Received the following email today about verifying business information:
“Learn more about…” link at the bottom isn’t a link, just different text color. Image just below that was a broken image icon. Sender address:

And the button link goes to:
![]()
I received a similar email today, but from a different sender “Payments Team” with a Shopify merchant’s store+ email address. I asked ChatGPT to look into it, and from what I can gather, it appears that a legitimate store may have been compromised/hacked. Send an email with the details and screenshot(s) to phishing@shopify.com to report it.
Reads like phishing, but there’s a simpler check that works no matter how convincing one of these looks. Just ignore the email entirely and go straight into your admin.
If Shopify genuinely needs something from you it shows up there as a banner or a task. Nothing legitimate ever depends on you clicking a button in your inbox.
Worth knowing these spike in the weeks before Black Friday, because that’s when the threat of a held payout is most likely to make somebody click without thinking it through.
If two-step authentication isn’t turned on for your Shopify account and for the email address tied to it, that’s the thing that actually protects you, since what these are after is account takeover rather than the click itself.