Shopify transaction data stolen by rogue support staff

By Chris Dawson September 24, 2020 - 10:49 am

Shopify are the latest big ecommerce name to have a security breach. Following eBay (rogue security staff) and Amazon (bribing employees), Shopify have discovered that two rogue members of their support team were engaged in a scheme to obtain Shopify transaction data of certain merchants.

Less than 200 merchants were effected and Shopify immediately launched an investigation to identify the issue and impact so they could take action and notify the affected merchants. Naturally they terminated these rogue support team members’ access to the Shopify network and referred the incident to law enforcement.

“We are currently working with the FBI and other international agencies in their investigation of these criminal acts. While we do not have evidence of the data being utilized, we are in the early stages of the investigation and will be updating affected merchants as relevant.”
– Shopify

With over a million merchants using their platform, this is in reality a tiny security breach, although nonetheless concerning for those who’s Shopify transaction data was compromised. This incident was not the result of a technical vulnerability on Shopify and the vast majority of merchants using Shopify are not affected. If you’ve not heard anything from Shopify then it’s likely you are one of the almost 1 million merchants who were unaffected

The stolen Shopify transaction data includes basic contact information, such as email, name, and address, as well as order details, like products and services purchased. Complete payment card numbers or other sensitive personal or financial information were not part of this incident. It looks very much like targeted data to inform give a competitive advantage to the recipients of the data.

“Our teams have been in close communication with affected merchants to help them navigate this issue and address any of their concerns. We don’t take these events lightly at Shopify. We have zero tolerance for platform abuse and will take action to preserve the confidence of our community and the integrity of our product.

To put it simply, we are committed to protecting our platform, our merchants, and their customers. We will continue to work hard to earn your trust every day.”
– Shopify

Comments are closed.

Featured in this article from the Tamebay Guide – companies that can help you grow and manage your business.


One platform with all the ecommerce and point of sale features you need to start, run, and grow your business.

See More Companies >

Recent Comments

13 mins ago
Rt: Would not be a shock if RM are being Restructured and trimmed up for a...
13 hours ago
Jonty: @Rob Royal Mail to fine customers if the over declare weight. Just about says it all...
17 hours ago
Rob: I spoke to RM last week about this because like others I always add a...
20 hours ago
Daz: Royal Mail.... this is starting to become very tedious, has anyone looked at the dedicated...