Shopify’s Trusted Shop App Is Being Turned Into a Weapon — The New Refund Scam That Can Reach Your Phone

Listen to this Post

Featured ImageIntroduction: When a Real Notification Becomes the Trap

For years, online scams have depended on one obvious weakness: getting victims to trust something that looks legitimate. A fake email, a suspicious website, or an unexpected text message was often enough to raise alarm. But cybercriminals are now finding a more dangerous shortcut — abusing legitimate platforms so the warning itself comes from a service people already trust.

A new phishing campaign uncovered by cybersecurity researchers demonstrates exactly how effective that strategy can be. Instead of sending a fake Shopify email or a poorly disguised SMS, attackers are abusing the infrastructure behind Shopify’s Shop app to generate genuine-looking order notifications. The result is a scam that can arrive as a legitimate push notification, appear inside a trusted application, and look like a normal purchase receipt.

That changes the psychology of the attack.

The victim is no longer being asked to trust an unfamiliar website. They are being asked to trust something that their phone has already authenticated as coming from a familiar shopping ecosystem.

According to research from Huntress, attackers are creating fraudulent Shopify seller accounts — and in some cases compromising legitimate stores — to generate fake orders associated with victims’ phone numbers or email addresses. The victims then receive genuine Shop app notifications about purchases they never made.

The notification is real.

The transaction displayed inside the application may look real.

But the customer service number buried inside the order is where the scam begins.

The Evolution of the Fake Refund Scam

The campaign represents a significant evolution of the classic fake-refund scam. Traditional versions usually begin with an email or phone call claiming that a subscription, antivirus product, technical service, or other purchase has been charged to the victim.

The attacker then creates a sense of urgency.

“You were charged.”

“You did not authorize this.”

“Call immediately to cancel.”

Once the victim calls, the criminal impersonates a customer-service representative and attempts to gain remote access to the computer, access online banking, or manipulate the victim into believing that a refund has been processed incorrectly.

The Shopify-focused campaign follows the same psychological formula, but it removes one of the scammer’s biggest weaknesses: the suspicious initial message.

The Notification Is Real — The Story Is Not

Huntress reported that attackers were using fraudulent Shopify seller accounts to create bogus orders against victims’ email addresses or telephone numbers.

Because those orders move through Shopify’s legitimate ecosystem, the resulting notifications can appear naturally inside the Shop app.

That distinction matters.

A phishing email can be blocked by an email gateway. A malicious domain can be flagged by a browser. A suspicious sender address can immediately expose a scam.

But a notification generated by a legitimate shopping application can bypass many of those instinctive warning signs.

The victim sees a familiar application icon.

They see an order.

They see a product.

They see an invoice or transaction identifier.

And they may even see shipping information.

Everything looks familiar enough to trigger trust.

The $339.96 “PC Protection Plan” Trap

One example highlighted by Huntress involved a fake receipt dated August 7 for a supposed $339.96 “premium PC protection plan.”

The fraudulent order included details designed to make the purchase appear authentic, including an invoice number and transaction ID.

But the most important part of the fake order was not the product.

It was the shipping address.

Attackers reportedly used the address field to insert a message telling the recipient to call a telephone number if they had not placed the order.

This is a clever abuse of application functionality.

A field designed for legitimate commerce becomes a communication channel for social engineering.

Turning Shipping Information Into a Phishing Message

The technique demonstrates why modern phishing is increasingly difficult to detect using traditional indicators.

Attackers do not necessarily need to inject malicious code into an application.

They do not necessarily need to compromise the application itself.

They can sometimes manipulate the content that legitimate users expect to see.

In other variants, the callback number reportedly appears in the order description rather than the shipping address. Some attacks also include fake shipment-tracking information designed to create additional urgency.

The message effectively tells the victim:

You have been charged.

You did not authorize this.

Something is already being shipped.

Call this number immediately.

That sequence is carefully designed to prevent the victim from slowing down and thinking critically.

The Phone Call Is Where the Real Attack Begins

The fraudulent order is not necessarily the end goal.

It is bait.

Once a victim calls the telephone number included in the fake order, the attacker can transition into a conventional refund scam.

The supposed support representative may claim that the victim accidentally paid for a service and that a refund must be processed immediately.

The conversation can then move toward remote-access software, online banking, or other sensitive systems.

Huntress reported that attackers have encouraged victims to install remote-access tools such as ScreenConnect or AnyDesk.

This gives the criminal a much more powerful position than simply having the victim visit a malicious website.

Remote Access Turns Social Engineering Into Control

Remote-access software can be legitimate and widely used by businesses for technical support.

That is precisely why it is attractive to scammers.

The attacker does not have to persuade the victim that a mysterious piece of malware is safe.

Instead, the victim is convinced that legitimate support software is required to process a refund.

Once access has been granted, the scammer may instruct the victim to open online banking or another financial account.

The victim believes the representative is helping.

The attacker sees an opportunity.

The Fake Refund Becomes a Fake Overpayment

The next stage relies on psychological manipulation rather than sophisticated malware.

Scammers may manipulate what the victim sees on the screen or coach them through displayed transaction figures.

The goal is to convince the victim that the refund amount was accidentally entered incorrectly.

For example, the attacker might claim that the victim was supposed to receive $339 but that the system mistakenly issued $3,399.

Suddenly, the victim believes they owe the scammer money.

This is the classic refund-scam reversal.

The attacker first convinces the victim that money was accidentally sent to them and then pressures them to return the difference.

Gift Cards Become the Final Exit

Victims can then be instructed to purchase gift cards and provide the redemption codes to the scammer.

The attacker does not need to maintain access to the victim’s bank account forever.

The gift cards become the cash-out mechanism.

Once the codes are supplied, the criminal can attempt to redeem or resell them, making recovery extremely difficult.

The entire attack therefore progresses through several psychological stages:

A fake purchase creates fear.

The legitimate Shop notification creates credibility.

A phone number creates a direct communication channel.

A fake support representative creates authority.

Remote access creates technical control.

A fabricated refund error creates confusion.

Gift cards provide the final monetization opportunity.

Living Off Trusted Sites: The Bigger Security Lesson

Huntress describes the campaign as an example of what it calls Living off Trusted Sites, or LoTS.

The concept is important because it reflects a broader change in cybercrime.

Attackers increasingly do not want victims to visit obviously malicious infrastructure.

They want victims to remain inside legitimate services.

Previous LoTS campaigns have abused platforms such as Dropbox, Canva, and DocuSign to add legitimacy to malicious communications.

The Shopify campaign takes that idea one step further by abusing the notification pipeline of a major commerce platform.

Trust Has Become an Attack Surface

The deeper problem is not Shopify alone.

It is trust.

Modern digital life depends on thousands of services that users automatically trust. We trust banking applications, cloud storage platforms, collaboration tools, shopping apps, payment processors, delivery services, and identity providers.

Attackers understand this.

Instead of asking, “How can I make my fake website look legitimate?” they are increasingly asking, “How can I make my malicious message appear inside something legitimate?”

That is a much more powerful question.

Why Traditional Phishing Detection Can Struggle

Traditional phishing awareness training often teaches people to examine sender addresses, URLs, spelling mistakes, domains, and suspicious attachments.

Those lessons remain valuable.

But they are no longer enough.

If the malicious content is delivered through a legitimate application, checking the domain may provide little protection.

There may be no suspicious URL.

There may be no malicious attachment.

There may be no strange sender.

The danger may simply be embedded inside legitimate content generated by a trusted platform.

The Psychological Attack Is More Important Than the Technical Attack

This campaign is a reminder that many successful cyberattacks do not depend on breaking encryption or exploiting a zero-day vulnerability.

They depend on breaking human judgment.

The attackers create uncertainty first.

Then they introduce urgency.

Then they offer a seemingly authoritative solution.

The victim is pushed toward a decision before they have time to independently verify what happened.

That is why unexpected financial notifications deserve a pause, even when they appear inside legitimate applications.

Shopify’s Response and User Guidance

Shopify has acknowledged the scam through its Help Center and has advised users to avoid interacting with unfamiliar telephone numbers, email addresses, or links contained in suspicious orders.

Huntress similarly recommends contacting Shop Support directly if users are concerned about the security of their accounts.

The distinction is critical:

Do not use the contact information provided by the suspicious order to verify the suspicious order.

Instead, open the official application or website independently and find the support channel yourself.

Check Your Bank Before Calling Anyone

One of the simplest defenses is also one of the most effective.

If a notification claims that you have been charged hundreds of dollars, check your bank or credit-card account independently.

Do not assume that an order notification means money has actually left your account.

An order can be created.

A notification can be generated.

A receipt can be displayed.

None of those facts automatically proves that your bank account was charged.

Use “Not My Order” When Appropriate

Shop users who receive a suspicious order can reportedly flag it as “Not my order.”

That provides an appropriate response path without requiring the victim to engage with the scammer.

The broader lesson is simple: use the security and reporting mechanisms provided by the platform rather than the contact details supplied by an unexpected transaction.

Newly Created Stores Are Another Warning Sign

Huntress also recommends examining a store’s reviews and history before making purchases.

This is particularly relevant because many of the fraudulent storefronts involved in the campaign were reportedly newly created.

A brand-new store is not automatically malicious.

But a combination of warning signs should increase skepticism.

A newly created seller.

An unexpected order.

A strange product.

An urgent phone number.

A refund warning.

A request for remote access.

Together, those indicators form a much stronger signal.

The Same Scam Could Spread Beyond Shopping

The technique is potentially more important than the individual Shopify campaign.

If attackers discover that legitimate application notifications are effective social-engineering channels, other ecosystems could become attractive targets.

Delivery platforms could theoretically become bait.

Invoice platforms could become bait.

Booking systems could become bait.

Payment applications could become bait.

Enterprise collaboration tools could become bait.

The common denominator is not the industry.

It is trusted notification infrastructure.

Why This Matters to Businesses

Organizations should not assume that phishing awareness programs protect employees simply because employees know how to identify suspicious emails.

Security teams need to consider trusted-platform abuse as part of their threat model.

An employee could receive a legitimate notification from a legitimate service and still be the target of a fraudulent transaction.

That means security awareness training should include a new rule:

A legitimate notification does not necessarily mean a legitimate request.

What Security Teams Should Watch For

Organizations can monitor for unusual use of remote-access tools, especially when employees have no legitimate support ticket associated with the session.

Security teams should also pay attention to unusual gift-card purchases, unexpected financial activity, and help-desk reports involving fake refunds.

Employees who report suspicious orders should be encouraged to contact internal security teams before calling numbers supplied inside those orders.

This creates an additional layer of verification between the attacker and the victim.

Deep Analysis: How the Attack Chain Works

Stage One: Identity Targeting

The attacker first obtains a victim’s email address or phone number.

These identifiers may come from previous data leaks, public information, marketing databases, breached accounts, or other sources.

The attacker does not necessarily need the victim’s Shopify credentials.

Stage Two: Fraudulent Commerce Activity

A fraudulent or compromised seller account is used to create an order associated with the target.

The purpose is not necessarily to complete a real transaction.

The purpose is to generate a convincing notification.

Stage Three: Trusted Notification Delivery

The Shop ecosystem processes the order as legitimate platform activity.

The victim receives a push notification or sees the order inside the application.

This is the critical trust-building stage.

Stage Four: Social Engineering

The order contains a telephone number or instructions encouraging the victim to call.

The victim is deliberately moved away from the platform’s normal support process.

Stage Five: Remote Access

The scammer may instruct the victim to install legitimate remote-support software.

The attacker now has a potential mechanism for observing or controlling the victim’s computer.

Stage Six: Financial Manipulation

The victim is directed toward online banking or another financial interface.

The attacker then attempts to manufacture the appearance of a mistaken refund.

Stage Seven: Monetization

The victim is pressured into “returning” money, often through gift cards.

At this point, the original Shopify notification has served its purpose.

It was simply the first step in a much larger social-engineering chain.

Defensive Command-Line Checks

Security-conscious users and administrators can review active network connections on Windows with:

Get-NetTCPConnection -State Established |
Sort-Object RemoteAddress |
Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,OwningProcess

This does not automatically identify a scam or malicious connection, but it can help administrators investigate unexpected outbound activity after a suspicious remote-support session.

To inspect running processes:

Get-Process |
Sort-Object CPU -Descending |
Select-Object -First 25 Name,Id,CPU

For organizations using Windows Defender, an administrator can review recent detections with:

Get-MpThreatDetection |
Select-Object DetectionTime,ThreatName,ActionSuccess

On Linux systems, administrators can inspect established network connections with:

ss -tunap

And review recently running processes with:

ps aux --sort=-%cpu | head -25

These commands are defensive investigation tools. They should be interpreted in context rather than treated as automatic proof of compromise.

If You Already Installed Remote-Access Software

If you installed ScreenConnect, AnyDesk, or another remote-access application because of an unexpected refund call, treat the situation seriously.

Disconnect the device from the network if you believe an attacker is actively controlling it.

Do not continue communicating with the scammer.

From a separate trusted device, change important passwords and review financial activity.

Contact your bank or card provider directly using the number printed on the card or obtained from the institution’s official website.

If the computer belongs to an organization, contact the security or IT team immediately.

Never Let the Scammer Define the Verification Process

One of the strongest defensive principles from this campaign is remarkably simple:

The person who created the emergency should never be allowed to control the verification process.

