The core of the deception lies in the trust users place in the Shop app, which aggregates order tracking and receipts from multiple retailers into a single interface . Scammers create counterfeit orders and inject them into a user's order history, making them appear alongside legitimate purchases. Because the Shop app auto-populates orders from connected email accounts (Gmail, Outlook, and others), the fake receipt gains credibility by appearing in a familiar, trusted context
.
Reported fake receipts impersonate brands such as Norton, McAfee, Apple (iPhones and Apple gift cards), and include PayPal-style payment claims . The choice of brand is deliberate social engineering: a fake receipt for a $300+ security subscription or an expensive Apple product creates urgency and panic, prompting the user to call the listed number to dispute the charge
.
The key element is a phone number embedded in the order details, shipping address field, or product description, often with a message directing the user to call "support" if the charge was unauthorized . When the victim calls, the scammer answers as a support agent and attempts to:
In most reported cases, no actual charge ever appears on the user's financial accounts — the entire threat is the call .
In response to the campaign, Shopify told BleepingComputer that it had identified bad actors misusing the platform and deployed new controls that "significantly reduced this activity and improved our ability to detect it going forward" . The specific technical measures were not detailed, but the company also directs users to its official security guidance on identifying phishing, vishing, and smishing attempts, which includes verifying email domains from official Shopify addresses like @shopify.com and never calling suspicious numbers
.
Shopify encourages users to forward suspicious emails to phishing@shopify.com. Gen Digital, whose Norton brand is impersonated in the scam, also recommends reporting suspicious Norton-related emails to spam@norton.com .
If you encounter an unexpected order or receipt in your Shop app, you should not engage with the listed contact information. Instead, follow these steps:
Do not call any phone number provided in the order. Legitimate companies do not include support numbers in digital receipts for you to call about disputed charges .
Verify charges directly with your bank or card issuer. Log into your financial accounts through their official app or website — not through links in the notification — to confirm whether any actual charge exists .
Do not click any links or download files from the suspicious order .
Disconnect email sync from the Shop app temporarily by going to Settings > Email Integration to prevent additional fake orders from auto-populating .
Report the scam. Forward the notification or email to phishing@shopify.com, and if it impersonates Norton, also send it to spam@norton.com .
If you already called the number, contact your bank immediately to freeze your accounts, run a malware scan on your device, change your Shopify password, and enable two-step authentication .
Mark the order as suspicious in the Shop app where available, which can help the platform identify and block similar fraudulent orders .
The callback phishing scam targeting Shopify's Shop app represents a notable evolution in phishing techniques: attackers are moving beyond email to place fraudulent receipts directly inside a trusted application where users manage real purchases. The campaign exploits user trust in the platform rather than any technical vulnerability in Shopify's infrastructure. The most effective defense is simple: never call a phone number embedded in a receipt, verify any alleged charge through official channels, and report suspicious activity to the affected platforms.