Skip to content
Breaking:

Scammers Abuse Shopify Order System to Deliver Fraudulent Push Notifications

Cybersecurity firm Huntress warns that threat actors are manipulating native Shop app alerts to conduct fake refund scams.

By The Company Wire3 min read
Share
Shopify — Scammers Abuse Shopify Order System to Deliver Fraudulent Push Notifications
Shopify — Scammers Abuse Shopify Order System to Deliver Fraudulent Push Notifications. Photo: TechRadar Pro.

Cybercriminals are exploiting Shopify Inc.’s native communications network to deliver targeted scam alerts directly into consumer devices, according to research published by cybersecurity firm Huntress. The activity manipulates the e-commerce platform's official order generation process to transmit push notifications that appear fully authentic to app users, as first reported by TechRadar Pro. By abusing legitimate platform architecture, the attack vector allows threat actors to circumvent common security controls and establish credibility with potential victims.

The campaign operates by having attackers establish original storefronts on Shopify or compromise pre-existing vendor accounts. Once a merchant profile is active, the perpetrators create artificial purchase orders and list targeted consumers as the intended recipients. To link the orders to specific individuals, threat actors pull contact details—including mobile phone numbers and email addresses—from dark web data repositories and leaked personal record databases that are distributed freely or sold for minimal fees online.

Because the initial transaction request is processed through Shopify’s actual backend services, the platform automatically triggers system-level notifications to the recipient's mobile device. Users who have installed the official Shop application receive real-time push alerts featuring authentic Shopify branding alongside their legitimate commercial updates. The direct integration into the native application environment makes the communication substantially harder for consumers to distinguish from standard order processing notifications.

To monetize the operation, attackers must trick recipients into transferring money or surrendering sensitive financial details. In this campaign, rather than using outbound phone calls or traditional email outreach, threat actors manipulate the shipping address input field during order creation. The attackers embed high-pressure messages and toll-free support numbers within the physical address lines, counting on victims to panic over an unauthorized charge and reach out to resolve the issue.

In one documented instance examined by Huntress, an attacker configured a recipient's shipping destination to read: Owen Nolan "2856 If You Didnt Place This Order Call Us at 1_888_690_3420-", Albany NY United States 1_888_690_3420. The inclusion of capitalization errors, unnatural formatting, and out-of-place telephone credentials within the address field serves as a key indicator of compromise, though researchers noted that stressed or distracted users remain vulnerable to the tactic.

The strategy builds upon traditional refund fraud, where perpetrators claim that an erroneous transaction or system mistake resulted in an unintended payout to the victim, demanding that the excess capital be returned. While legacy refund scams rely on fake transaction receipts, modified web pages, or actual payments that are subsequently reversed, the Shopify technique shifts the burden onto the target to initiate contact, capitalizing on the perceived legitimacy of push notifications generated directly by Shopify’s servers.

Analysis from Huntress revealed that the storefronts deployed in the campaign were typically recently registered accounts. Some observed storefronts operated under default names such as "My Store" or presented "coming soon" landing pages prior to being removed from the platform. The cybersecurity firm noted that the specific merchant account observed during its investigation was deleted before full forensic scrutiny could be completed.

Huntress did not disclose whether the campaign successfully defrauded victims or whether specific groups of Shopify users were intentionally targeted. To protect against the vector, security experts recommend that consumers refrain from using phone numbers or web links contained within order address details. Users concerned about potential account compromises should inspect their financial institution statements to confirm whether actual charges occurred, utilize the "Not my order" reporting option inside the Shop application, and evaluate store reviews and history prior to engaging with unfamiliar digital merchants.

Sources

  1. TechRadar Pro

Company: Shopify

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.