The fake Walmart store scam: discount ads that harvest your card
Malwarebytes counted more than 120 near-identical fake Walmart storefronts, all cut from one WooCommerce template, all promoted through mobile ads offering name-brand liquor at 40 to 70 percent off. Tap the ad and you land on a page wearing Walmart's logo, colours and layout. Add to cart, reach the checkout, type your card, and the number, expiry and CVV go straight to the operators. There is no real store behind it. This is the fake-website version of the Walmart scam, and it is a different animal from the phone-call gift-card version.
No order ships. The store exists to copy your card.
The bottom line: any Walmart "store" you reach from a discount ad, on a domain that is not walmart.com, is there to steal your card, not to sell you anything. On July 29, 2026, Malwarebytes documented more than 120 of these fake storefronts. They borrow Walmart's branding but sit on generic .shop names Walmart does not own, such as allgoodscenter.shop, marketbasketcenter.shop, broadbasket.shop, smartbasketplace.shop and valueparcel.shop. The real Walmart store is only ever at walmart.com. Each fake page harvests your full card number, expiry and CVV at checkout, then goes quiet. This is not the Walmart phone-call gift-card scam, which we cover separately; this one is a fake website.
The ad promised 60% off premium vodka. That was the hook.
The scam starts where you already are: scrolling on your phone. An ad slides into a feed or a game, showing a bottle of premium spirits, a familiar retail logo and a number that stops your thumb. Sixty, seventy percent off. A price no store runs, on a brand no store discounts that hard.
Tap it and the storefront that opens looks the part. The right blue, a spark logo close enough to pass a glance, a tidy grid of products with slashed prices, a footer with a US business address and a phone number. It reads as a real Walmart sale you happened to catch. Malwarebytes found the same template repeated across the network: identical catalogue, identical prices, identical images, only the domain changing from one site to the next.
You add a couple of bottles, maybe some heavily discounted household goods to round out the cart, and reach the checkout. It asks for the usual: name, shipping address, and the full card number, expiry date and CVV. You enter them. The page may thank you, may error, may just hang. It does not matter which, because the moment your card details left the form, the operators had everything they wanted. There is no real store or inventory behind it. The address and phone in the footer are invented, and there is no store behind them.
One template, cloned into a hundred storefronts
What makes this campaign worth a warning is not a single clever site. It is the assembly line. Malwarebytes reported more than 120 of these fake Walmart stores running at once, every one of them stamped from the same WordPress and WooCommerce template. Same product catalogue, same prices, same photos, same layout. Swap the domain and you have another store, ready to advertise.
Each one carries a fabricated US business address and phone number in the footer, the paperwork of legitimacy without any of the substance. That volume is deliberate. When one domain gets reported, blocklisted and taken down, ten more are already live, so the ads keep pointing somewhere that still works. It is the same disposable-infrastructure logic behind other fake online store scams and the counterfeit sellers we documented on TikTok Shop: cheap to spin up, meant to be thrown away.
The structural weakness is the same as the strength. A hundred lookalike storefronts can copy Walmart's page pixel for pixel, but not one of them can be walmart.com. The address bar is the part the template cannot fake.
How to spot a fake Walmart store
You do not need to inspect the code. Every tell on this list is visible before you type a single digit.
- The discount is impossible. Name-brand spirits at 40 to 70 percent off is bait, not a sale. Real retailers do not clear premium liquor at those margins. If the price is the reason you are here, that is the red flag doing its job.
- The domain is not walmart.com. Walmart's online store lives only at walmart.com. A generic name like broadbasket.shop or valueparcel.shop, with no Walmart identity in it, is not Walmart no matter how the page looks.
- The branding is borrowed, the domain is not. Logo, colours and layout are trivial to copy. Ownership of the address is not. Copied branding on a domain the brand does not own is the whole scam in one sentence.
- You arrived from an ad, not by typing. A tapped ad is a path someone paid to put in front of you. Close it and type walmart.com yourself; if the sale is real, it will be there.
- The footer address and phone prove nothing. A US address and a phone number are two lines of text anyone can invent. On this network they are fabricated and lead nowhere.
- An unfamiliar site is asking for your full card. If you have never bought from this domain and it wants the card number, expiry and CVV, stop. That is the point where the scam collects.
Check the store before you type your card
SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus an Android app. Paste a store's address, or let the extension check it the moment you land, and it tells you whether the domain is a known fake before you reach the checkout form. The reported storefronts in this network already return a danger verdict, and the AI deep scan (Premium, $14.99/year) reads the page itself to catch clones the feeds have not seen yet.
About to buy from a Walmart sale you found in an ad? Scan the link free first →
Where a browser layer stops this, and where the price does
SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. Because these domains do not carry the word Walmart in the hostname, it is worth being straight about which layer does the work here.
- Layer 1, Local detection: URL-shape checks run in the extension before the page renders, covering 60+ URL patterns, no-HTTPS and raw-IP checks, and homograph tricks. These storefronts use ordinary .shop words with no brand string to catch, so the local layer is not what flags them by name. The deciding signal comes from the next layer.
- Layer 2, API checks: the domain is cross-referenced server-side against our 550+ brand database, Google Safe Browsing, PhishTank, URLhaus and ScamAdviser feeds, and our own indicator blocklist, which now carries the storefronts reported in this network. That is why pasting allgoodscenter.shop or marketbasketcenter.shop into SafeBrowz returns a danger verdict today. None of these checks needs the page to load.
- Layer 3, AI deep scan (Premium): AI content analysis via our proxy reads the page like a shopper would and can flag a Walmart-branded storefront selling premium liquor at a giveaway price on a no-name domain, in any of the 100+ languages the AI scan reads. This is what catches a clone the feeds have not indexed yet.
The honest limit: a brand-new storefront freshly cut from this template, that no feed has reported yet, may come back caution rather than danger until it is flagged. That gap is exactly why the price is the signal you can trust without any tool at all. No real retailer sells name-brand spirits at 60 to 70 percent off, and Walmart's store is only ever at walmart.com. The tool narrows the gap; the offer closes it.
Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.
If you already entered your card
Assume the card is in the wrong hands and move on it the same day. The order matters less than the speed.
- Call your card issuer now. Use the number on the back of the card, say the number was entered on a fraudulent site, and ask them to freeze and reissue it. A new card number is the clean break.
- Watch the statement and dispute anything you did not authorise. In the US the Fair Credit Billing Act gives you the right to dispute card charges; most issuers let you flag a transaction in the app in minutes.
- Update the card everywhere you saved it. If those details were stored in other accounts or subscriptions, replace them so a stopped card does not break services you actually use.
- Consider a virtual card next time. A single-merchant or one-time virtual card limits the damage if a checkout turns out to be fake. Our guide to safer online payments walks through the options.
- Report it. File with the FTC at reportfraud.ftc.gov, and if money was lost, the FBI's Internet Crime Complaint Center at ic3.gov. Our walkthrough of the first steps after a scam covers the full lockdown.
Check a store before you reach the checkout
Found a Walmart sale, or any store, through an ad or a feed post? Paste the address here. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.
Frequently asked questions
Is allgoodscenter.shop a real Walmart website?
No. Walmart's only website is walmart.com. allgoodscenter.shop, marketbasketcenter.shop, broadbasket.shop, smartbasketplace.shop and valueparcel.shop are among more than 120 lookalike storefronts Malwarebytes documented on July 29, 2026. They copy Walmart's logo, colours and layout to look official, but they are registered on generic .shop names Walmart does not own. Their only purpose is to harvest the card details you type at checkout. There is no real store behind it.
I entered my card on one of these fake Walmart stores. What should I do?
Treat the card as compromised and act today. Call your bank or card issuer using the number on the back of the card, tell them the number was entered on a fraudulent site, and ask them to freeze and reissue it. Watch your statement and dispute any charge you did not authorise; in the US the Fair Credit Billing Act gives you the right to dispute card charges. If you saved that card in other accounts, update it there too. Then report the site at reportfraud.ftc.gov and, if you lost money, at ic3.gov.
Why is the liquor so cheap on these Walmart stores?
Because there is no liquor. The 40 to 70 percent discount on premium spirits is bait, not a sale. The product pages, prices and photos exist only to move you to a checkout form. Once you enter your card number, expiry and CVV, the operators have what they came for. There is no real inventory behind it, and the fabricated business address and phone number in the footer lead nowhere.
How can I tell a fake Walmart store from the real Walmart site?
Read the domain in the address bar, not the logo on the page. Walmart's store lives only at walmart.com. If the name is a generic word like broadbasket.shop or valueparcel.shop with no Walmart identity, it is not Walmart, no matter how closely the page copies the branding. Two more tells: an impossible discount on name-brand goods, and arriving from a mobile ad rather than typing the address yourself.
Are all .shop websites scams?
No. .shop is an ordinary top-level domain used by many legitimate businesses. The problem here is not the ending of the address, it is that these specific sites impersonate Walmart on domains Walmart does not own and never ship an order. Judge a store by its registrable domain and the plausibility of its offer, not by whether it ends in .shop, .com or anything else.
Last updated 2026-07-30