Threat reportPhishingTL-2026-0944
Shopify Shop App Abused to Deliver Fake Receipts for Callback Phishing (TOAD) Attacks Impersonating Norton, McAfee, Apple and PayPal
Shopify Shop App Abused to Deliver Fake Receipts for (TL-2026-0944), also tracked as Fake invoices moving from inboxes to shopping apps, is a high-severity phishing campaign, first published 2026-06-25. It has no confirmed attribution, affects Shopify Shop (consumer order-tracking app, iOS/Android), maps to 14 MITRE ATT&CK techniques (T1005, T1056, T1111), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0944
- Threat ID
- TL-2026-0944
- Also known as
- Fake invoices moving from inboxes to shopping apps, Shop app fake receipt callback phishing
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumer, retail, financial services, general public
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Shopify Shop App Abused to Deliver Fake Receipts for
Malware and tooling: AnyDesk, TeamViewer
How Shopify Shop App Abused to Deliver Fake Receipts for works
Threat actors are inserting fraudulent purchase receipts into Shopify's Shop order-tracking app to run callback phishing (TOAD) campaigns impersonating Norton, McAfee, Apple and PayPal. The fake receipts embed attacker-controlled support phone numbers; victims who call are socially engineered into surrendering credentials, payment card data and one-time passcodes, or into installing remote access software.
Researchers at Gen Digital (the parent company of Norton, Avast, Avira, AVG and LifeLock) disclosed an in-the-wild abuse campaign in which scammers cause fraudulent purchase receipts to appear inside Shopify's consumer Shop app, which consumers use to track online orders. Rather than relying on a traditional email lure that must survive spam filtering and earn the recipient's trust, the actors place the fake invoice directly inside a legitimate, trusted application where users already expect to see real orders, dramatically increasing perceived legitimacy.
The fake receipts impersonate well-known brands — Norton/Norton LifeLock, McAfee, Apple (gift cards and iPhones), PayPal, and high-value items such as MacBooks — and typically claim a charge of several hundred dollars for a purchase or subscription the victim never made. Each fraudulent order includes an attacker-controlled 'support', 'billing', or 'cancellation department' phone number. This is a classic telephone-oriented attack delivery (TOAD) / callback phishing pattern: the lure contains no malicious link or attachment to trip automated defenses; instead it manipulates the alarmed victim into voluntarily phoning the attacker.
When the victim calls, the scam moves off-platform. A call-center operator skilled in social engineering poses as billing support, Norton support, PayPal support or a cancellation/refund department and walks the victim through 'cancelling' the bogus charge. Over the course of the call the operator extracts account credentials, payment card details and one-time passcodes (OTPs), and in some cases convinces the victim to install legitimate remote access / remote control software so the operator can take control of the device — the same playbook used by refund-scam and ransomware-precursor crews who pivot from a phone call to hands-on-keyboard access.
Gen Digital found no evidence that Shop, Shopify, or any of the impersonated companies (Norton, McAfee, Apple, PayPal) were breached. The exact mechanism by which the fraudulent orders are injected into the Shop app remains unconfirmed. Shop populates a user's order list through several legitimate channels — merchant/order workflows, email parsing (Shop scans connected Gmail/Outlook inboxes for shipping and tracking keywords), and account association — and the researchers believe the actors have found a way to misuse one of these legitimate ingestion paths rather than compromising the platform itself. Many fake receipts contain poor grammar, but victims frequently overlook these errors when distracted by an unexpected large charge. This threat is a fraud/abuse-of-feature campaign, not a software vulnerability; there is no associated CVE.
