Scammers are abusing Shopify's Shop order tracking app by planting fake receipts for Norton, Apple, and McAfee products that trick users into calling fraudulent support numbers, where they are pressured to share sensi... Shopify told BleepingComputer it has deployed new controls that have significantly reduced the f...

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What is the callback phishing scam targeting Shopify's Shop app, how do threat actors exploit the. Article summary: ## Callback Phishing Scam Targeting Shopify's Shop App. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
Threat actors are actively exploiting Shopify's Shop order-tracking app by inserting fake purchase receipts into users' order histories to push a callback phishing campaign. When users call the fraudulent support number listed on the receipt, scammers posing as customer service agents attempt to steal sensitive information or trick victims into installing remote access software . The campaign impersonates well-known brands including Norton, McAfee, Apple, and PayPal, with reports of fake receipts for iPhone purchases and Apple gift cards alongside phony security subscriptions
. Crucially, cybersecurity researchers at Gen Digital and Shopify have found no evidence that the Shop app or Shopify's platform itself was breached — the scammers appear to be abusing a legitimate feature of the order-tracking system
.
The core of the deception lies in the trust users place in the Shop app, which aggregates order tracking and receipts from multiple retailers into a single interface . Scammers create counterfeit orders and inject them into a user's order history, making them appear alongside legitimate purchases. Because the Shop app auto-populates orders from connected email accounts (Gmail, Outlook, and others), the fake receipt gains credibility by appearing in a familiar, trusted context
.
Reported fake receipts impersonate brands such as Norton, McAfee, Apple (iPhones and Apple gift cards), and include PayPal-style payment claims . The choice of brand is deliberate social engineering: a fake receipt for a $300+ security subscription or an expensive Apple product creates urgency and panic, prompting the user to call the listed number to dispute the charge
.
The key element is a phone number embedded in the order details, shipping address field, or product description, often with a message directing the user to call "support" if the charge was unauthorized . When the victim calls, the scammer answers as a support agent and attempts to:
In most reported cases, no actual charge ever appears on the user's financial accounts — the entire threat is the call .
In response to the campaign, Shopify told BleepingComputer that it had identified bad actors misusing the platform and deployed new controls that "significantly reduced this activity and improved our ability to detect it going forward" . The specific technical measures were not detailed, but the company also directs users to its official security guidance on identifying phishing, vishing, and smishing attempts, which includes verifying email domains from official Shopify addresses like @shopify.com and never calling suspicious numbers
.
Shopify encourages users to forward suspicious emails to phishing@shopify.com. Gen Digital, whose Norton brand is impersonated in the scam, also recommends reporting suspicious Norton-related emails to spam@norton.com .
If you encounter an unexpected order or receipt in your Shop app, you should not engage with the listed contact information. Instead, follow these steps:
Do not call any phone number provided in the order. Legitimate companies do not include support numbers in digital receipts for you to call about disputed charges .
Verify charges directly with your bank or card issuer. Log into your financial accounts through their official app or website — not through links in the notification — to confirm whether any actual charge exists .
Do not click any links or download files from the suspicious order .
Disconnect email sync from the Shop app temporarily by going to Settings > Email Integration to prevent additional fake orders from auto-populating .
Report the scam. Forward the notification or email to phishing@shopify.com, and if it impersonates Norton, also send it to spam@norton.com .
If you already called the number, contact your bank immediately to freeze your accounts, run a malware scan on your device, change your Shopify password, and enable two-step authentication .
Mark the order as suspicious in the Shop app where available, which can help the platform identify and block similar fraudulent orders .
The callback phishing scam targeting Shopify's Shop app represents a notable evolution in phishing techniques: attackers are moving beyond email to place fraudulent receipts directly inside a trusted application where users manage real purchases. The campaign exploits user trust in the platform rather than any technical vulnerability in Shopify's infrastructure. The most effective defense is simple: never call a phone number embedded in a receipt, verify any alleged charge through official channels, and report suspicious activity to the affected platforms.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Scammers are abusing Shopify's Shop order tracking app by planting fake receipts for Norton, Apple, and McAfee products that trick users into calling fraudulent support numbers, where they are pressured to share sensi...
Scammers are abusing Shopify's Shop order tracking app by planting fake receipts for Norton, Apple, and McAfee products that trick users into calling fraudulent support numbers, where they are pressured to share sensi... Shopify told BleepingComputer it has deployed new controls that have significantly reduced the fraudulent activity, though specific technical details were not disclosed [26].
If you see a suspicious receipt in your Shop app, do not call any phone number listed in the order.
Loading comments...
Comments
0 comments