Back to all lessons
Awareness Lessons
2 months ago

Scammers Hijack Shopify's Notification System for Fake Refund Phishing

Attackers are exploiting legitimate Shopify infrastructure by creating or compromising seller accounts to send fraudulent refund and order notifications directly through the platform's own Shop app. Because the messages originate from a trusted, official system, traditional phishing indicators — such as suspicious sender domains or spoofed email headers — are absent, making the scam far more convincing to end users. This tactic represents a dangerous evolution of 'fake refund' fraud, weaponizing trusted business platforms against their own customers. The root issue is a combination of weak controls over merchant account creation and insufficient end-user awareness that even legitimate-looking platform notifications can be malicious.

Tactical Insight

Immediate actions

  • Treat unsolicited refund or order notifications with skepticism and verify them by logging directly into your account via the official website or app — never via a link in the notification.
  • Enable multi-factor authentication (MFA) on all Shopify seller accounts to reduce the risk of account compromise being used as a launchpad.

Platform & Access Controls

  • Shopify and similar platforms should implement behavioral anomaly detection on seller accounts to flag unusual bulk messaging or notification patterns.
  • Apply stricter merchant account vetting and ongoing monitoring to detect fraudulent or newly compromised seller accounts before they can abuse notification systems.
  • Limit the rate and volume of push notifications that a single seller account can send within a given time window.

Detection & User Awareness

  • Train users and employees to recognise that legitimate platforms will never ask for payment details, gift card codes, or personal information via a push notification.
  • Organizations should include platform-native notification abuse scenarios in regular phishing awareness training programs.
  • Monitor threat intelligence feeds for emerging abuse of legitimate SaaS notification channels and update security awareness content accordingly.