Full Report
A Shopify fake refund scam has been making the rounds over the past few months, targeting Shopify’s Shop app users directly within the app. Here’s what to know.
Analysis Summary
# Incident Report: Shopify "Living Off Trusted Sites" Fake Refund Scam
## Executive Summary
Threat actors are exploiting Shopify’s legitimate "Shop" application infrastructure to deliver fraudulent invoice notifications directly to users. By creating fake merchant accounts, scammers trigger native push notifications and in-app receipts containing fraudulent support numbers to facilitate "fake refund" callback scams. This technique bypasses traditional email security filters by leveraging a trusted platform's internal notification system.
## Incident Details
- **Discovery Date:** May 2026 (Ongoing through August 2026)
- **Incident Date:** May 2026 – Present
- **Affected Organization:** Shopify (Platform exploited); Multiple end-users
- **Sector:** E-commerce / Retail
- **Geography:** Global (Reports specifically note US/New York lures)
## Timeline of Events
### Initial Access
- **Date/Time:** May 2026
- **Vector:** Abuse of legitimate Shopify merchant account creation.
- **Details:** Attackers register fake Shopify stores (e.g., "My Store") or compromise existing merchant accounts to access the Shopify order management system.
### Lateral Movement
- **Details:** N/A – The attack does not move laterally through a network but moves from the Shopify merchant platform to the consumer-facing "Shop" app via automated synchronization of order data.
### Data Exfiltration/Impact
- **Details:** No direct data exfiltration from Shopify; however, successful scams lead to the theft of financial funds, bank credentials, and potential remote access to victim devices via social engineering.
### Detection & Response
- **Discovery:** Huntress employees and researchers at Gen Digital observed unsolicited notifications for high-value items (e.g., $339.96 PC protection plans) within their official Shop apps.
- **Response Actions:** Shopify has taken down identified fraudulent stores (e.g., "My Store"). Security researchers have issued public warnings to increase user awareness.
## Attack Methodology
- **Initial Access:** Creation of fraudulent merchant accounts on Shopify.
- **Persistence:** Maintaining fake stores until flagged and removed by Shopify.
- **Defense Evasion:** "Living Off Trusted Sites" (LOTS). By using Shopify’s own infrastructure, the malicious messages bypass spam filters and DMARC/SPF checks that would block traditional phishing emails.
- **Discovery:** Using harvested phone numbers or email addresses to "assign" orders to targets.
- **Impact:** Financial fraud via "Callback Scams." Victims are pressured to call a number where they are tricked into granting remote access or sending money via gift cards/wire transfers.
## Impact Assessment
- **Financial:** High potential for individual victims; scammers often target amounts between $300–$1,000 per transaction.
- **Data Breach:** Exposure of victim phone numbers/emails to scammers; potential loss of banking credentials during the callback phase.
- **Operational:** Minimal disruption to Shopify platform, but significant abuse of its notification features.
- **Reputational:** Moderate; erodes user trust in the "Shop" app's notification reliability.
## Indicators of Compromise
- **Network Indicators:**
- Communications with `1__888__690__3420` (Defanged callback number)
- **Behavioral Indicators:**
- Unsolicited "Order Confirmed" push notifications within the Shopify Shop app.
- Receipts for digital goods (e.g., "PC protection plan") from unknown merchants like "My Store."
- Shipping address fields containing urgent "Call Support" messages instead of physical addresses.
## Response Actions
- **Containment:** Shopify identifies and disables fraudulent merchant accounts.
- **Eradication:** Removal of fake order entries from the Shop app database.
- **Recovery:** User education and alerts regarding the nature of callback scams.
## Lessons Learned
- **Key Takeaways:** Attackers are moving away from email spoofing toward abusing the internal notification pipelines of trusted SaaS platforms.
- **Systemic Issue:** Trust in native app notifications is high; platforms must implement better verification for new merchants before allowing them to trigger global notifications to non-customers.
## Recommendations
- **For Users:** Do not call numbers provided in unsolicited invoices. Verify orders by logging directly into a merchant's official website, not through the notification link.
- **For Platforms:** Implement rate-limiting on "New Order" notifications for new or unverified merchant accounts. Use AI to scan "Shipping Address" fields for suspicious strings like "Call this number" or "Refund."