# Shopify Shop App Abused to Deliver Fake Receipts for Callback Phishing (TOAD) Attacks Impersonating Norton, McAfee, Apple and PayPal

> Threat actors are inserting fraudulent purchase receipts into Shopify's Shop order-tracking app to run callback phishing (TOAD) campaigns impersonating Norton, McAfee, Apple and PayPal. The fake receipts embed attacker-controlled support phone numbers; victims who call are socially engineered into surrendering credentials, payment card data and one-time passcodes, or into installing remote access software.

- **Published:** 2026-06-25T00:00:00Z
- **Last reviewed:** 2026-06-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0944
- **ID:** TL-2026-0944
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Researchers at Gen Digital (the parent company of Norton, Avast, Avira, AVG and LifeLock) disclosed an in-the-wild abuse campaign in which scammers cause fraudulent purchase receipts to appear inside Shopify's consumer Shop app, which consumers use to track online orders. Rather than relying on a traditional email lure that must survive spam filtering and earn the recipient's trust, the actors place the fake invoice directly inside a legitimate, trusted application where users already expect to see real orders, dramatically increasing perceived legitimacy.

The fake receipts impersonate well-known brands — Norton/Norton LifeLock, McAfee, Apple (gift cards and iPhones), PayPal, and high-value items such as MacBooks — and typically claim a charge of several hundred dollars for a purchase or subscription the victim never made. Each fraudulent order includes an attacker-controlled 'support', 'billing', or 'cancellation department' phone number. This is a classic telephone-oriented attack delivery (TOAD) / callback phishing pattern: the lure contains no malicious link or attachment to trip automated defenses; instead it manipulates the alarmed victim into voluntarily phoning the attacker.

When the victim calls, the scam moves off-platform. A call-center operator skilled in social engineering poses as billing support, Norton support, PayPal support or a cancellation/refund department and walks the victim through 'cancelling' the bogus charge. Over the course of the call the operator extracts account credentials, payment card details and one-time passcodes (OTPs), and in some cases convinces the victim to install legitimate remote access / remote control software so the operator can take control of the device — the same playbook used by refund-scam and ransomware-precursor crews who pivot from a phone call to hands-on-keyboard access.

Gen Digital found no evidence that Shop, Shopify, or any of the impersonated companies (Norton, McAfee, Apple, PayPal) were breached. The exact mechanism by which the fraudulent orders are injected into the Shop app remains unconfirmed. Shop populates a user's order list through several legitimate channels — merchant/order workflows, email parsing (Shop scans connected Gmail/Outlook inboxes for shipping and tracking keywords), and account association — and the researchers believe the actors have found a way to misuse one of these legitimate ingestion paths rather than compromising the platform itself. Many fake receipts contain poor grammar, but victims frequently overlook these errors when distracted by an unexpected large charge. This threat is a fraud/abuse-of-feature campaign, not a software vulnerability; there is no associated CVE.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1598 Phishing for Information
- T1589 Gather Victim Identity Information
- T1566 Phishing
- T1684.001 Impersonation
- T1204 User Execution
- T1219 Remote Access Tools
- T1111 Multi-Factor Authentication Interception
- T1056 Input Capture
- T1005 Data from Local System
- T1657 Financial Theft

## Sources

- [Order tracking app Shop abused to push callback phishing attacks](https://www.bleepingcomputer.com/news/security/order-tracking-app-shop-abused-to-push-callback-phishing-attacks/)
- [Gen Digital — Fake invoices are moving from inboxes to shopping apps](https://www.gendigital.com/blog/insights/research/fake-invoices-shopping-apps)
- [Shop Help Center — Identifying and reporting suspected fraud on Shop](https://help.shop.app/en/shop/suspected-fraud/identifying-and-reporting-fraud-on-Shop)
- [Norton Support — Verify that an email you receive from Norton is legitimate](https://support.norton.com/sp/en/us/home/current/solutions/v71088498)
- [Proofpoint — Caught Beneath the Landline: A 411 on Telephone-Oriented Attack Delivery (TOAD)](https://www.proofpoint.com/us/blog/threat-insight/caught-beneath-landline-411-telephone-oriented-attack-delivery)
- [Intel 471 — To Deliver Malware, Attackers Use the Phone (callback phishing)](https://www.intel471.com/blog/to-deliver-malware-attackers-use-the-phone)
- [The Hacker News — Hackers Using PDFs to Impersonate Microsoft, DocuSign and More in Callback Phishing Campaigns](https://thehackernews.com/2025/07/hackers-using-pdfs-to-impersonate.html)
- [The Hacker News — FBI Alerts Law Firms to Luna Moth's Callback Phishing Campaign](https://thehackernews.com/2025/05/hackers-are-calling-your-office-fbi.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0944
