Store owners are receiving spam messages through their Shopify contact forms with vague content like “I want to share something important about [store name]” followed by suspicious email addresses (ending in @shopify-experts.org) and phone numbers.
Official Response:
Shopify staff confirmed these are spam/phishing attempts that should be deleted and ignored
The @shopify-experts.org domain is not legitimate
Users should forward suspicious emails to safety@shopify.com so Shopify can track these attempts
Pattern Identified:
Multiple users report receiving identical or nearly identical messages
Messages include various phone numbers (UK and US numbers that appear fake)
Some variants use Gmail addresses
The spam campaign has been ongoing since at least 2021 and continues into 2024
Recommended Solutions:
Install spam prevention apps like Zero Spam Contact Form or Shop Protector
I just received a customer message from my store’s contact form saying: “I want to share something important about [my store name], are you the correct person for this?”.
It’s quite vague and the email it is from ends in [her name]@shopify-experts.org
What’s the correct way about going about this message?
Welcome to the Shopify Community! Glad you reached out about this message you’ve received. I’ve spoken with our team and can confirm that this message is a spam attempt and should be ignored. We do not distribute any email addresses that end in @shopify-experts.org.
As mentioned, the best course of action is to delete, and ignore this message. Thank you for taking the time to report it to us. In the future, if you ever receive any suspicious emails or messages, don’t hesitate to reach out. If you’re confident an email is spam or a phishing attempt, please forward it to safety@shopify.com so we can track these attempts. We also have a help document on phishing and protecting your account if you’d like to learn more.
Thanks for joining the thread @lode and @Kateymacey1 . Glad to hear that this topic was helpful for you in determining that this message you received is spam, appreciate the updates!
I’ve updated this topic and marked my answer as the solution for the benefit of others moving forward as well.
I got the same one thought it was strange as well because just a few days had someone add hundreds into their cart but didn’t complete the purchases. Looks like they were trying to do something sketchy but not sure what their goal was. I deleted the customer from my list and archieved the abandoned carts sure wish we could completely delete people like this. Anyways hate that this happens with all the hard work I put into the store, then someone trying to rip me off all the time.
I understand that receiving suspicious messages like this can be a discouraging experience, especially when it takes away from the valuable time you’re putting in to build and grow your business.
I want to assure you that there is no security threat to your store as a result of these emails. If you continue to receive messages like this, please feel free to send them to safety@shopify.com so our team can keep track of them.
Something else to consider is using an app like Zero Spam Contact Form or Shop Protector, as these can help prevent spam messages from coming through your store’s contact form.
I received the exact message same message word for word this morning. Analytics says my contact page received a hit from Bangladesh at the time it was sent.
Please refer to the accepted solution above in this thread and feel free to disregard any spam messages that come through your contact form. Any suspicious emails can also be forwarded to safety@shopify.com along with the headers so that our team can investigate and work to reduce emails like this going forward.
They are still at it. I just got one today and thought it was strange they only said, “need to speak with someone”. Thank God for this platform because it didn’t sit right and because I saw your post, I know it isn’t.