Is the email regarding 'Shopify Protection Portal' legitimate or a scam?

Is the email regarding 'Shopify Protection Portal' legitimate or a scam?

fcbeautyco
Tourist
10 0 2

I got an email from ahram.kim@nychhc.org    and it gave me a link to log in to my "Shopify Protection Portal"

Following subsequent monitoring by Shopify Security Organization (SSO) we have scheduled a proper security measure to be taken beyond password and 2Factor authentication to prevent Ecommerce fraud on your store as an administrator. You are receiving a copy of this message in fulfillment of “Shopify client protection policy”.

Note: Shopify will take not responsibility for any compromise of account not under this Client protection plan.

Visit www.nychealthandhospitals.org

Reply 1 (1)

Moira
Shopify Staff (Retired)
2118 231 341

Hey, @fcbeautyco!

This is Moira from the Social Care team at Shopify. Thank you for bringing this to our attention. This is in fact a phishing email, and not a legitimate email from Shopify, please ensure to not click on any links or download any attached files. We are working to mitigate these types of emails.

In case you have already clicked on any links within the email, please follow the steps below:

  • We recommend securing your devices by running anti-malware software.
    It is also advised that you ensure your wifi is secured according to the instructions provided by your ISP.

  • Update your password for your Shopify account - ensure you are using a strong unique password. We have a handy resource I’d recommend looking over here

  • Update the password for your email account login and enable any additional security features that your email service provider offers.

  • Another merchant has asked a similar question in the past. To view additional steps that are to be taken if your account has been compromised, check out our response here.

If you did not click on any links, just to be extra safe it's important that you follow these steps to secure your account and then go through your Shopify Admin to ensure all of your account details are still valid and unchanged.

  • To help secure your Shopify admin, make sure that the store owner and the staff have verified email addresses.

  • To be proactive against potential phishing attacks in the future, we highly recommend you also enable 2-factor authentication and visit this guide to be better informed.

  • For further information on Account security protocol please take a look at this guide

If you continue to receive these emails may I kindly ask you to forward them to our Safety team by emailing safety@shopify.com. If possible, can you follow these steps to send the complete email including headers? Click here for instructions.

Please don't hesitate to let us know if you have any security concerns about your account with Shopify.

Cheers!

Moira | Social Care @ Shopify
- Was my reply helpful? Click Like to let me know!
- Was your question answered? Mark it as an Accepted Solution
- To learn more visit the Shopify Help Center or the Shopify Blog