3 email addresses in conjunction with Shopify, one of which unique to Shopify, ie not shared with anyone else, has received spam style emails asking for small amounts of money for Ringgo. This is a parking app. The Update Payment details uses the domain halaalstyle.com which just shouts SCAM.

It is notable that this email has not been sent to any other of our email address.

In my opinion, the only rational explanation is that Shopify has been compromised and it would be useful to know the depth of this hack.

Can anyone enlighten us?

@Mikexx One address getting phished doesn’t by itself point to Shopify’s core platform being breached - the much more common cause is a third-party app or integration on the store (or on a supplier/marketing tool) that had read access to that address and got compromised or scraped, or the address leaked from somewhere else entirely (a data broker, a WHOIS record if it’s a domain contact, etc). Shopify’s own systems aren’t the only place an address tied to your store could have been exposed.

Two things worth doing: 1) In Settings > Apps and sales channels, check for anything you don’t recognize or haven’t used recently and revoke it - a rogue app with customer/read scope is the classic way one specific address ends up on a spam list while others don’t. 2) Run the address through haveibeenpwned.com to see if it shows up in an unrelated breach, since that would explain the isolation without involving Shopify at all.

The “Ringgo unpaid parking charge” template with a fake payment-update domain is a very widely reused phishing kit right now, hitting all kinds of businesses, not just Shopify merchants - so on its own it isn’t evidence of a targeted hack. If you want it formally looked at, report it to Shopify support so they can check whether other merchants have flagged the same pattern.

If this answer helped, mark it as a solution.

My policy regarding emails is simple. When I create an account with say Lloyds bank, I will use the address: lloydsbank.com@mydomain.xx

It will be a unique address and not provided to any third party. This is the principle associated with our Shopify account. It immediately tells me the source of a leak.

I used your http://haveibeenpwned.com/ link and can confirm “Good news — no pwnage found! This email address wasn’t found in any of the data breaches loaded into Have I Been Pwned. That’s great news!”

You are on a public domain. Any public space that surfaces your email address, including any form or embedded link, or through other channels like WHOIS, is susceptible to spam. Shopify is not compromised. Just stop. You have been here for 2 years. You should know all this.

And just because you’ve received an email, doesn’t mean whoever sent it knows that is an official email. A simple bot can send out a thousand emails to a thousand different local parts on the same domain. info, help, support, doesn’t matter. If I know your domain, I can spam 50k emails to different local parts. Do you honestly think you are the only one who gets spam?

It’s not Shopify, it’s just a fact of being a public business. Don’t try to investigate. Don’t try to make a mountain out of a pebble. We all get it. Just mark as spam and delete. No problem.

Hi there @Mikexx
I don’t think it’s safe to assume Shopify itself was hacked just because the message was sent to a Shopify email address. Unique addresses may also be leaked through third party services, forwarding, compromised accounts, or data breaches.

The payment domain does not match, which is a very strong signal, so I wouldn’t click the link or enter any information. Look at the email headers and authentication results, and then report the message as phishing. Also check your shopify account history and the permisions on any third party apps for anything you dont recognize.

We had a similar situation with an email address that was only used for one service, and I wouldn’t immediately assume the service itself was breached. I’d check the full headers first, especially the actual sending domain and SPF/DKIM results. If the message is coming from somewhere completely unrelated, it could be an app or third-party integration that had access to the address rather than Shopify itself. The halaalstyle.)com payment link would definitely make me treat it as phishing, though.

@Mikexx I’d add one important step before assuming the email came from a Shopify-related source: check whether that exact email address is exposed anywhere publicly on the store.

Search the storefront for the address, including the page source and any contact/about/footer sections. Also check old apps and integrations that may have had access to store/contact information.

And if the email is supposedly from Shopify, don’t judge it by the display name alone. Check the actual sender domain, Reply-To address, and SPF/DKIM results in the full headers.

Most importantly, don’t use the payment link in the email. If you need to verify an account or payment issue, open Shopify directly rather than following the email.

I wouldn’t call this evidence of a Shopify breach without the headers and more evidence. A compromised third-party app, exposed email address, or simple scraping campaign are all plausible explanations.

Are saying that Shopify routinely share email addresses because I am on a public domain?

Aren’t all domains public? gmail.com outlook.com are two that come to mind. Can you please define ‘public domain’ and it’s relevance to an email address?

Why would someone sending me spam know “that is an official email”? Are we talking domain or the unique unofficial email we only use with Shopify?

From saying, "If I know your domain, I can spam 50k emails to different local parts. Do you honestly think you are the only one who gets spam? " What are the ‘local parts’ you mention? Only if Shopify is hacked would I expect you to use an unique email address only provided to Shopify. Do you understand how you get from a domain to an email address?

Nope. Shopify doesn’t need to. There are numerous ways to get spam.

So how a sample would work:

  1. You sign up with Shopify with the email address abc123@whatever.com
  2. You set up your store and theme. The theme has contact links throughout. In the footer. In the contact form. Shopify also puts contact email in the policies if you choose the templates.
  3. You want to have generalstore.com as your website domain so you sign up for a third party domain and connect it to Shopify. You want a professional email so you get that as well.
  4. This registration can also hold publicly accessible data including email address of the registrant.
  5. In Shopify, you want your email to be the one you just made so you go through Settings to verify the address. All your contact info on the website is now the new address.
  6. A bot scrapes public databases and sends out emails.

This is just one way. A quick and verifiable way to see that it is not “Shopify being hacked”. You of course may have a completely different setup. But it really doesn’t matter. A few spam emails aren’t going to kill you. It’s not the end of the world. We all get spam and we all deal with it.