MITRE ATT&CK techniques used in TL-2026-0944
Collection
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception
Execution
Command and Control
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Impact
stealth
Affected products and versions in Shopify Shop App Abused to Deliver Fake Receipts for
- Shopify — Shop (consumer order-tracking app, iOS/Android)
Vulnerable versions: all (feature abuse, not a vulnerability) - Gen Digital — Norton / Norton LifeLock (brand impersonated)
Vulnerable versions: brand impersonation - McAfee — McAfee consumer antivirus (brand impersonated)
Vulnerable versions: brand impersonation - Apple — Apple gift cards / iPhone / MacBook (brand impersonated)
Vulnerable versions: brand impersonation - PayPal — PayPal (brand impersonated)
Vulnerable versions: brand impersonation
Remediation for Shopify Shop App Abused to Deliver Fake Receipts for
Immediate actions
- Do not call phone numbers shown on unexpected receipts or charge notifications inside the Shop app or any shopping app
- Treat any unsolicited 'order' for Norton, McAfee, Apple, PayPal or other high-value items that you did not buy as a scam lure
- If you already called and disclosed data, immediately contact your bank or card issuer through the number on the back of your card and reset affected passwords
- If you installed any remote access software at a caller's request, disconnect the device from the network and remove the software
Workarounds
- Disconnect third-party email parsing/inbox connections from the Shop app if order auto-population is not needed
- Report suspected fraudulent orders to Shop via help.shop.app and to the impersonated brand's official abuse channel
Longer-term hardening
- Verify alleged charges only through the official app, website, or phone number of the actual vendor — never the number printed in the suspicious receipt
- Enable transaction alerts with your bank and card issuer to independently confirm real charges
- Educate household members and employees on callback phishing (TOAD): no legitimate vendor requires you to call a number in a receipt to dispute a charge
- Use a password manager and phishing-resistant MFA (passkeys/FIDO2) so disclosed reusable secrets and OTPs have limited value
Timeline of Shopify Shop App Abused to Deliver Fake Receipts for
- Gen Digital assessed that inserting fake receipts into the Shop app is more effective than email delivery because users inherently trust a legitimate shopping app where real orders appear.
- Researchers noted the attacker contact details (phone/email) can be embedded in multiple receipt fields: order details, product description, receipt body, or the shipping-address field.
- Gen Digital enumerated the legitimate Shop ingestion channels that could be abused: connected Gmail/Outlook inbox parsing (keywords like 'tracking number' / 'track your package'), email linked to the Shop account, and Shop Pay transactions.
- Defensive guidance issued: do not call numbers on suspicious receipts, verify charges with the bank directly, reset passwords and contact card issuers if data was disclosed.
- During the call, operators extract credentials, payment card data and OTPs, and in some cases induce victims to install remote access software.
- Fake receipts embed an attacker-controlled support/billing/cancellation phone number; victims who call are moved off-platform and socially engineered.
- Gen Digital found no evidence that Shop, Shopify, or any impersonated company was compromised; the campaign abuses legitimate features rather than exploiting a vulnerability.
- Researchers state the exact injection path into the Shop order list remains unconfirmed; candidate vectors are merchant/order workflow, email parsing, and account association.
- Impersonated brands documented: Norton/Norton LifeLock, McAfee, Apple (gift cards, iPhone), PayPal, and high-value items such as MacBooks.
- BleepingComputer reported the campaign: order-tracking app Shop abused to push callback phishing (TOAD) attacks.
- Gen Digital published research describing fake invoices/receipts being inserted into shopping apps, including Shopify's Shop app, to drive callback phishing.
Sources cited for Shopify Shop App Abused to Deliver Fake Receipts for
- Order tracking app Shop abused to push callback phishing attacks
- Gen Digital — Fake invoices are moving from inboxes to shopping apps
- Shop Help Center — Identifying and reporting suspected fraud on Shop
- Norton Support — Verify that an email you receive from Norton is legitimate
- Proofpoint — Caught Beneath the Landline: A 411 on Telephone-Oriented Attack Delivery (TOAD)
- Intel 471 — To Deliver Malware, Attackers Use the Phone (callback phishing)
- The Hacker News — Hackers Using PDFs to Impersonate Microsoft, DocuSign and More in Callback Phishing Campaigns
- The Hacker News — FBI Alerts Law Firms to Luna Moth's Callback Phishing Campaign
Detection coverage for TL-2026-0944
As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0944 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.