Cybercriminals have found a new way to exploit the Shop app by placing fake purchase receipts directly into users’ order histories. The fraudulent orders appear alongside legitimate purchases and encourage victims to call fake customer support numbers, where scammers attempt to steal personal and financial information.
Researchers warn that the tactic is more convincing than traditional phishing emails because users often trust the Shop app and expect to see genuine order updates.
Shop App Scam Uses Fake Purchase Receipts
The Shop app from Shopify allows users to track deliveries, view digital receipts, and manage orders from multiple online stores in one place.
According to researchers at Gen Digital, attackers have started abusing that trust by inserting fake invoices into users’ order histories. The fraudulent receipts impersonate well-known brands, including Norton, McAfee, Apple, and PayPal.
Because the fake orders appear next to real purchases, many users assume they are legitimate.
Fake Support Numbers Lead to Callback Phishing
Each fraudulent receipt contains a customer support phone number that victims can call to dispute the purchase.
Instead of reaching a legitimate company, callers speak with scammers posing as support representatives. The criminals then use social engineering to convince victims to share account credentials, payment card details, and one-time authentication codes.
In some cases, they also persuade victims to install remote access software. Once installed, the attackers can gain direct access to the victim’s device.
Why the Scam Is So Effective
Researchers say the Shop app scam has a major advantage over traditional callback phishing emails.
People already trust the Shop app to display accurate order information. As a result, they are more likely to believe a suspicious invoice that appears inside the application than one delivered by email.
Many of the fake receipts contain grammar mistakes and awkward wording. However, users may overlook those warning signs when they believe someone has charged them for an expensive purchase.
Researchers Still Don’t Know How Attackers Insert Fake Orders
Gen Digital has not confirmed how attackers add the fraudulent receipts to users’ order histories.
The Shop app can import order information through several methods, including email parsing, linked accounts, and merchant order workflows. However, researchers have not identified which process the attackers currently exploit.
Importantly, the investigation found no evidence that Shopify, the Shop app, or any of the impersonated companies suffered a security breach.
How to Protect Yourself
Users who discover an unfamiliar purchase inside the Shop app should avoid calling any phone number listed in the receipt.
Instead, they should verify the transaction directly with their bank or payment card provider using official contact information. Anyone who has already shared sensitive information with the scammers should immediately change affected account passwords and contact their card issuer to protect their accounts.
The latest Shop app scam demonstrates how attackers continue to adapt callback phishing techniques by abusing trusted platforms instead of relying solely on fraudulent emails.


0 responses to “Shop App Scammers Use Fake Orders to Launch Callback Phishing Attacks”