Researchers reported that threat actors are inserting fake invoices and purchase receipts into Shopify’s legitimate Shop order-tracking app, making fraudulent charges appear more credible than traditional phishing emails. The bogus orders impersonate brands including Norton, McAfee, Apple, and PayPal, often claiming high-value purchases, gift cards, iPhones, or subscription renewals. Each fake receipt directs victims to a scam-controlled support number, exploiting trust in the app’s normal order history and notifications.
Once victims call, the attackers use callback-phishing tactics to steal payment card details, passwords, and one-time passcodes, and in some cases persuade users to install remote-access software. Researchers said the exact insertion method remains unconfirmed, but it may involve merchant workflows, email parsing, or other order-ingestion paths in the Shop ecosystem; they found no evidence that Shop, Shopify, or the impersonated brands were breached. Public reports indicate the activity is ongoing, and users are being urged to verify charges only through official brand sites, bank or card-provider accounts, and to avoid phone numbers embedded in suspicious receipts.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Gen Digital researchers documented a scam in which fraudulent invoices and purchase receipts appear inside the legitimate Shop order-tracking app, impersonating brands such as Norton, McAfee, Apple, and PayPal. The researchers said the fake orders direct victims to scam-controlled phone numbers and found no evidence that Shop, Shopify, or the impersonated brands were breached.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
huntress.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.