Threat reportPhishingTL-2026-0944

Shopify Shop App Abused to Deliver Fake Receipts for Callback Phishing (TOAD) Attacks Impersonating Norton, McAfee, Apple and PayPal

highACTIVE

Shopify Shop App Abused to Deliver Fake Receipts for (TL-2026-0944), also tracked as Fake invoices moving from inboxes to shopping apps, is a high-severity phishing campaign, first published 2026-06-25. It has no confirmed attribution, affects Shopify Shop (consumer order-tracking app, iOS/Android), maps to 14 MITRE ATT&CK techniques (T1005, T1056, T1111), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0944

Threat ID
TL-2026-0944
Also known as
Fake invoices moving from inboxes to shopping apps, Shop app fake receipt callback phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumer, retail, financial services, general public
Target regions
North America, Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in Shopify Shop App Abused to Deliver Fake Receipts for

Malware and tooling: AnyDesk, TeamViewer

How Shopify Shop App Abused to Deliver Fake Receipts for works

Threat actors are inserting fraudulent purchase receipts into Shopify's Shop order-tracking app to run callback phishing (TOAD) campaigns impersonating Norton, McAfee, Apple and PayPal. The fake receipts embed attacker-controlled support phone numbers; victims who call are socially engineered into surrendering credentials, payment card data and one-time passcodes, or into installing remote access software.

Researchers at Gen Digital (the parent company of Norton, Avast, Avira, AVG and LifeLock) disclosed an in-the-wild abuse campaign in which scammers cause fraudulent purchase receipts to appear inside Shopify's consumer Shop app, which consumers use to track online orders. Rather than relying on a traditional email lure that must survive spam filtering and earn the recipient's trust, the actors place the fake invoice directly inside a legitimate, trusted application where users already expect to see real orders, dramatically increasing perceived legitimacy.

The fake receipts impersonate well-known brands — Norton/Norton LifeLock, McAfee, Apple (gift cards and iPhones), PayPal, and high-value items such as MacBooks — and typically claim a charge of several hundred dollars for a purchase or subscription the victim never made. Each fraudulent order includes an attacker-controlled 'support', 'billing', or 'cancellation department' phone number. This is a classic telephone-oriented attack delivery (TOAD) / callback phishing pattern: the lure contains no malicious link or attachment to trip automated defenses; instead it manipulates the alarmed victim into voluntarily phoning the attacker.

When the victim calls, the scam moves off-platform. A call-center operator skilled in social engineering poses as billing support, Norton support, PayPal support or a cancellation/refund department and walks the victim through 'cancelling' the bogus charge. Over the course of the call the operator extracts account credentials, payment card details and one-time passcodes (OTPs), and in some cases convinces the victim to install legitimate remote access / remote control software so the operator can take control of the device — the same playbook used by refund-scam and ransomware-precursor crews who pivot from a phone call to hands-on-keyboard access.

Gen Digital found no evidence that Shop, Shopify, or any of the impersonated companies (Norton, McAfee, Apple, PayPal) were breached. The exact mechanism by which the fraudulent orders are injected into the Shop app remains unconfirmed. Shop populates a user's order list through several legitimate channels — merchant/order workflows, email parsing (Shop scans connected Gmail/Outlook inboxes for shipping and tracking keywords), and account association — and the researchers believe the actors have found a way to misuse one of these legitimate ingestion paths rather than compromising the platform itself. Many fake receipts contain poor grammar, but victims frequently overlook these errors when distracted by an unexpected large charge. This threat is a fraud/abuse-of-feature campaign, not a software vulnerability; there is no associated CVE.

MITRE ATT&CK techniques used in TL-2026-0944

Collection

T1005 Data from Local System

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception

Execution

T1204 User Execution

Command and Control

T1219 Remote Access Tools

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Shopify Shop App Abused to Deliver Fake Receipts for

  • Shopify — Shop (consumer order-tracking app, iOS/Android)
    Vulnerable versions: all (feature abuse, not a vulnerability)
  • Gen Digital — Norton / Norton LifeLock (brand impersonated)
    Vulnerable versions: brand impersonation
  • McAfee — McAfee consumer antivirus (brand impersonated)
    Vulnerable versions: brand impersonation
  • Apple — Apple gift cards / iPhone / MacBook (brand impersonated)
    Vulnerable versions: brand impersonation
  • PayPal — PayPal (brand impersonated)
    Vulnerable versions: brand impersonation

Remediation for Shopify Shop App Abused to Deliver Fake Receipts for

Immediate actions

  • Do not call phone numbers shown on unexpected receipts or charge notifications inside the Shop app or any shopping app
  • Treat any unsolicited 'order' for Norton, McAfee, Apple, PayPal or other high-value items that you did not buy as a scam lure
  • If you already called and disclosed data, immediately contact your bank or card issuer through the number on the back of your card and reset affected passwords
  • If you installed any remote access software at a caller's request, disconnect the device from the network and remove the software

Workarounds

  • Disconnect third-party email parsing/inbox connections from the Shop app if order auto-population is not needed
  • Report suspected fraudulent orders to Shop via help.shop.app and to the impersonated brand's official abuse channel

Longer-term hardening

  • Verify alleged charges only through the official app, website, or phone number of the actual vendor — never the number printed in the suspicious receipt
  • Enable transaction alerts with your bank and card issuer to independently confirm real charges
  • Educate household members and employees on callback phishing (TOAD): no legitimate vendor requires you to call a number in a receipt to dispute a charge
  • Use a password manager and phishing-resistant MFA (passkeys/FIDO2) so disclosed reusable secrets and OTPs have limited value

Timeline of Shopify Shop App Abused to Deliver Fake Receipts for

  • Gen Digital assessed that inserting fake receipts into the Shop app is more effective than email delivery because users inherently trust a legitimate shopping app where real orders appear.
  • Researchers noted the attacker contact details (phone/email) can be embedded in multiple receipt fields: order details, product description, receipt body, or the shipping-address field.
  • Gen Digital enumerated the legitimate Shop ingestion channels that could be abused: connected Gmail/Outlook inbox parsing (keywords like 'tracking number' / 'track your package'), email linked to the Shop account, and Shop Pay transactions.
  • Defensive guidance issued: do not call numbers on suspicious receipts, verify charges with the bank directly, reset passwords and contact card issuers if data was disclosed.
  • During the call, operators extract credentials, payment card data and OTPs, and in some cases induce victims to install remote access software.
  • Fake receipts embed an attacker-controlled support/billing/cancellation phone number; victims who call are moved off-platform and socially engineered.
  • Gen Digital found no evidence that Shop, Shopify, or any impersonated company was compromised; the campaign abuses legitimate features rather than exploiting a vulnerability.
  • Researchers state the exact injection path into the Shop order list remains unconfirmed; candidate vectors are merchant/order workflow, email parsing, and account association.
  • Impersonated brands documented: Norton/Norton LifeLock, McAfee, Apple (gift cards, iPhone), PayPal, and high-value items such as MacBooks.
  • BleepingComputer reported the campaign: order-tracking app Shop abused to push callback phishing (TOAD) attacks.
  • Gen Digital published research describing fake invoices/receipts being inserted into shopping apps, including Shopify's Shop app, to drive callback phishing.

Sources cited for Shopify Shop App Abused to Deliver Fake Receipts for

Detection coverage for TL-2026-0944

As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0944 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats