Fake Receipts Are Appearing in Your Trusted Shopping Apps
Scammers are injecting fake purchase receipts into Shopify's Shop app, tricking users into calling fraudulent support numbers.
Source
GetCyberRight Intelligence
Original headline: Shop App Callback Phishing Myth
Plain-English summary by GetCyberRight. Read the full report at the source above.
When Your Shopping App Becomes a Scam Tool
Scammers have found a dangerous new way to reach you: through an app you already trust. They're injecting fake purchase receipts directly into Shopify's Shop app, making fraudulent charges appear alongside your real orders. When you see an unfamiliar purchase and call the "customer support" number listed, you're actually reaching criminals ready to steal your money and personal information.
The Details
The Shop app is Shopify's official order tracking tool, used by millions to monitor packages and manage purchases from thousands of online stores. Because the app pulls in real transaction data, most people trust what they see there completely.
Here's how the scam works: Attackers exploit weaknesses in how some merchants integrate with Shopify. They inject fake order confirmations that look completely legitimate within your Shop app. These fake receipts show purchases you never made, often for expensive items or subscription services. The receipt includes a phone number labeled as "customer support" or "billing questions."
When you call that number to dispute the charge, you reach scammers posing as helpful support staff. They'll ask you to "verify your identity" by providing personal information, credit card details, or banking credentials. Some will request remote access to your computer to "cancel the order." Others will ask for payment to process a refund. Every piece of information you provide goes straight to criminals who can drain bank accounts, make fraudulent purchases, or steal your identity.
Who Is Affected
Anyone who uses the Shop app is potentially vulnerable. This includes anyone who has ordered from Shopify-based stores, which covers millions of small businesses, major retailers, and direct-to-consumer brands. If you've ever tracked a package through Shop, you're a possible target.
This scam is particularly dangerous for families who share devices or accounts. Parents might see charges they assume their teens made, or vice versa. Seniors who are careful about clicking email links may let their guard down with an app they consider safe. The trust factor makes this scam especially effective.
What You Should Do Right Now
Never call phone numbers listed on unexpected receipts. Instead, go directly to the merchant's official website (type it yourself, don't click links) and use the contact information listed there.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Check your actual credit card or bank statement before taking any action. If a charge appears in Shop but not on your real statement, it's fake. If it does appear, contact your bank directly using the number on your card.
Review all orders in your Shop app regularly. Look for anything unfamiliar and verify each purchase against your email confirmations and bank records.
Enable purchase notifications on your credit cards and bank accounts. Real-time alerts help you spot actual fraudulent charges immediately.
Before calling any support number, verify it independently. Use GCR Scam Guard or search the number online to check for scam reports.
The Bigger Picture
This attack represents an evolution in phishing tactics. Criminals are moving beyond suspicious emails into the apps and platforms we trust most. They're exploiting the fact that we've been taught to trust official apps more than random emails. As our digital lives become more interconnected, scammers will continue finding creative ways to abuse that trust. Staying informed about emerging threats is no longer optional. It's a basic safety requirement for anyone who shops, banks, or communicates online.
How GetCyberRight Can Help
Before calling any phone number from an unexpected receipt or message, use GCR Scam Guard to verify its legitimacy. Our tool helps you check whether contact numbers and receipts are genuine before you engage with potential scammers. It's like having a cybersecurity expert check things out before you take action. Because the best defense against scams is knowing what to look for before you become a victim.
Curated from trusted cybersecurity sources by GetCyberRight
Source: GetCyberRight IntelligenceStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Fake Orders Are Appearing in Your Shop App. Here's What to Know
Scammers are injecting fraudulent receipts into Shopify's legitimate Shop app to trick users into calling fake support numbers.
3 min readYour Prime Day Phone Trade-In Could Leak Your Family's Private Data
Rushing to trade in your old phone for a Prime Day deal? Without proper data removal, your photos, passwords, and messages could end up in a stranger's hands.
3 min readUpdates Are Important, But Your Passwords and Habits Matter More
Microsoft extended Windows 10 security updates to 2027. That's good news, but it won't protect you from weak passwords and phishing scams.
4 min readPrime Day's Hidden Risk: The Companies You've Never Heard Of Get Hacked
Market research firm Klue was breached and customer data stolen. Here's why data broker breaches put your family at risk, and what you can do about it.
3 min read