Affected Systems
Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures. Scope includes any user with the Shop app installed who may receive fake order notifications.
Exploitation Status
Active exploitation confirmed. Threat actors are currently abusing Shopify's Shop app infrastructure to inject fake receipts and conduct callback phishing campaigns. This is an ongoing abuse of legitimate platform features rather than a technical vulnerability.
Business Impact
Users may receive convincing fake order receipts through the trusted Shopify Shop app, increasing likelihood of successful phishing. Attackers aim to harvest credentials, payment card data, or trick victims into installing remote access tools (e.g., AnyDesk, TeamViewer). Organizations using Shopify for e-commerce or whose employees use the Shop app for personal purchases face social engineering risk. No direct technical compromise of Shopify infrastructure, but platform trust is weaponized.
Urgency
🟠Within 24 hours
Recommended Actions
- Alert users and employees about fake Shopify Shop app receipts; emphasize verifying orders directly with merchants before calling any phone numbers
- Block or monitor outbound connections to common remote access tools (AnyDesk, TeamViewer, ScreenConnect) at network perimeter if not business-required
- Review email gateway and endpoint logs for phishing indicators related to fake Shopify receipts or callback scam patterns
- Coordinate with Shopify security team if your organization operates stores on the platform to understand abuse mitigation measures
- Educate help desk and finance teams on callback phishing tactics to recognize and escalate suspicious user reports
