The standard advice for spotting phishing is straightforward, check the sender’s email address, look for the spoofed domain, notice the poor grammar, hover over the link before clicking. That advice is becoming less useful as attackers have discovered something more effective: skip the spoofing entirely and use the real thing.
Huntress published an investigation documenting a fake refund scam running inside Shopify’s Shop app since at least May 2026. The scam does not send fake emails from a Shopify lookalike domain. It sends real notifications through Shopify’s actual notification pipeline, which appear inside the Shop app as authentic receipts, complete with push alerts on the victim’s mobile device.
Multiple Huntress employees received these notifications between May and August 2026. Gen Digital researchers documented the same campaign independently. Reddit’s r/Scams community has multiple threads about it.
How the Scam Works
Shopify allows store owners to create orders and generate receipts for customers. When an order is created with a customer’s phone number or email address, the Shop app sends that customer a notification.
Scammers are exploiting this by creating fake Shopify stores and generating fake orders that list victims as the customers. The victim receives a legitimate Shop notification for a purchase they never made. The receipt looks indistinguishable from a real Shopify purchase confirmation because it is coming from Shopify’s own systems.
One receipt documented by Huntress, received on August 7, was for a “purchase” of a premium PC protection plan for $339.96. The description included an invoice number, a transaction ID, and a “support” phone number listed multiple times. The shipping address field, repurposed as a message, read: “2856 If You Didnt Place This Order Call Us at 1__888__690__3420, Albany NY.”
The store generating the notification was called “My Store” and had been removed by the time Huntress investigated it.
What Happens When Victims Call
The phone number is the trap. Victims who call reach a scammer who runs a standard fake refund script. The scammer acknowledges the “error,” apologises, and offers to process a refund. To do so, they ask the victim to install remote access software such as ScreenConnect or AnyDesk. Once installed, the scammer can see the victim’s screen and direct them to log into their bank account.
The scammer uses remote access to move money between accounts on the victim’s screen, creating the appearance of an accidental overpayment. The victim’s screen is then obscured while the real manipulation happens. The scammer claims the victim was accidentally refunded too much and must return the difference immediately, typically via Google Play gift cards whose codes the scammer redeems before the call ends.
Some variants of the Shopify scam incorporated the app’s shipment tracking feature, adding a fake “out for delivery” status to increase urgency and legitimacy.
This Is Not a Shopify Vulnerability. It Is Shopify’s Features Being Weaponised.
Huntress categorises the technique as a variant of “Living Off Trusted Sites,” or LoTS, a method that became increasingly common in 2025. Rather than linking victims to a fake domain, LoTS attacks use legitimate platforms’ own infrastructure to deliver malicious content that passes every technical check: the sender is real, the domain is real, the hosting is real, and the SSL certificate is real.
The most comparable documented example is a PayPal variant: scammers open real PayPal accounts and send actual PayPal invoices with fake callback numbers in the note field. The emails arrive from PayPal’s genuine servers, bypass spam filters entirely, and the invoice link opens a real page hosted at PayPal.com. The only fake element is the callback number.
The Shopify version adds one further layer: the notification does not arrive by email at all. It arrives as a push notification inside an app the victim already trusts, on a device they use daily, looking exactly like every other Shopify order confirmation they have ever received.
The Context: Shopify Is Having an Unusual Week
The Huntress investigation lands in a week when Shopify has been prominent in EcomWatch’s coverage for other reasons: the CEO’s controversial voting comments generating a boycott campaign targeting merchants, and a broader conversation about platform trust and merchant dependency.
The fake refund scam is a different kind of platform trust issue. The boycott campaign is about whether consumers trust the person running Shopify. The fake refund scam is about whether consumers can trust notifications that come through Shopify’s infrastructure. Both, in different ways, are questions about what it means to rely on a platform.
What Shopify Users Should Do
Do not call any phone number embedded in a Shop app receipt for a purchase you did not make. Shopify does not embed callback numbers in receipts. Any receipt containing a phone number asking you to call about a refund is a scam regardless of how legitimate the notification looks.
If you receive an unrecognised order in your Shop app, report it within the app as “Not my order.” Check your actual bank account or payment method to confirm whether you were charged. If you were not charged, no action beyond reporting is required. Contact Shop Support through the official app or website, not through any contact information in the suspicious receipt.
Our Take
The App You Trust Is Now the Attack Surface
The Shopify fake refund scam is a preview of where consumer fraud is heading. The old model required spoofing: fake domains, fake sender addresses, fake websites that looked real but were not.
The new model requires none of that because the real infrastructure is available to anyone who creates an account. Shopify’s notification system is a feature, not a vulnerability. Scammers have figured out that features are more useful to them than vulnerabilities because features are not patched and not blocked by spam filters.
The victim receives a real notification from a real platform through a real app on their real device. Every signal they have been trained to use to evaluate legitimacy says this is legitimate. The only thing that is not legitimate is the phone number in the receipt.
For fraud that has been running since May, targets thousands of people, and is sophisticated enough to be documented simultaneously by two separate cybersecurity firms and discussed in Reddit threads, the response from Shopify has been a Help Centre article. Whether that is adequate is a question worth asking as peak season approaches and the volume of legitimate Shopify order notifications hitting consumers’ phones is about to increase significantly.