If an unexpected order tells you to call a number, do not call that number.

Open the service independently.

Find its official support channel.

Check your bank independently.

Check your account independently.

Only then decide whether something actually happened.

What Undercode Say:

Trust Is Becoming a Cybersecurity Vulnerability

The Shopify campaign illustrates something much larger than another refund scam.

Cybersecurity has traditionally focused heavily on malicious infrastructure.

But attackers are increasingly hiding behind infrastructure that is already trusted.

The Perfect Phishing Message May Not Look Like Phishing

The most dangerous message may have no suspicious domain.

It may have no spelling errors.

It may not arrive from a strange sender.

It may appear inside an application you use every day.

Legitimate Platforms Can Be Abused Without Being “Hacked”

This distinction is essential.

A scammer does not necessarily need to compromise Shopify’s core systems to abuse Shopify.

They may simply manipulate legitimate functionality in a way the platform was never intended to support.

The Notification Pipeline Is Now Part of the Attack Surface

Push notifications are powerful because users instinctively associate them with events that have already happened.

A notification saying “Your order has shipped” feels different from an email claiming “Your order has shipped.”

The former feels system-generated.

That psychological difference is valuable to criminals.

LoTS Could Become a Major Cybercrime Pattern

Living off Trusted Sites deserves increasing attention because it changes the economics of phishing.

Instead of building infrastructure, attackers can exploit services that already have strong reputations.

That potentially makes their campaigns cheaper and harder to distinguish from normal activity.

Social Engineering Is Adapting Faster Than Awareness Training

Many security-awareness programs still revolve around suspicious emails.

Attackers have moved beyond that.

The next generation of training needs to teach people how to question unexpected actions inside trusted applications.

A Real App Does Not Guarantee a Real Transaction

This should become a basic cybersecurity principle.

An authentic application can display fraudulent information.

A legitimate account can be abused.

A trusted notification can contain malicious instructions.

Trust must therefore be attached to the action, not simply the platform.

Remote Support Tools Remain a Favorite Criminal Weapon

Tools such as AnyDesk and ScreenConnect are useful technologies.

The problem is not the software itself.

The problem is who is controlling the session and why.

A legitimate remote-access program can become dangerous when a victim installs it under fraudulent instructions.

Gift Cards Remain Attractive Because They Are Difficult to Reverse

The final stage of these scams also demonstrates why criminals continue to favor gift cards.

Once redemption codes are handed over, recovering the money can be extremely difficult.

The victim may think they are performing a refund.

The attacker knows they are receiving a cash-equivalent asset.

Urgency Is the Scammer’s Most Valuable Tool

The fake order creates emotional pressure.

The victim believes money has already disappeared.

The attacker then presents a phone call as the only immediate solution.

Removing urgency from the situation dramatically weakens the attack.

Independent Verification Breaks the Chain

The most effective defense is often independent verification.

Do not verify an order through the telephone number inside the order.

Do not verify a banking problem through the person who claims to have caused it.

Do not download software because an unsolicited caller tells you to.

Verify through a separate trusted channel.

Businesses Need to Update Security Awareness Training

Corporate security teams should expand phishing simulations beyond email.

Training should include fake invoices, marketplace notifications, collaboration alerts, support calls, delivery messages, and fraudulent transactions appearing inside legitimate applications.

Security Teams Should Treat Reports of “Refund Calls” Seriously

An employee saying, “Someone called me about a refund,” should not automatically be treated as a minor scam attempt.

The employee may already have installed remote-access software.

The incident could have progressed into credential theft or financial fraud.

The Human Firewall Still Matters

Technology can detect suspicious behavior.

It can block malicious domains.

It can monitor endpoints.

But the victim remains an important part of the attack chain.

Teaching users to stop, verify, and independently investigate can prevent an otherwise sophisticated campaign from succeeding.

The Industry Is Entering a New Trust Era

The future of phishing may be less about creating convincing fake websites and more about manipulating legitimate digital ecosystems.

That makes identity, notification systems, marketplace infrastructure, and third-party integrations increasingly important security boundaries.

Shopify Is Only One Example

The same strategy could potentially be adapted to almost any platform capable of generating trusted notifications.

That makes this campaign worth studying even for people who rarely use Shopify.

The underlying attack pattern is platform-independent.

Security Needs to Follow the User

Users do not think in terms of DNS reputation, authentication tokens, application APIs, or infrastructure trust relationships.

They think:

“My phone says I bought something.”

Security systems and awareness programs need to understand that psychological reality.

The Most Dangerous Scam May Be the One That Looks Completely Normal

That is the central lesson.

