Attackers are abusing Shopify's Shop order-tracking app by inserting fake purchase receipts into users' order histories, then using the listed phone numbers to trick people into calling scammers. The fake receipts impersonate brands including Norton, McAfee, Apple, and PayPal, and the callback phishing flow aims to steal credentials, payment-card details, and one-time passcodes; some victims are also persuaded to install remote-access software. Researchers said they found no evidence that Shop, Shopify, or the impersonated brands were breached, and the insertion method is still unclear.
Why it matters: This matters because the scam appears inside a trusted shopping app rather than email, making it more believable and more likely to fool consumers. Users should avoid calling numbers shown on unexpected Shop receipts, verify charges directly with their bank or merchant, and reset credentials and contact their card issuer if they already engaged with the scammers.
Bill Toulas
2026.06.25
100% relevant
This article establishes a distinct scam campaign centered on abuse of the Shop app itself as the lure delivery channel for callback phishing, not just generic invoice phishing.
← Back to all stories