Security researchers have identified a phishing campaign that abuses Shopify’s own Shop app to deliver fake order and refund notifications directly to victims’ phones, marking a notable evolution of the classic “fake refund” scam.
According to research from cybersecurity firm Huntress, attackers are creating fraudulent Shopify seller accounts, or hijacking legitimate ones, to generate bogus orders against victims’ phone numbers or email addresses. Because Shopify’s Shop app treats these as genuine transactions, targets receive real push notifications and in-app receipts, rather than a suspicious email or text from an unfamiliar sender. Huntress said several of its own employees were targeted between May and August 2026, and that the technique has also been documented by researchers at Gen Digital and reported by users on Reddit.
In one example cited by Huntress, a fake receipt dated 7 August billed the recipient $339.96 for a “premium PC protection plan,” complete with a fabricated invoice number and transaction ID. The real sting sits in the shipping address field, which attackers repurpose to display a message urging the recipient to call a phone number if they did not place the order. Some variants dispense with the fake address altogether and instead push recipients toward the number via the order description, while others add a spoofed “out for delivery” shipment tracker to increase pressure on the target.
Victims who call the number are funnelled into a standard refund scam. Huntress said callers are typically talked into installing remote access tools such as ScreenConnect or AnyDesk, or into logging into their online banking. From there, scammers manipulate on-screen figures, sometimes editing displayed transaction details or coaching victims to misread a refund amount, to convince them they were mistakenly overpaid. Victims are then pressured to “return” the difference, usually by purchasing gift cards and handing over the redemption codes, which attackers cash out quickly.
Huntress frames the campaign as a variant of a technique it calls Living off Trusted Sites (LoTS), where attackers route victims through a legitimate, trusted platform before reaching a malicious outcome, rather than relying on a fake domain that is easier to flag. While earlier LoTS attacks used links to services such as Dropbox, Canva, or DocuSign to add credibility, this campaign instead abuses Shopify’s own notification pipeline to generate content that looks and functions exactly like a native alert. The firm noted a similar pattern in a previous campaign involving genuine PayPal invoices carrying fraudulent callback numbers.
Shopify has acknowledged the scam in its Help Center. The company and Huntress both advise users not to interact with unfamiliar phone numbers, email addresses, or links found within an order, and to contact Shop Support directly if they are concerned about the security of their account. Users who receive a suspicious order notification are advised to check their bank statements before assuming any charge went through, and can flag the order as “Not my order” within the Shop app. Huntress also recommends checking a store’s reviews and history before purchasing, noting that many of the fraudulent shopfronts used in this campaign were newly created.