Criminals do not always need to create something fake.

Sometimes they only need to put something malicious inside something real.

The Best Defense Is a Deliberate Pause

When money, refunds, passwords, or remote access are involved, urgency should become a warning signal.

Stop.

Close the message.

Open the service independently.

Check your bank.

Contact official support.

Then act.

Trust Should Be Verified, Not Assumed

The Shopify campaign demonstrates why cybersecurity cannot depend solely on recognizable brands.

A trusted logo is not proof.

A legitimate application is not proof.

A push notification is not proof.

Verification must come from an independent source.

The Bigger Warning for 2026

As cybercriminals increasingly combine legitimate cloud services, AI-assisted social engineering, automated account creation, and trusted notification systems, attacks will become increasingly difficult to identify through appearance alone.

The strongest defense will increasingly be behavioral:

Why did I receive this?

Was I expecting it?

Did money actually leave my account?

Who is asking me to act?

Can I verify that independently?

Those questions can stop an attack before the attacker ever reaches the technical stage.

✅ The Core Shopify Abuse Claim

The supplied report attributes the campaign to research from Huntress and describes fraudulent Shopify seller accounts being used to generate unexpected orders and Shop notifications. The campaign is presented as an abuse of legitimate platform functionality rather than a conventional Shopify malware infection.

✅ The Fake Refund and Remote-Access Pattern

The described progression — unexpected order, callback request, remote-access software, banking interaction, fake refund discrepancy, and gift-card payment — is consistent with the established refund-scam model described in the source material.

✅ Living off Trusted Sites

Huntress’s characterization of the campaign as Living off Trusted Sites (LoTS) is central to the supplied reporting. The broader security interpretation is also reasonable: attackers can gain credibility by routing malicious social engineering through legitimate services.

❌ A Legitimate Shop Notification Does Not Prove Your Account Was Charged

Receiving an authentic-looking order notification does not automatically mean a real payment was taken from a bank account or credit card. Users should independently inspect their financial accounts before assuming money has been lost.

❌ Remote-Access Software Is Not Inherently Malicious

AnyDesk and ScreenConnect are legitimate remote-support technologies. The security problem arises when scammers persuade victims to install or authorize them under false pretenses.

Prediction

(+1) Trusted-Platform Abuse Will Become a Bigger Phishing Trend

As conventional email filters become better at identifying malicious domains and obvious phishing messages, attackers are likely to continue moving toward legitimate platforms that can generate convincing notifications.

The next wave may involve commerce, payment, delivery, cloud-storage, collaboration, and identity platforms.

(+1) Security Training Will Shift From “Spot the Fake” to “Verify the Request”

Organizations will increasingly teach employees that a legitimate notification can still lead to a fraudulent action.

The emphasis will move from identifying fake interfaces toward independently verifying unexpected transactions and instructions.

(+1) Remote-Access Scams Will Remain a Major Monetization Method

As long as scammers can convince victims that technical assistance is required, legitimate remote-support tools will remain attractive to criminals.

The technology itself is unlikely to disappear.

The fight will focus on preventing unauthorized social-engineering-driven use.

(-1) Platform Reputation Alone Will Become Less Reliable

The old assumption that “I trust this company, therefore this message is safe” is becoming increasingly dangerous.

Attackers are learning that they can exploit the reputation of trusted ecosystems without necessarily compromising the underlying company.

Final Takeaway: When the Alert Is Real but the Emergency Is Fake

The Shopify Shop scam represents an important shift in modern phishing.

The attacker does not necessarily need a fake application.

They do not necessarily need a malicious domain.

They may not even need to compromise the victim’s device at the beginning.

Instead, they can exploit something much simpler: the trust people place in legitimate notifications.

That is what makes this campaign so effective.

A real notification can carry a fake story.

A real order can contain a fake telephone number.

A real support tool can be used by a criminal.

A real banking screen can be manipulated through social engineering.

And a legitimate platform can become the first step in an entirely fraudulent transaction.

The safest response to an unexpected order is therefore not panic.

It is verification.

Do not call the number in the message.

Do not install software because a stranger tells you to.

Do not log into your bank while someone is remotely controlling your computer.

Do not purchase gift cards to “return” a refund.

Instead, leave the notification, open the service independently, check your financial accounts, and contact official support through a channel you found yourself.

In the evolving world of cybercrime, the most dangerous scam may no longer be the one that looks fake.

It may be the one that looks exactly like something you already trust.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.itsecurityguru.org
Extra Source Hub (Possible Sources for article):
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube