A Shopify customer opens the Shop app to check on a package. Sitting in their order history is a receipt for something they never purchased. A $499 charge, maybe a “renewal” for software they don’t remember buying. There’s a number to call if it’s a mistake. So they call it. And that phone call is the entire attack.
No malicious link. No attachment. No payload your email gateway can quarantine. This is callback phishing, and the most interesting cybersecurity story this week isn’t a new exploit or a critical CVE. It’s that attackers have figured out how to deliver their lure through a legitimate app’s order history, where none of your perimeter tooling is watching. BleepingComputer reported this week that threat actors are stuffing fake purchase receipts into Shop, Shopify’s order-tracking app, to push users toward calling attacker-controlled phone numbers.

The payload is a phone number, and that breaks your stack
Think about what your defenses are tuned to catch. Your firewall inspects traffic. Your email security detonates attachments and rewrites URLs. Your EDR watches for processes doing suspicious things on disk. Every layer of that defense in depth is built around the assumption that the attack arrives as data crossing a wire and executing somewhere you control.
Callback phishing, sometimes called telephone-oriented attack delivery, sidesteps all of it. The receipt looks real because it’s displayed inside a real app on real infrastructure. The “threat” is a ten-digit number the victim dials voluntarily. On the other end is a human running a script: confirm your “refund,” install this “remote support tool” so we can process it, read us the code on your screen. That remote tool is often a legitimate, signed RMM product. By the time anything lands on the endpoint, the user has already invited it in and your threat detection has nothing anomalous to flag.
The genius, and it’s worth calling it that, is that the abuse happens on a platform the victim already trusts. Shopify’s order history feels authoritative. People don’t scrutinize their own purchase records the way they scrutinize a cold email. Attackers borrowed the platform’s credibility for free.
Same playbook, different lure: the parcel mules
Run that pattern alongside another scam Malwarebytes flagged this week and the shape becomes obvious. “Parcel Expert” job listings promise easy money for receiving packages at home, inspecting them, and reshipping them abroad. The packages are bought with stolen cards. The “employee” is a reshipping mule who never gets paid, and who has now put their name, address, and ID on a fraud pipeline.
Different surface, identical logic. There’s no software vulnerability to patch in either case. The exploited system is a person operating inside a legitimate-looking process, a job application, an order receipt, who has no reason to suspect the frame around the interaction is fake. You can’t brute-force your way past a help desk’s MFA when the victim is reading you the code over the phone, and you can’t write a firewall rule for a fraudulent job offer on a recruiting site.
This is the part security teams keep underweighting. A huge slice of real-world loss now comes from attacks that contain zero technical indicators of compromise. There’s nothing for a signature to match. The only artifact is a human decision made under a plausible pretext.
What actually works against attacks with no IOCs
You can’t block a phone number you’ve never seen or a job ad on a third-party site. You can shrink the blast radius and shorten the time to detection. Here’s where to start.
Immediately:
- Tell employees, in plain language, that no legitimate refund or “renewal cancellation” ever requires them to install remote-access software. Make that a hard rule. Anyone who hears it on a call should hang up and report it.
- Lock down who can install RMM and remote-support tools. Application allowlisting that permits only the RMM your IT team actually uses turns “the caller told me to install AnyDesk” into a non-event. This is basic security hardening with outsized payoff.
- Give people a frictionless way to verify a charge or a recruiter. A two-line internal note, “saw a weird receipt? forward it here before you call anyone,” catches these before the phone gets dialed.
On an ongoing basis:
- Treat RMM execution as a high-signal event. If your threat-protection tooling can alert when an unsanctioned remote-support agent launches, you’ve recovered the detection point that callback phishing tries to erase. Watch for the legitimate-tool-doing-illegitimate-things pattern rather than known-bad hashes.
- Run incident response tabletops for the no-malware scenario. Walk through a finance employee who granted a remote session and read out an MFA code. Your playbook should not depend on EDR firing an alert, because in this scenario it won’t.
- Fold social-engineering pretexts into awareness training that uses current lures. Fake receipts and reshipping jobs beat the generic “don’t click suspicious links” slide because they match what people are actually seeing.

Stop grading attacks by their delivery mechanism
The uncomfortable lesson threading these two stories is that the trust boundary moved and most defensive budgets didn’t follow. We spent years hardening the channels we own: email, the network edge, the endpoint. Attackers responded by delivering through channels we don’t own at all, a Shopify order history, a recruiting platform, an inbound phone call, with the human as the execution environment.
Good cyber security in 2026 means assuming the lure will arrive somewhere your sensors can’t see, and designing for the moment after the human falls for it. Constrain what a deceived employee can actually do, make remote-access tooling loud when it runs, and rehearse the response for a breach that left no malware behind. The receipt is fake. The risk is not.
Frequently Asked Questions
- What is callback phishing?
- It’s a scam that lures a victim into calling an attacker-controlled phone number, often using a fake invoice or receipt, instead of clicking a link. The attacker then talks the victim into installing remote-access software or handing over credentials, leaving little for traditional email and network filters to catch.
- How do we detect an attack that has no malicious file or URL?
- Shift detection to behavior and identity. Alert on unsanctioned remote-support tools launching, on remote sessions started right before sensitive actions, and on unusual access patterns, since these attacks produce no signature-matchable indicators.
- Why are attackers abusing legitimate apps like Shop?
- Because the platform’s credibility does the work for them. A fake receipt inside a real order history looks authoritative, so victims trust it far more than an unsolicited email and act on it without scrutiny.
Sources
- Order-tracking app Shop abused to push callback phishing attacks
- Beware of “Parcel Expert” job offers: They’re parcel mule scams
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
