That Shop App Receipt You Don't Recognize Is a Scam
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

FOR BUSINESS

Open a free Amazon Business account

Business pricing, bulk buying and tax-exempt orders.

Create a free account

As an affiliate, we earn on qualifying purchases.

Scammers are inserting fake purchase receipts into the Shop app to trick users into calling support lines or clicking malicious links. Users should verify transactions carefully and avoid engaging with suspicious notifications.

Cybercriminals are inserting fake purchase receipts into the Shop app order histories, impersonating legitimate companies like Apple and PayPal. These fraudulent entries aim to trick users into calling scam support lines or sharing personal information, posing a significant security risk for millions of users.

Recent reports from cybersecurity researchers reveal that scammers are embedding fake invoices and order notifications within the Shop app user histories. These fake receipts often claim that large charges, subscriptions, or order preparations have been processed. They include contact details for disputing the charges, but calling these numbers leads to scammers who seek to steal login credentials, credit card info, or install malware.

Shop has acknowledged the issue, stating that they are implementing new controls to prevent such manipulations, but details on how the fake entries are inserted remain unclear. Experts note that these scams are part of a broader callback phishing tactic, frequently used by PayPal impersonators, which relies on convincing notifications to lure victims into malicious interactions.

At a glance
reportWhen: ongoing as of June 2026
The developmentCybercriminals are manipulating Shop app order histories with fake receipts to conduct callback phishing scams targeting users’ personal data.

Why Fake Shop Receipts Pose a Serious Security Threat

This scam is particularly concerning because it leverages a trusted app, making users less suspicious of fake notifications. The fake receipts may lead to identity theft, financial fraud, or remote device access if users engage with scammers. Since Shop app integrates with email and shipping data, the fake entries can appear highly convincing, increasing the risk of victims falling for the scam.

RUNBOX Wallet for Men Slim Leather Bifold RFID Blocking with 2 ID Windows

RUNBOX Wallet for Men Slim Leather Bifold RFID Blocking with 2 ID Windows

  • Slim and Compact Design: Measures 4.3×3.2×0.6 inches, fits in pocket
  • Capacity and Card Slots: Holds up to 15 cards with 2 additional slots
  • Quick Access Features: Includes 2 ID windows and 2 quick slots

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Shop App Security Incidents

The Shop app, used by millions for order tracking and payment, pulls data from Shopify stores and email messages, which scammers are exploiting to insert fake purchase records. While Shop has not reported a breach of their systems, the scam involves malicious third-party actors manipulating user histories. Similar callback phishing schemes have been reported before, but this specific tactic of inserting fake receipts into app histories is a recent development that cybersecurity experts are currently investigating.

“The way these fake receipts are integrated into user histories makes them appear legitimate, which can easily deceive unsuspecting users.”

— an anonymous researcher

JSAUX USB Data Blocker & USB C Data Blocker, Charge-Only, 4-Pack, Grey

JSAUX USB Data Blocker & USB C Data Blocker, Charge-Only, 4-Pack, Grey

  • Data Protection from Viruses: Blocks data transfer to prevent malware
  • Charge-Only Functionality: Allows charging without data transfer
  • Fast Charging Support: Supports up to 100W fast charging

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unclear Details About How Fake Orders Are Inserted

It is not yet confirmed how threat actors are inserting these fake receipts into user histories, nor whether Shop, Shopify, or any of the companies being impersonated have been breached. The specifics of the attack vector remain under investigation, and Shop has not provided detailed technical explanations.

Identity Theft Protection Roller Stamp, 1 Refill Ink - Confidential Roller Stamp for Identity Protection & Security Stamps- Blocking Out Privacy Information and Guard Your Address and ID

Identity Theft Protection Roller Stamp, 1 Refill Ink – Confidential Roller Stamp for Identity Protection & Security Stamps- Blocking Out Privacy Information and Guard Your Address and ID

  • Identity Theft Protection: Obscures sensitive data securely
  • Convenient to Use: Quickly conceal personal info
  • Time and Cost Saving: Reduces shredding needs

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Users and Shop Security Measures

Users should verify any suspicious receipts against their bank or vendor accounts and avoid calling any phone numbers or clicking links in unrecognized notifications. Shop is expected to enhance security controls and provide further guidance on identifying authentic transactions. Cybersecurity researchers will continue investigating the method of insertion and the scope of the scam.

Password Keeper,Auto Filling and Offline Storage Password Manager, Type-C Port, Compatible with Phones, Tablets,Computers,etc. Electronic Password Keeper is Suitable for Various APP Or Websites

Password Keeper,Auto Filling and Offline Storage Password Manager, Type-C Port, Compatible with Phones, Tablets,Computers,etc. Electronic Password Keeper is Suitable for Various APP Or Websites

  • One Master Password: Secure access to all credentials
  • Auto Fill & Instant Login: Automatically fill login details
  • Type-C Connectivity: Compatible with phones, tablets, computers

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How can I tell if a Shop receipt is fake?

Check your bank or credit card statements for matching charges. Look for poor grammar, spelling errors, or unfamiliar contact details in the notification. If in doubt, verify directly with the vendor through official channels.

What should I do if I receive a suspicious receipt?

Do not call any support numbers or click links. Report the suspicious receipt to Shop and the legitimate vendor. If you have engaged with scammers, change your passwords and monitor your accounts for unusual activity.

Is my Shop account or device compromised?

There is currently no evidence that Shop or Shopify systems have been breached. The scam appears to involve third-party manipulation of user histories rather than a direct breach of the platform.

Will Shop implement new security controls?

Yes, Shop has announced they are working on ‘new controls’ to mitigate the insertion of fake receipts, though specific measures have not yet been disclosed.

Should I stop using the Shop app?

No. Continue using the app but remain vigilant. Verify transactions carefully and report any suspicious activity to Shop support.

Source: Lifehacker

POOL SEASON

Pool season Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Lenovo Surges In Global Coverage

Lenovo’s media mentions have surged, with GDELT recording 46 mentions in recent analysis, indicating heightened global attention on the company.

Indonesia’s social media ban tests families’ digital reality

Indonesia’s recent social media restrictions are impacting families’ online routines, raising questions about digital access and daily life.

AI coding agents can be tricked into installing malware via ‘clean’ GitHub repositories — Mozilla’s 0din team shows how Claude Code can be exploited by its own helpfulness

Researchers demonstrate how AI coding tools like Claude can be tricked into installing malware from seemingly safe GitHub repositories, posing security risks.

Xsolis Data Breach Affects 1.4 Million Individuals

Xsolis disclosed a data breach affecting approximately 1.4 million individuals, exposing sensitive health and personal information. The incident was detected in January.