{"id":563,"date":"2026-07-01T14:49:09","date_gmt":"2026-07-01T09:19:09","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=563"},"modified":"2026-08-18T14:56:11","modified_gmt":"2026-08-18T09:26:11","slug":"fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/","title":{"rendered":"Fake Shop Receipts Bring Callback Phishing Into Trusted Order Histories"},"content":{"rendered":"<p>Cybercriminals continue to evolve their <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing<\/a> tactics, and email is no longer their only delivery channel. A new Shop app phishing campaign plants fake purchase receipts directly inside users&#8217; order histories, exploiting the trust people place in legitimate shopping applications.<\/p>\n<p>Instead of malicious links, victims are prompted to call fraudulent support numbers, where attackers attempt to steal sensitive information or gain remote access to devices.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Your Endpoint Defenses with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Shop app phishing campaign exploits trusted order histories<\/h2>\n<p>The Shop app, developed by Shopify, helps users manage purchases from multiple merchants through a centralized order history. Researchers from Gen Digital recently discovered that threat actors are abusing this trusted environment by inserting fraudulent purchase receipts alongside legitimate orders.<\/p>\n<p>Importantly, there is no evidence that Shopify, Shop, or the impersonated brands were compromised. Instead, attackers are exploiting the platform&#8217;s trusted user experience through social engineering.<\/p>\n<p>The fake receipts imitate well-known companies, including:<\/p>\n<ul>\n<li>Norton<\/li>\n<li>McAfee<\/li>\n<li>Apple<\/li>\n<li>PayPal<\/li>\n<\/ul>\n<p>Each receipt claims that an expensive purchase has been made and provides a phone number for disputing the transaction. Because users expect purchase information inside an order-tracking application, these fake entries appear far more convincing than traditional phishing emails.<\/p>\n<h2>How the callback phishing attack works<\/h2>\n<p>Unlike conventional phishing campaigns that rely on malicious links, callback phishing shifts the attack to a live conversation.<\/p>\n<p>The attack typically follows this sequence:<\/p>\n<table>\n<thead>\n<tr>\n<th>Stage<\/th>\n<th>Attacker activity<\/th>\n<th>Risk to users<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Fake receipt<\/td>\n<td>Fraudulent purchase appears inside Shop<\/td>\n<td>Creates urgency and panic<\/td>\n<\/tr>\n<tr>\n<td>Phone call<\/td>\n<td>Victim calls the listed support number<\/td>\n<td>Establishes attacker credibility<\/td>\n<\/tr>\n<tr>\n<td>Social engineering<\/td>\n<td>Scammer impersonates customer support<\/td>\n<td>Builds trust through conversation<\/td>\n<\/tr>\n<tr>\n<td>Data theft<\/td>\n<td>Requests passwords, payment details, or MFA codes<\/td>\n<td>Credential compromise and financial fraud<\/td>\n<\/tr>\n<tr>\n<td>Device takeover<\/td>\n<td>Victim installs remote access software<\/td>\n<td>Full endpoint compromise<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>During the phone conversation, attackers commonly attempt to obtain:<\/p>\n<ul>\n<li>Enterprise credentials<\/li>\n<li>Banking or payment card information<\/li>\n<li>OTP theft through <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-multi-factor-authentication-mfa\/\">MFA<\/a> verification requests<\/li>\n<li>Password reset codes<\/li>\n<li>Approval for installing remote support applications<\/li>\n<\/ul>\n<p>In several observed cases, victims were instructed to install remote access software under the pretense of processing refunds or reversing fraudulent transactions. Once installed, attackers gain direct control over the endpoint, significantly expanding the scope of the compromise.<\/p>\n<h2>Enterprise risks extend beyond personal purchases<\/h2>\n<p>Although the fraudulent receipts target consumers, the consequences can quickly affect enterprise environments.<\/p>\n<p>Employees frequently use the same devices for both personal shopping and business applications. If a user installs remote access software or shares authentication information during a callback phishing attack, attackers may gain access to:<\/p>\n<ul>\n<li>Corporate VPN sessions<\/li>\n<li>Enterprise password managers<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/blogs\/single-sign-on-its-relevance\/\">Single sign-on<\/a> sessions<\/li>\n<li>Cloud applications<\/li>\n<li>Business email accounts<\/li>\n<li>Sensitive corporate documents<\/li>\n<\/ul>\n<p>Even when corporate credentials are not disclosed immediately, compromised endpoints may provide attackers with opportunities for lateral movement, privilege escalation, or additional credential harvesting.<\/p>\n<p>Strong identity security therefore extends beyond protecting login credentials. Organizations must also protect endpoints from post-phishing compromise and unauthorized remote access.<\/p>\n<h2>How Hexnode helps reduce post-phishing endpoint and access risk.<\/h2>\n<p>Callback phishing often succeeds by convincing users to install unauthorized remote access software or disclose credentials and MFA codes. Reducing the risk requires both preventive controls and continuous threat detection.<\/p>\n<p>Hexnode UEM helps reduce endpoint exposure by using app blocklist\/<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-allowlist\/\">allowlist<\/a> policies to restrict unwanted or untrusted apps, creating device compliance policies, supporting BYOD containerization, and using device compliance to inform <a href=\"https:\/\/www.hexnode.com\/blogs\/conditional-access-explained\/\">Conditional Access<\/a> decisions through IdP integrations such as Microsoft Entra ID or Okta.<\/p>\n<p>These controls help administrators restrict unwanted or untrusted apps and enforce compliance-based access decisions on managed devices.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Containerization-Smarter-BYOD-Management-for-Enterprises.png?format=webp\" class=\"resource-box__image\" alt=\"Containerization-Smarter-BYOD-Management-for-Enterprises\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Containerization-Smarter-BYOD-Management-for-Enterprises.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Containerization-Smarter-BYOD-Management-for-Enterprises-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Containerization-Smarter-BYOD-Management-for-Enterprises-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Containerization-Smarter-BYOD-Management-for-Enterprises-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Containerization-Smarter-BYOD-Management-for-Enterprises\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Containerization: Smarter BYOD Management for Enterprises\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Discover how containerization secures BYOD by separating work and personal data on devices.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/byod-containerization\/'>\n                            Download the Infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<p>If an attack progresses beyond the initial social engineering stage, Hexnode XDR provides visibility into suspicious endpoint activity. <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> is documented as monitoring real-time endpoint events and identifying anomalies such as unauthorized process execution, brute-force attempts, known malware signatures, anomalous file changes, and unauthorized network beaconing; documented response actions include process neutralization and network isolation.<\/p>\n<h2>Conclusion<\/h2>\n<p>The latest Shop app phishing campaign demonstrates that attackers no longer depend solely on email to deceive victims. By planting fake purchase receipts inside a trusted order-tracking application, they exploit user confidence to facilitate credential theft, OTP theft, and remote device compromise.<\/p>\n<p>Organizations cannot rely on user awareness alone. Combining strong identity security practices with endpoint management, application control, and continuous threat detection provides a more resilient defense against modern callback phishing campaigns.<\/p>\n<p>As attackers increasingly weaponize trusted digital experiences, layered security becomes essential for protecting both users and enterprise resources.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Identity Security After Phishing<\/h5><p>Block risky apps, enforce compliance, and detect endpoint compromise with Hexnode UEM and XDR faster.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How is callback phishing different from traditional phishing?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Instead of directing victims to malicious websites, callback phishing persuades users to initiate contact over the phone. This gives attackers more opportunities to manipulate victims through live conversations.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why should organizations monitor remote access software installations?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Unauthorized remote support tools can provide attackers with persistent access after a successful scam. Monitoring these applications helps security teams detect suspicious activity before it escalates.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals continue to evolve their phishing tactics, and email is no longer their only delivery&#8230;<\/p>\n","protected":false},"author":6,"featured_media":571,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,13],"class_list":["post-563","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-identity-abuse","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Shop App Fake Receipts Drive Callback Phishing Scams<\/title>\n<meta name=\"description\" content=\"Learn how shop app phishing uses fake receipts to steal credentials, OTPs, and device access, and how Hexnode strengthens identity security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Shop App Fake Receipts Drive Callback Phishing Scams\" \/>\n<meta property=\"og:description\" content=\"Learn how shop app phishing uses fake receipts to steal credentials, OTPs, and device access, and how Hexnode strengthens identity security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-01T09:19:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:26:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Fake Shop Receipts Bring Callback Phishing Into Trusted Order Histories\",\"datePublished\":\"2026-07-01T09:19:09+00:00\",\"dateModified\":\"2026-08-18T09:26:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/\"},\"wordCount\":853,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp\",\"articleSection\":[\"Phishing\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/\",\"name\":\"Shop App Fake Receipts Drive Callback Phishing Scams\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp\",\"datePublished\":\"2026-07-01T09:19:09+00:00\",\"dateModified\":\"2026-08-18T09:26:11+00:00\",\"description\":\"Learn how shop app phishing uses fake receipts to steal credentials, OTPs, and device access, and how Hexnode strengthens identity security.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fake Shop Receipts Bring Callback Phishing Into Trusted Order Histories\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Shop App Fake Receipts Drive Callback Phishing Scams","description":"Learn how shop app phishing uses fake receipts to steal credentials, OTPs, and device access, and how Hexnode strengthens identity security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/","og_locale":"en_US","og_type":"article","og_title":"Shop App Fake Receipts Drive Callback Phishing Scams","og_description":"Learn how shop app phishing uses fake receipts to steal credentials, OTPs, and device access, and how Hexnode strengthens identity security.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-01T09:19:09+00:00","article_modified_time":"2026-08-18T09:26:11+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp","type":"image\/webp"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Fake Shop Receipts Bring Callback Phishing Into Trusted Order Histories","datePublished":"2026-07-01T09:19:09+00:00","dateModified":"2026-08-18T09:26:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/"},"wordCount":853,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp","articleSection":["Phishing","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/","url":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/","name":"Shop App Fake Receipts Drive Callback Phishing Scams","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp","datePublished":"2026-07-01T09:19:09+00:00","dateModified":"2026-08-18T09:26:11+00:00","description":"Learn how shop app phishing uses fake receipts to steal credentials, OTPs, and device access, and how Hexnode strengthens identity security.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories.webp?format=webp","width":1340,"height":700,"caption":"Fake-Shop-Receipts-Bring-Callback-Phishing-Into-Trusted-Order-Histories"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/fake-shop-receipts-bring-callback-phishing-into-trusted-order-histories\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Fake Shop Receipts Bring Callback Phishing Into Trusted Order Histories"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=563"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/563\/revisions"}],"predecessor-version":[{"id":572,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/563\/revisions\/572"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/571"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}