Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    US seizes hundreds of FIFA World Cup illegal streaming domains

    June 29, 2026

    HackTheBox – WingData

    June 28, 2026

    Data breach exposes up to 14.2 million email logins at six ISPs

    June 28, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Order-tracking app Shop abused to push callback phishing attacks
    News

    Order-tracking app Shop abused to push callback phishing attacks

    adminBy adminJune 26, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Order-tracking app Shop abused to push callback phishing attacks

    Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users’ order histories to trick them into providing sensitive data or installing remote access software.

    The Shop digital shopping assistant serves as a centralized platform where users can track orders from multiple online retailers, access receipts and shipping updates, and discover and purchase products from merchants that use Shopify.

    The app is very popular in North America, where support and purchasing options are more substantial. It has 50 million downloads on Google Play and 7 million ratings in Apple’s App Store.

    image

    According to cybersecurity company Gen Digital, scammers are inserting fake orders that appear alongside legitimate purchases, impersonating brands such as Norton, McAfee, Apple, and PayPal.

    Fake Norton purchase receipt in the Shop app
    Fake Norton purchase receipt in the Shop app
    Source: Gen Digital

    The threat actor also listed a phone number in the digital receipts that users can call to dispute purchases. However, at the other end is a scammer posing as a support agent.

    Using social engineering tactics, the fraudster tries to convince the victim to disclose account credentials, payment card details, and temporary authentication codes (OTPs).

    In some cases, the researchers say that victims are tricked into installing software that grants remote access to the device.

    Gen Digital researchers note that inserting the fake receipts in the Shop app is a more effective method than using email to deliver fraudulent purchase notifications, a more common technique known as callback phishing.

    Shop is a legitimate shopping app, and users inherently trust it, so orders that appear there are far more likely to prompt responses from unsuspecting users.

    However, the researchers say that many of the false receipts contain poor grammar, which is an obvious red flag. Nevertheless, users may miss the mistakes when they see an invoice for a large purchase.

    Despite the observed wave of fraudulent invoices, it is unclear how they are inserted into the Shop app.

    The researchers say that Shop can populate orders from multiple sources, including email parsing, account association, and order workflows, but no particular one could be confirmed as the delivery channel for the fraudulent notifications.

    Gen Digital underlines that they found no evidence that Shop, Shopify, or any of the impersonated companies were compromised.

    BleepingComputer has reached out to Shopify with related questions, but we have not received a response as of publishing.

    Until the situation clears up, users who see receipts for orders they didn’t place on Shop are advised not to call the phone number listed on them, but instead to verify any alleged charge directly with their bank.

    Those who have already contacted the scammers and disclosed sensitive information should immediately reset their account passwords and contact their card issuer for cancellation.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe Tokenpocalypse Is Here: Companies Are Scrambling To Stop Spending So Much on AI
    Next Article Microsoft quietly extends free Windows 10 ESU support to October 2027
    admin
    • Website

    Related Posts

    News

    US seizes hundreds of FIFA World Cup illegal streaming domains

    June 29, 2026
    News

    Data breach exposes up to 14.2 million email logins at six ISPs

    June 28, 2026
    News

    Scientists Think They’ve Uncovered the 15-Million-Year-Old Origin of Laughter

    June 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Our Picks

    US seizes hundreds of FIFA World Cup illegal streaming domains

    June 29, 2026

    HackTheBox – WingData

    June 28, 2026

    Data breach exposes up to 14.2 million email logins at six ISPs

    June 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.