A phishing scam is targeting Shopify store owners through fraudulent emails requesting business verification details. The emails appear legitimate but redirect users to fake login pages designed to steal credentials.
Messages may be sent to secondary business emails rather than the store owner’s registered email
How to verify legitimate Shopify emails:
Check the sender’s email address carefully before clicking
Legitimate Shopify emails display a verification icon next to the sender name
Always inspect the actual URL before entering any information
Avoid emails from generic addresses like “@gmail.com”
Multiple users have reported receiving these scam emails recently. Community members recommend reporting such incidents directly to Shopify using official channels.
Summarized with AI on October 25.
AI used: claude-sonnet-4-5-20250929.
You must check the sender’s email address before clicking on an email. If you have clicked to open a link, please check the address URL before doing anything.
Oop, we just got one of these this weekend. What tipped me off was it was sent to our distro email that we use as our forward-facing email, and not the store owner’s email. I had to shout at the others on the distro email so they wouldn’t click the link until I had a chance to closely review it, haha.
Thank you sharing this since March @shopfy-2020 I was looking through Reddit and apparently somebody encountered something similar recently. A rule of thumb for anyone who might be seeing this for the first time is to always disregard any “official mail” coming from an account with “@gmail.com” or something similar in its address. It’s not from Shopify directly and is most likely a scam.