Cybercriminals are putting a new twist on the classic fake refund scam by abusing Shopify’s legitimate Shop notification pipeline instead of relying only on spoofed emails or fake websites. Security researchers at Huntress say victims are receiving bogus purchase and invoice alerts directly inside the real Shop app, sometimes accompanied by normal-looking push notifications that make the messages appear much more trustworthy.
The campaign matters because it exploits user trust in a genuine platform rather than merely impersonating Shopify from the outside. Huntress says several of its own employees received the messages between May and August 2026, while similar reports appeared elsewhere during the year. The objective is to convince a target that an unfamiliar purchase has been made and push the victim toward contact details controlled by scammers.
Attackers are abusing Shopify’s own notification infrastructure
Huntress says the scheme likely relies on fraudulent or compromised Shopify seller accounts that generate bogus orders. Because the order is created inside Shopify’s ecosystem, the victim can receive an authentic Shop app notification instead of a conventional phishing email sent from a suspicious domain.
Researchers describe the tactic as a variation of ‘Living Off Trusted Sites.’ In this case, Shopify’s own notification mechanism helps deliver the fraudulent order alert, lowering a user’s natural suspicion because the message appears inside a legitimate service.
The fake order is designed to make victims call the scammer
The fraudulent orders can contain attacker-controlled contact details in fields such as the shipping address or receipt information. A victim who sees a large or unfamiliar purchase may believe the phone number or email shown in the order is the correct place to dispute the charge or request a refund.
Huntress warns that scammers may then pressure callers into granting remote access, disclosing online-banking credentials, or ‘returning’ a supposed overpayment through gift cards or a wire transfer. The original purchase is fake, but any money sent by the victim is real.
Users should verify the transaction outside the suspicious order
Huntress recommends that users avoid calling phone numbers, emailing addresses or opening links included in an unfamiliar order. Instead, they should independently check their bank, card issuer, PayPal or other payment account to confirm whether a real charge exists.
Shopify users can mark suspicious Shop orders as ‘Not my order’ where available, while Shopify’s security guidance advises reporting phishing through official channels. The broader lesson is that a notification delivered through a real platform can still contain attacker-controlled content.
Trusted-platform abuse is becoming a bigger cybersecurity problem
The Shopify case illustrates a broader challenge: attackers increasingly try to operate inside services users already trust, including cloud platforms, advertising systems, collaboration tools and customer-support infrastructure. When criminals can borrow a trusted platform’s branding or delivery channel, traditional visual warning signs become less reliable.
For users and businesses, the safer habit is to verify the underlying event through a second independent channel before taking action. A payment alert should be checked against the actual payment account, and support contact details should be obtained separately from the suspicious message. Platform authenticity and message authenticity are no longer the same thing.







