yourself. nebty’s public blog post does not include this finding. It comes from the report handed to the trade outlet.
How to spot the copies
One clue on its own proves nothing. Several together do. The shops advertise discounts of up to 65 percent on real products. The addresses follow a visible pattern of brand name plus a filler word such as store, direct, global or hub. The suffix is almost always .shop. nebty chief executive Benedikt Scheungraber says 96 percent of the confirmed pages share identical build files and resolve to 27 shared commerce backends. That uniformity is what made the cluster visible in the first place. You can look up an address in the public database. The manufacturer’s own site and its list of authorized dealers is the more reliable route.
The network is still running. More than 105,000 shops were still reachable as of the investigation. nebty says it contacted the hosting provider behind most of the pages and got no answer. Targeted takedowns on behalf of affected brands do work. The shops removed that way have stayed offline, according to nebty’s observations.





