Shopify's Shop App Targeted by Callback Phishing Scams

Shopify's Shop App Targeted by Callback Phishing Scams

First seen 26 Jun 2026, 00:12 UTC BleepingcomputerGbhackersCybersecuritynewsScworld 90% similarity 62.2
Share:

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting Shopify's Shop app to insert fake purchase receipts into users' order histories, tricking them into revealing sensitive information or installing malicious software. The app, popular in North America with 50 million downloads, has seen scammers impersonating reputable brands like Norton and PayPal. Victims are misled into calling a fraudulent support number listed on these receipts, where scammers attempt to extract account credentials and payment details. Researchers from Gen Digital have identified this shift from traditional email phishing to in-app attacks as particularly effective due to the inherent trust users place in the app. Although the exact method of how these fake receipts are inserted remains unclear, no evidence suggests that Shopify or the impersonated companies have been compromised. Users are advised to verify any suspicious receipts directly with their banks and to reset passwords if they have already engaged with the scammers.

Key Points: • Scammers are inserting fake invoices into the Shop app to exploit user trust. • Victims are misled into calling a fraudulent support number for assistance. • Users are advised to verify suspicious receipts directly with their banks.

ThreatCluster AI

Timeline

2026-06-25
Discovery of phishing attacks in Shop app
Researchers identified multiple campaigns inserting fake receipts in the Shop app, marking a shift in phishing tactics.
Bleepingcomputer
2026-06-26
Ongoing scam campaigns reported
Reports confirm ongoing exploitation of the Shop app by scammers using fake invoices to steal credentials.
Gbhackers
2026-06-26
User warnings issued
Users are cautioned to avoid calling numbers on suspicious receipts and to verify charges with their banks.
Cybersecuritynews

Community

Browse all →