Hackers Abuse Shopping Apps to Push Fake Receipts and Support Number Fraud

Threat actors are abusing Shop, Shopify’s widely used order-tracking application, by injecting fake purchase receipts directly into users’ order histories to steal sensitive data or gain remote control of their devices.

The campaign was documented by Gen Digital, whose researchers found fraudulent orders appearing alongside legitimate purchases inside the app, impersonating major brands including Norton, McAfee, Apple, and PayPal.

Shop functions as a centralized digital shopping assistant, allowing users to track orders from multiple retailers, access receipts, receive shipping updates, and purchase products from Shopify-powered merchants.

The app carries an enormous reach, with over 50 million downloads on Google Play and 7 million ratings in Apple’s App Store, and is particularly dominant across North America.

Abuse Shopping Apps to Push Fake Receipts

Users who track real packages and review genuine receipts inside Shop are far more likely to treat any notification from the app as credible. According to Gen Digital, scammers insert fake orders that appear seamlessly among a victim’s real purchase history.

These fraudulent receipts typically claim that an expensive item, such as a Norton LifeLock subscription, a McAfee renewal, an iPhone, or an Apple gift card, has just been charged for several hundred dollars.

Embedded within the receipt, whether in the product description, order body, or even the shipping address field, is a phone number the victim is encouraged to call to dispute the charge.

 scam chain (Source: gendigital)
 scam chain (Source: gendigital)

At the other end is a scammer posing as a billing or cancellation support agent. Using social engineering, the fraudster attempts to extract account credentials, payment card details, and one-time authentication codes.

In more aggressive cases, Gen Digital researchers note that victims have been tricked into installing remote access software, handing the attacker direct control over the compromised device. How the fake receipts are being inserted into the shop remains unconfirmed.

The app can populate orders from several sources, including email parsing, account association, and merchant order workflows, but Gen Digital could not identify a single confirmed delivery pathway.

Critically, researchers found no evidence that Shop, Shopify, or any of the impersonated brands have been breached or compromised. Users who spot a receipt for a purchase they do not recognize inside Shop should not call any phone number listed within the order.

The safest response is to verify the alleged charge directly with the bank or card issuer using contact details obtained independently of the suspicious notification.

Anyone who has already called and disclosed sensitive information should immediately reset passwords for all associated accounts, prioritizing email, Apple ID, and banking credentials, and contact their card issuer to request a freeze or cancellation.

If remote access software was installed during the interaction, the device should be disconnected from the internet and scanned thoroughly before resuming any sensitive activity.

The scam works because it borrows the credibility of a trusted environment. The moment a user steps outside that environment to independently verify a charge, the entire illusion collapses.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories