Table of Contents
The email cleared SPF. It cleared DKIM. It cleared DMARC. Composite authentication returned pass. Every signal a defender is trained to trust came back green, and every one of them was telling the truth. The message really was sent through Shopify's own mailer platform, from a real Shopify merchant account, over infrastructure that authenticates millions of legitimate storefronts every day. The authentication was never the weak point. The weak point was that the store was fraudulent, and the brand it claimed to be had nothing to do with it.
The target was one mailbox at a marine-engines manufacturer. The pretext was a Norton subscription charge dispute for $349.99. And the only thing the recipient was asked to do was pick up the phone.
When the Authentication Is Real and the Sender Is Not
Email authentication answers a narrow question. SPF confirms the sending server is authorized to send for the domain. DKIM confirms the message was signed by that domain and not altered in transit. DMARC confirms those results align with the visible From address. None of these mechanisms asks whether the sender is honest. They only ask whether the sender is who the envelope says it is.
In this case the envelope was completely accurate. The message was sent by store+98939404608@g[.]shopifyemail[.]com, signed with a valid DKIM signature under d=mailer3.g[.]shopifyemail[.]com, with SPF pass, DMARC pass under an action=none policy, and compauth=pass. Shopify genuinely sent this email on behalf of a genuine merchant account. The account just happened to be an auto-generated throwaway storefront named VersionVault, spun up to blast a Norton-branded lure through a reputable service provider's pipes.
The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches, and phishing remains a leading initial-access path precisely because attacks like this one never trip the technical controls we lean on. When authentication passes, most secure email gateways relax. That relaxation is the entire attack.
See Your Risk: Calculate how many threats your SEG is missing
A Storefront Built to Send One Email
Shopify assigns every new store a myshopify.com subdomain automatically. That convenience is what the attacker weaponized. The storefront store-6-bjxtociu[.]myshopify[.]com was never a real business. It existed to satisfy the one requirement Shopify's mailer enforces: a valid merchant account behind the send. Once that account was live, every transactional or marketing email it generated shipped with airtight authentication.
This is the pattern the Microsoft Digital Defense Report 2024 describes as the industrialization of abuse against trusted cloud services. Rather than register a look-alike domain and fight for reputation, the attacker rents legitimacy from a platform that has already earned it. There is no attacker-owned sending domain to block, no newly registered domain age to flag, and no reputation deficit to detect. The myshopify[.]com subdomain and the g[.]shopifyemail[.]com sender are both on infrastructure that defenders explicitly allow.
The brand story is where the seams show. A Shopify storefront called VersionVault sending a Norton antivirus billing notice makes no sense. Norton does not bill through Shopify merchant mailers. The mismatch between the sending infrastructure, the display name, and the impersonated brand is the first honest tell in an otherwise flawless delivery.
The Whole Point Was a Phone Number
There was no malicious link in this email. There was no attachment. A URL scanner had nothing to scan, and an attachment sandbox had nothing to detonate. The message claimed the recipient's Norton subscription had auto-renewed for $349.99 and that a dispute or cancellation required calling a support line at +1 (803) 470-8962.
This is a telephone-oriented attack delivery, or TOAD, a form of vishing that moves the entire exploit off the wire and onto a phone call. The fabricated charge does the psychological work: it is large enough to alarm, plausible enough to seem real, and framed as something the victim can reverse if they act now. Once the target calls, a live operator takes over. That is where remote-access tools get installed, where card numbers get read aloud, and where a fake refund gets turned into a real wire.
CISA's guidance on stopping the phishing attack cycle emphasizes that the payload is not always a link. When the call to action is a phone number, the defensive surface shifts entirely to content analysis and behavioral signals, because the usual indicators of compromise simply are not present in the message.
Reply-To Is Where the Mask Slips
Under the Shopify sender sat one field that did not belong. The Reply-To address quietly diverted to preparmy[.]com, a privacy-protected domain unrelated to Shopify, to Norton, or to the VersionVault storefront. If the recipient replied instead of calling, that response would land on attacker-controlled infrastructure while the original delivery kept its clean provenance.
