Social EngineeringBleeping Computer
8.0 — CRITICAL
Order-tracking app Shop abused to push callback phishing attacks
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Threat actors are abusing the Shop order-tracking app by inserting fake purchase receipts to trick users into providing sensitive data or installing remote access software. This is a callback phishing attack, where users trust the app and respond to suspicious notifications.
⚙️Technical Details
💥Impact Assessment
Severity: high
Who Is at Risk
users who use the Shop app, particularly those in North America with substantial support and purchasing options
🛡️Recommended Actions
1Verify any alleged charge directly with your bank instead of calling the phone number listed on suspicious receipts
2Reset account passwords immediately if sensitive information has been disclosed to scammers
3Contact card issuers for cancellation of compromised cards
📦Affected Products
Shop digital shopping assistant
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
