Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Explore retail threat intelligence trends, including leaked credentials, counterfeit sellers, lookalike domains, paid ad abuse, and social impersonation.
Retail & Consumer Goods
Report Date: 08/28/2026
The biggest retail exposure between March and July 2026 came from leaked credentials. Credential and dark-web monitoring surfaced more retail data than any individual impersonation channel, with exposure concentrated in gift-card balances and loyalty accounts. One credential dump against a single gift-card platform accounted for most of the sector's May exposure on its own.
Counterfeit selling increasingly shifted to marketplaces and smaller e-commerce storefronts over the period. Activity on these channels was minimal in April, but grew to become the largest source of impersonation activity by July. Lookalike domains also remained a significant source of activity, increasingly serving as one component of broader, multi-channel campaigns.
Paid abuse against retail brands appeared on Bing almost as frequently as on Meta, highlighting a potential coverage gap for programs focused primarily on Meta. Social impersonation spreads across Facebook, Instagram, and TikTok in near equal thirds, so a program scoped to one platform sees roughly a third of the problem.
Overall, retail threats during this period were driven by credential exposure, a shift toward marketplaces and e-commerce storefronts, and abuse of paid advertising channels.
Every month in the window carried confirmed activity across multiple surfaces, meaning monitoring and takedown capacity needed to support a consistent volume of threats without relying on seasonal lulls.
Confirmed activity against the typical retail brand roughly quadrupled between April and July, outpacing the broader market. In April the typical retail brand saw about 40 percent less confirmed activity than the typical brand in other industries. By July, it saw about two and a half times as much. Because retail activity increased relative to other industries, not just in overall volume, the data points to a retail-specific shift rather than a broader increase affecting all sectors.
A retail team benchmarking against a cross-industry average could be planning for less than half the volume it now handles. Most of that gap opened in just four months, meaning capacity set at the start of the year may already be insufficient.
Consumers trust retail brands, promotions run constantly, and payment and loyalty details sit right behind the login. That combination gives attackers a large audience and a fast way to turn access into money.
Retail Activity vs Market (per-brand median)

Confirmed retail impersonation was dominated by lookalike domains through the spring before shifting toward other channels. Lookalike domains carried between about a half and two thirds of monthly activity from March through June, primarily appearing as fake storefronts, promotion pages, and spoofed brand sites. By July, marketplace listings had overtaken them.
Social impersonation splits almost evenly in three ways: Facebook at about 30 percent, Instagram at 27 percent, and TikTok at 22 percent, with Telegram and X together making up most of the remainder. In paid abuse, Facebook Ads carry roughly 47 percent, Bing Ads close to 40 percent, and Google Ads under 15 percent. Messaging abuse is entirely carrier SMS.
A retail brand that monitors Meta properties and Google Ads, which is the common configuration, is watching a little over half of its social exposure and about six in ten of its paid exposure.
Retail Confirmed Activity by Surface (Share of the Month)

Monitoring scoped to a single social platform, or to Google and Meta advertising alone, creates predictable coverage gaps, particularly across lower-cost advertising channels. Activity also migrates between surfaces faster than most review cycles run, so a surface-by-surface monitoring approach risks focusing on where attackers were rather than where they are moving next.
About three quarters of campaigns touch no domain at allAcross Doppel telemetry, only about a quarter of tracked impersonation campaigns involve a domain. Paid ads appear in roughly 46 percent, social media in 44 percent, and messaging in 36 percent. A program that watches for lookalike domains alone sees nothing of the other three quarters, and sees only part of the campaigns it does catch.
This measure spans all of Doppel's telemetry, so it is broader than retail alone. As retail impersonation moves further onto marketplaces, advertising, and social, domain monitoring captures a shrinking share of the real footprint.
05. CREDENTIAL AND DATA EXPOSURE
Leaked gift-card and loyalty data is the largest retail exposure in this window, larger than any impersonation surface. Credential leaks accounted for most of this exposure, with leaked data concentrated in stored value and account access.
Because these are leaked records identified through monitoring rather than impersonation threats, no remediation action was taken, and this activity is not included in the impersonation figures elsewhere in the report.
A gift-card platform produced repeated large leaks, including a May event that by itself accounted for most of the sector's exposure that month, then recurred at lower volume in June and July. A cannabis retailer produced a steady monthly stream throughout, suggesting ongoing account-data leakage throughout the period. A specialty jewelry retailer also appeared in the data in July.
The resulting fraud often targets stored value because a gift-card balance is transferable, hard to reverse, and rarely covered by chargeback protection. A loyalty account often holds a saved payment method behind weaker login controls than the payment method itself. The FTC reported that consumers lost $15.9 billion to fraud in 2025, up from about $12 billion the year before.
Retail Credential and Dark-Web Exposure by Month (Indexed)

