The images in this article were generated with artificial intelligence. How we publish
In recent weeks, reports of malicious actors who insert false invoices and receipts into Shop, the order tracking app linked to Shopify, have increased in order to deceive users to deliver sensitive data or install remote access software. These fraudulent notifications are shown along with legitimate purchases, imitate recognized brands such as Norton, McAfee, Apple or PayPal and usually include a phone number to "dispute" charges - when actually on the other side is a scam who uses social engineering techniques.
Shop works as a digital assistant that consolidates orders and receipts from multiple shops and, therefore, the confidence implied in the application makes a false invoice there more convincing than an email. Digital Gen researchers describe these attacks and stress that there is no evidence that Shop or Shopify have been compromised; the problem seems to reside on the channels that the app itself uses to population the order history, such as post analysis, account associations or automated order flows. You can read the technical report here: Gen Digital - Fake inventions in shopping apps.

The method is dangerous because it exploits human behavior: in the face of a high amount of receipt many people act quickly for fear of an unauthorized charge. The scammers use this momentum to ask for credentials, card information or temporary codes (OTP) and, in some cases, persuade the victim to install a remote access tool with which to take control of the device. The combination of confidence in the app and temporary pressure is what increases the effectiveness of fraud.
It is not yet clear how exactly those fake bills are injected into Shop, and that complicates the answer. In the meantime, the experts' recommendation is to avoid following the contacts offered on fraudulent invoices and to verify any charges directly with the bank or with trade through official channels. To better understand how phishing scams work and how to recognize them, the FTC maintains useful resources: How to recognize and avoid phishing - FTC.
If he already interacted with a supposed "support" and provided sensitive information, change passwords immediately, activate multifactor authentication if you have not done so and contact your card issuer to block or replace the payment medium. If remote access software has been installed, disconnect the network device, remove the suspicious application if possible and request specialized technical assistance for a complete analysis; do not attempt to resume sensitive operations until you confirm the integrity of the system.

Users can reduce their exposure by reviewing the Shop settings: disable the automatic mail parseus if they don't need it, limit app permissions, check which accounts are linked and review the order history calmly rather than acting under pressure. It is also recommended to use SMS or mail bank alerts for new charges and regularly audit account recovery methods (alternative mail, telephone) to detect unauthorized additions.
From the point of view of companies and security equipment, this incident reinforces the need to combine technical controls with specific training: to monitor signs of fraud related to third-party apps, to deploy detection of abnormal behaviour in endpoints and to educate employees and customers about social engineering indicators in mobile contexts and service aggregation applications. EDR tools, identity management policies and phishing simulations help measure and improve resilience to this type of vector.
Shop is very popular in North America; your Google Play page shows the scope of the app: Shop in Google Play. Until there is more clarity about the delivery of these false invoices, prudence and verification through official channels are the best defence:: do not call numbers on suspicious receipts, do not share codes or passwords and report incidents to Shopify and local authorities so that the campaign can be drawn and mitigated in a coordinated manner.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...