A legitimate Norton notice keeps replies inside Norton. A legitimate Shopify transactional email keeps replies inside the merchant. A privacy-shielded third domain in the Reply-To is a deception marker that no amount of valid DKIM can launder away.
MITRE ATT&CK Alignment
| Technique | ID | Application |
|---|---|---|
| Phishing | T1566 | Norton charge-dispute lure delivered through an abused, fully authenticated Shopify mailer account |
| Phishing for Information | T1598 | Callback pretext (TOAD) drives the target to a phone number for live social engineering |
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Envelope / From | store+98939404608@g[.]shopifyemail[.]com | Legitimate Shopify mailer sender for an abused merchant account |
| DKIM signing domain | mailer3.g[.]shopifyemail[.]com | Valid DKIM signature, authentication genuinely passes |
| Fraudulent storefront | store-6-bjxtociu[.]myshopify[.]com | Auto-generated throwaway store ("VersionVault") |
| Reply-To domain | preparmy[.]com | Privacy-protected, unrelated to sender or impersonated brand |
| Callback number | +1 (803) 470-8962 | Telephone-oriented attack, sole call to action |
| Impersonated brand | Norton | Fake $349.99 subscription charge-dispute notice |
| SPF / DKIM / DMARC | Pass / Pass / Pass (action=none) | End-to-end authenticated, not a spoof |
| compauth | Pass | Composite authentication clean |
Detecting an Attack That Fails No Authentication Check
Authentication tells you the mail was not forged. It cannot tell you the sender is trustworthy. Catching this message requires reading the relationship between its parts rather than validating each part in isolation. A Shopify mailer sending a Norton billing notice, a storefront display name that matches neither the brand nor any prior sender, a Reply-To on an unrelated privacy-shielded domain, and a payload that is a phone number instead of a link are individually subtle and collectively damning.
That correlation is what behavioral analysis is built for. IRONSCALES Adaptive AI models each recipient's normal senders and flags the brand-to-infrastructure mismatch and the anomalous Reply-To, while the callback pretext and fabricated charge amount are scored as social-engineering signals rather than trusted because the envelope authenticated. The single affected mailbox was contained before the recipient dialed the number.
The Takeaway
The uncomfortable lesson here is that a passing authentication result is a statement of provenance, not a verdict of safety. As attackers keep renting reputation from Shopify, and from every other platform that lets anyone provision a sending identity in minutes, the green checkmarks will keep coming back clean. Defense has to move up the stack, to intent and relationship and behavior, because the wire-level signals have been conceded.
Callback lures like this one are among the hardest to catch for exactly this reason: no link, no attachment, no spoof, no reputation deficit. The teams that stop them are the ones reading brand-to-sender coherence and anomalous reply paths, not just the auth headers. That is the same analytic muscle that underpins business email compromise protection, where the fraud also hides behind messages that pass every technical test. When the authentication is honest and the sender is not, the content is the only place left to look.
Related attacks
| Attack | What happened |
|---|---|
| A Fake Bitdefender Charge Showed Up on the Calendar, Not the Inbox | Attackers weaponized a Google Calendar .ics invite to deliver a fake Bitdefender subscription charge. |
| The PayPal Email That Wanted a Phone Call, Not a Click | A PayPal email landed spotless through Mimecast. |
| A Fake Scotiabank Voicemail Was Actually an HTML File Asking You to Call an Attacker | A Scotiabank-branded Interac e-Transfer alert carried an attachment disguised as a voicemail MP3. |
| Pandora Renewal Scam: No Links, Just a Callback | A fake Pandora Premium renewal notice carried no links and no attachments. |
| McAfee Invoice Scam Weaponized a Google Calendar Invite 71 Minutes After Domain Registration | A same-day registered domain abused Google Calendar invites to deliver a McAfee/Webroot invoice scam with a callback phone number. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.