Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Threat actors are injecting fraudulent purchase receipts into Shopify’s Shop order-tracking app, a platform with 50 million installs on Google Play, to run callback phishing campaigns that harvest credentials, payment cards, and one-time passwords. The attack operates entirely within a trusted, authenticated mobile application, bypassing email security controls and exploiting the implicit trust users place in the app’s order history. Organizations with BYOD policies or consumer-facing employees face elevated risk, as successful attacks can result in compromised accounts, unauthorized financial transactions, and remote access tool installation on personal devices that may also access corporate resources.

Author

Tech Jacks Solutions