FeedSocial EngineeringOrder-tracking app Shop abused to push callback phishing att...
Social EngineeringBleeping Computer
8.0CRITICAL

Order-tracking app Shop abused to push callback phishing attacks

📅 25 June 2026 at 19:45 UTC📰 Bleeping ComputerView original source ↗
Order-tracking app Shop abused to push callback phishing attacks

Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Threat actors are abusing the Shop order-tracking app by inserting fake purchase receipts to trick users into providing sensitive data or installing remote access software. This is a callback phishing attack, where users trust the app and respond to suspicious notifications.

⚙️Technical Details
💥Impact Assessment
Severity: high
Who Is at Risk
users who use the Shop app, particularly those in North America with substantial support and purchasing options
🛡️Recommended Actions
1Verify any alleged charge directly with your bank instead of calling the phone number listed on suspicious receipts
2Reset account passwords immediately if sensitive information has been disclosed to scammers
3Contact card issuers for cancellation of compromised cards
📦Affected Products
Shop digital shopping assistant

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed