LegalBrandGuard

BogusBazaar: anatomy of a fake-storefront network

Updated on August 5, 2026 · LegalBrandGuard · 3 min read

Quick answer

BogusBazaar is a network of fake stores documented in 2024 by Security Research Labs: more than 75,000 fraudulent domains and roughly 850,000 victims. It operates as a service model, with an infrastructure team and operators — which explains why a shut-down domain is immediately replaced.

The documented scale

The figures below come from the investigation published by Security Research Labs, a German cybersecurity company, in 2024. They cover a single network — others exist.

IndicatorReported value
Fraudulent domains identifiedmore than 75,000
Estimated victimsroughly 850,000
Stores per serverroughly 200
Most affected regionsWestern Europe and the United States

The point of these figures is not to dramatize, but to correct a common intuition. Discovering a fake site feels like an isolated incident, the work of one individual. It is in fact one element of mass production.

A service model, not a craftsman

This is the point that changes everything for a targeted brand. The network does not operate like a lone fraudster who builds one site and then moves on to the next.

Researchers describe a two-tier organization: a central team that provides and maintains the infrastructure — servers, store templates, payment chains — and operators who run the stores without needing any particular technical skill.

Direct consequence: shutting down a domain does not touch the infrastructure. It costs the operator the price of a domain name, and the store reopens elsewhere.

Payment, decoupled from the storefront

An analysis published in May 2026 by Allure Security, building on the SRLabs investigation, details a second architectural choice: the payment page is not tied to the storefront. When a payment provider blocks a page for fraud, the operator installs a new one — the store itself does not change.

SRLabs describes "extensive orchestration capabilities [that] enable [it] to quickly deploy new webshops or rotate payment pages and domains in response to take-downs." Cutting a payment channel slows down the money coming in, without ever touching the store itself.

The preference for expired domains

One technical detail of the investigation has significant practical consequences: the network favors domains that have expired and already carry a favorable reputation with search engines.

A freshly registered domain draws suspicion from security filters and search engines. A domain with a history, bought back after expiring, inherits part of that trust.

This adds a nuance to the signal most often recommended for spotting a fake site — domain age. An old domain is not necessarily legitimate if it has changed hands.

Domain names that carry no trace of the brand

These networks have adapted their practices to existing defense mechanisms. The UDRP procedure, the traditional arbitration route, relies on similarity between the domain name and the brand: a generic domain escapes it by design.

Hence the use of names with no apparent connection to the brand being copied, even though the site's content reproduces it in full.

What this changes for a brand

Three practical consequences follow from how this operates.

  • A single takedown is not enough. Shutting down a domain helps the customers who would have encountered it, but does not touch the network. Across a portfolio Allure Security estimated at 22,500 active domains in May 2026, one isolated takedown accounts for 0.004% of it — the underlying infrastructure stays intact. Monitoring matters as much as one-off action.
  • Searching by domain name is not enough. Stores with generic names escape any permutation-based search.
  • Acting early shifts the balance of power. A domain that has been registered but is not yet online has neither customers nor revenue to claim.

Key takeaways

  • Each server hosts roughly 200 stores on average, with backup domains kept in reserve — replacing a shut-down domain costs the operator only the price of a domain name.
  • The payment page is decoupled from the storefront: when a provider blocks it for fraud, the operator installs another one without touching the site, according to a May 2026 analysis by Allure Security building on the SRLabs investigation.
  • The network favors expired domains that already carry a favorable reputation with search engines, which adds a nuance to domain age as a reliable trust signal.
  • Some stores carry entirely generic names with no connection to the copied brand — a strategy that makes them invisible to the UDRP procedure and to domain-name-based searches.
  • Across a portfolio estimated at 22,500 active domains in May 2026, one isolated takedown accounts for only 0.004% of it: the underlying infrastructure survives each individual shutdown.
  • Acting before a domain actually goes live shifts the balance of power, since it then has neither customers nor revenue to point to.

Frequently asked questions

What is BogusBazaar?+
A criminal network of fake online stores documented in 2024 by Security Research Labs, a German cybersecurity company. Their investigation identifies more than 75,000 fraudulent domains and roughly 850,000 victims, mainly in Europe and the United States.
Why is a shut-down domain immediately replaced?+
Because the creation process is industrialized. The network operates as a service model: a central team manages the infrastructure, and operators run the stores. One server hosts roughly 200 stores, and domains are kept in reserve. Shutting down a domain costs the operator only a few euros.
How does this network choose its domains?+
Researchers note a preference for expired domains that already have a favorable reputation with search engines. Buying a domain with an existing history makes it possible to bypass the distrust that affects freshly registered names.
Do these networks only target major brands?+
No. Selection is automated and picks out brands whose catalog can be exploited and whose recognition is strong enough to generate searches. Mid-sized brands are particularly exposed: well-known enough to attract traffic, rarely covered by active monitoring.

Check your own brand

Our analysis combines two approaches: variants of your domain name, and sites that display your brand without carrying it in their address.

Scan my site for free

Sources

See also: recognizing a fake site impersonating your brand.