I was mailed by apps.shopifyteam@gmail.com

Hi, @acingpancing ,

This definitely looks to be what is considered a ‘phishing’ email and should not be replied to. Can I confirm that you have not clicked any links within the email and entered any of your account information?

There are a couple of things you can do here. First, you can report the email as phishing, as shown below.

Then if there is a link inside of a phishing email you receive, please, submit it to Google Safe Browsing. You can complete the submission on this link here. While doing this, ensure you do not open the link. Instead, Right-click on the hyperlink/link, click on the copy link and paste it to Google Safe Browsing. Shopify’s Security Teams work with Google to ensure that illegitimate sites are reported and flagged with warning tags.

To help investigate this matter further, I will ask you to collect the Headers from the email you received. The headers are part of the email code that includes essential information that they can use to try to stop the campaign at its source. Then, please make a report to our investigation team by following the steps below.

  1. Obtain the Headers File

Please see MX Toolbox’s’ guide for Getting Email Headers by selecting your email service provider on the left-hand navigation and following the steps to download the EML file.

  1. Attach the file to the email you received and forward it to safety@shopify.com.

This will allow us to view the email exactly as it was sent to you and collect all the necessary information they need.

If for any reason, you cannot download the EML file, you can use the MXToolbox guide to view and copy the headers into a text file and attach it in place of the EML file.

Security Tip: Two-Step Authentication helps prevent unauthorized users from accessing your account (even if they acquired your password). We strongly recommend this feature for all users.

We truly appreciate your assistance here.