Scammers hijack real Shopify notifications to swindle victims — here's how to stay safe
Would you recognize a fake notification if it came directly from Shopify?
by https://www.techradar.com/uk/author/sead-fadilpai · TechRadarNews By Sead Fadilpašić Published 14 August 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
- Huntress uncovers Shopify refund scam using fake orders and app notifications
- Attackers embed contact details in shipping addresses to trick victims into paying
- Users advised to ignore suspicious info, verify refunds, and report fake stores
Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.
Security researchers at Huntress outlined how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.
If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.
Latest Videos FromTechRadarWatch full video here:
Abusing Shopify's infrastructure
There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible.
In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.
Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.
This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors