The store’s order tracking app is being misused to push phishing attacks

Threat actors are increasingly abusing Shop, the order tracking app from Shopify, by adding fake purchase receipts to users’ histories to trick them into providing sensitive data or installing remote access software.
Shopify’s digital shopping assistant acts as a central platform where users can track orders from multiple online retailers, access receipts and shipping updates, and find and purchase products from merchants using Shopify.
The app is very popular in North America, where support and purchase options are very important. It has 50 million downloads on Google Play and 7 million ratings on Apple’s App Store.
According to cybersecurity firm Gen Digital, fraudsters place fake orders that appear as legitimate purchases, posing as products such as Norton, McAfee, Apple, and PayPal.

Source: Gen Digital
The threat actor also listed a phone number on digital receipts that users could call to dispute a purchase. However, on the other hand it is a scam that pretends to be a support agent.
Using social engineering techniques, the fraudster tries to convince the victim to reveal account details, payment card details, and one-time verification codes (OTPs).
In some cases, researchers say victims are tricked into installing software that provides remote access to the device.
Gen Digital researchers note that inserting fake receipts into the Shop app is a more effective method than using email to deliver fraudulent purchase notifications, a common technique known as phishing.
The store is an official shopping app, and users naturally trust it, so orders from there are more likely to prompt responses from unsuspecting users.
However, researchers say that many fake receipts contain incorrect grammar, which is an obvious red flag. However, users may miss errors when they see an invoice for a large purchase.
Despite the recognition of fraudulent invoices, it is not clear how they are entered into the Store application.
Researchers say the Store can fill orders from multiple sources, including email transfers, account associations, and job orders, but none can be confirmed as a delivery channel for fake notifications.
Gen Digital insists they have found no evidence that Shop, Shopify, or any third-party companies have been compromised.
BleepingComputer reached out to Shopify with related questions, but we have not received a response as of press time.
Until the situation is rectified, users who see receipts for orders they did not place in the Store are advised not to call the phone number listed, but instead to confirm any suspected charge directly with their bank.
Those who have already contacted fraudsters and disclosed sensitive information should immediately reset their account passwords and contact their card issuer for cancellation.
Security teams penetrate 54% of successful attacks and monitor 14%. Some walk around the area without being seen.
The Picus white paper shows how breaches and attack simulations evaluate your SIEM and EDR rules so that threats stop slipping through detection.
Get a white paper