One Chinese hosting network, AS199242 (Beijing Ruihao Kai Yuan Technology), carries close to 20 percent of the malicious domains observed for retail brands, and a second network carries another 14 percent. Two providers account for a third of the sector's malicious hosting between them.
A third of a sector's malicious domains sitting behind two named networks is worth a standing abuse relationship with each. Reporting domains one at a time as they surface will never keep pace. It points in the same direction as the counterfeit finding above, since China accounts for about 45 percent of global counterfeit seizures.
A single CDN fronts about 60 percent of these domains, and that figure is not worth acting on. Mainstream CDNs front malicious and legitimate traffic alike, so the share reflects where the internet is hosted and says nothing about where an attacker chose to be. Domain parking at Bodis and registrar infrastructure at Namecheap account for most of the remainder, with smaller volumes on Alibaba Cloud and Asiatech.
These figures are a lower bound, drawn from the portion of activity enriched with external infrastructure signals.
Marketplace activity went from about 1 percent of confirmed impersonation in April to roughly a third in June and the largest single surface in July. That is where counterfeit retail selling now happens.
The bulk of it sits on long-tail e-commerce storefronts, away from the major platforms most brands watch, with Shein the most prominent named marketplace in the later months and eBay, Amazon, Alibaba, Etsy, 1688, Facebook Marketplace, and Craigslist all appearing earlier in the window. A specialty jewelry retailer and an apparel and lifestyle group carried most of the volume, which fits the categories that dominate counterfeit seizures worldwide.
The OECD and EUIPO estimate global trade in counterfeit goods at $467 billion, about 2.3 percent of world imports, with clothing, footwear, and leather goods together making up 62 percent of seizures. The pattern in this telemetry is the online retail edge of that trade.
For a brand protection program built around domain takedowns, this is the hardest of the three findings to act on. A counterfeit listing has a different escalation path than a lookalike domain. It reappears under a new seller identity, so registrar escalation does not apply, and enforcement depends on each marketplace's own process.
Below are three representative patterns from the window, described generically. Brand names are withheld.
Stored-value leak at scale. A gift-card platform saw repeated large credential and balance-data leaks, with one May event producing most of the sector's exposure for that month and smaller recurrences in June and July. The exploitable asset is a transferable balance, so the fraud does not require a card.
Counterfeit storefront network. A specialty jewelry retailer was impersonated across long-tail e-commerce storefronts and marketplace listings, growing through June and July to become the sector's largest single source of confirmed activity. Listings recurred under new seller identities after removal.
Multi-surface apparel impersonation. An apparel and lifestyle group was impersonated simultaneously on marketplace listings, lookalike domains, and social accounts, with the same product ranges appearing across all three. No single surface would have shown the campaign's real size.
Stored-value and loyalty exposure. Monitor for leaked gift-card codes, balances, and loyalty credentials as a distinct feed from payment-card exposure. Rate-limit and re-verify balance transfers and account recovery, which is where leaked stored value converts to loss.
Marketplace enforcement. Build a standing escalation path with each major marketplace and treat long-tail e-commerce storefronts as the primary counterfeit surface. Track seller identity reuse across removals so repeat operators are visible.
Advertising coverage beyond Meta and Google. Extend paid-abuse monitoring to Bing, which carries close to 40 percent of paid impersonation against the sector. Cheaper inventory is where campaigns go when the large platforms tighten.
Social breadth over social depth. Cover Facebook, Instagram, and TikTok together, since the three split the surface almost evenly. Connect account takedowns to the domains and listings they point at.
Hosting and parking escalation. Consolidate abuse reporting against the two networks that carry a third of the sector's malicious domains between them. Domain-by-domain reporting will not keep pace.
Findings are based on Doppel telemetry across a global customer base, with strongest coverage in North America.
Doppel protects individuals and brands from AI-powered impersonation, phishing, fraud, and social engineering by dismantling attacker infrastructure and building resilience through training and simulation.
Doppel's comprehensive Digital Risk Protection solution detects threats across multiple channels, links alerts into a real-time threat graph, and offers AI-driven infrastructure disruption. These threats inform phishing simulation campaigns and security awareness training to offer robust Human Risk Management capabilities that strengthen employee defenses through next-generation training and testing.
Doppel's mission is to protect the world from social engineering attacks every day. Founded in 2022, Doppel is an AI-native platform designed for social engineering defense.
Median Takedown Time Domains, Social Media, Paid Ads
<10h
Faster takedowns on emerging threat vectors than our competitors.
Indicators Analyzed Daily
+1B
Faster takedowns on emerging threat vectors than our competitors.
Trusted Customers
200+




Prepared by Doppel SECR - Social Engineering Counterintelligence & Research