HomeCyber BalkansScammers Exploit Shopify Notification System in New Fake Refund Scam

Scammers Exploit Shopify Notification System in New Fake Refund Scam

Published on

spot_img

Phishing Campaign Exploits Shopify’s Notification System

In a troubling development in online scams, security researchers have uncovered a sophisticated phishing campaign that leverages Shopify’s own Shop app to send deceptive order and refund notifications directly to victims’ mobile devices. This marks a significant evolution of the classic “fake refund” scam, demonstrating how cybercriminals are continuously adapting their tactics.

According to research from the cybersecurity firm Huntress, attackers are employing two main strategies: creating fraudulent seller accounts on Shopify or hijacking existing legitimate ones. These fraudsters generate fake orders directed at unsuspecting victims’ phone numbers or email addresses. The critical aspect of this scheme is that Shopify’s Shop app processes these fraudulent transactions as if they were valid. Consequently, victims receive authentic push notifications and in-app receipts, in stark contrast to the usual suspicious emails or text messages that often accompany phishing attempts.

Between May and August 2026, several employees at Huntress became targets of this scam, providing firsthand evidence of the technique’s efficacy and reach. The issue has also caught the attention of researchers at Gen Digital and has been discussed by users on forums such as Reddit, further highlighting the campaign’s growing prevalence.

One particularly illustrative example cited by Huntress involved a fake receipt dated August 7, which billed the recipient for $339.96 for a supposed “premium PC protection plan.” This fraudulent document featured a carefully crafted invoice number and transaction ID, aiming to enhance its legitimacy. However, the real trick lies within the shipping address field, where attackers insert a message instructing the recipient to call a specified phone number if they claim they did not place the order. In some cases, attackers omit the fake address entirely, instead compelling victims to contact the number based on details provided in the order description. Additional tactics include embedding a spoofed “out for delivery” shipment tracker designed to increase urgency and pressure on the potential victim.

Victims who take the bait and call the number are then funneled into a more traditional refund scam. Huntress indicates that these callers are frequently persuaded to install remote access tools like ScreenConnect or AnyDesk, or they are prompted to log into their online banking accounts. In these scenarios, scammers deftly manipulate on-screen figures—sometimes altering visible transaction details or guiding victims to misinterpret a refund amount—to convince the victims they had received an accidental overpayment. This deceptive process often culminates in victims being pressured to “return” the difference, commonly through the purchase of gift cards, the redemption codes for which are quickly siphoned off by the scammers.

Huntress categorizes this campaign as a variant of a strategy they describe as Living off Trusted Sites (LoTS). This approach allows attackers to route victims through a legitimate platform before reaching a harmful outcome, circumventing the need for using a dubious domain that might be more easily flagged. In earlier LoTS attacks, links to trusted services like Dropbox, Canva, or DocuSign were used to lend credibility. In stark contrast, this new campaign skillfully exploits Shopify’s notification system, generating messages that mirror those of legitimate transactions, thus enhancing their deceptive impact. Huntress noted a comparable pattern in prior campaigns that involved genuine PayPal invoices accompanied by fraudulent callback numbers.

In response to this alarming trend, Shopify has acknowledged the scam through its Help Center. Both Shopify and Huntress urge users to refrain from engaging with unfamiliar phone numbers, email addresses, or links presented in suspected orders. Users are advised to contact Shopify Support directly should they have any concerns regarding their account security. Additionally, recipients of dubious order notifications are encouraged to review their bank statements before assuming that any charges have been applied, and they can flag any suspicious orders as “Not my order” within the Shop app interface.

Huntress also recommends that users critically evaluate online stores, paying close attention to their reviews and history before making purchases. Many of the fraudulent storefronts associated with this ongoing campaign were newly established, serving as a practical reminder of the need for diligence in online transactions.

In conclusion, as scammers continue to exploit trusted platforms like Shopify, the importance of consumer awareness and vigilance cannot be overstated. Increasingly sophisticated scams like this emphasize the necessity for users to stay informed and vigilant against potential online threats.

Source link

Latest articles

Trump Administration Enables Private-Sector Cyber Offensives

In an era where cyber threats loom larger than ever, organizations are urged to...

Cyber Briefing: August 13, 2026 – CyberMaterial

Cybersecurity Brief: Recent Developments in Cyber Espionage and Data Breaches In today's evolving digital landscape,...

More like this

Trump Administration Enables Private-Sector Cyber Offensives

In an era where cyber threats loom larger than ever, organizations are urged to...