Possible Scam Email?

A few days ago I got an email from a wellsonatshopify@gmail.com stating that I “due to significant non-compliance issues affecting your Protocol Card Industry Data Security Standard (PCI DSS) and Trivial File Protocol (TFTP) configurations” my store would be terminated and suspended. I haven’t given anyone any information yet, but have followed some of the steps bringing me to “Shopify Support” live chat through the telegram app as well as then an agency instagram account to get it all fixed and looked at for a price. I was even given a link showing that the company of the instagram account is a partner, but nothing verify it’s really from Shopify. Is this a scam and will my store really be terminated as well as any future stores I make if I don’t get this fixed?

This is what the email specifically read:

Dear Subscriber,

This email is prompted by a thorough analysis of your store, which has resulted in your store being placed on probation and transaction limitations due to significant non-compliance issues affecting your Protocol Card Industry Data Security Standard (PCI DSS) and Trivial File Protocol (TFTP) configurations. These issues have compromised our ability to retain your personal data information and track transactions.

Although we believe this non-compliance may be unintentional, it’s crucial to address it promptly to ensure your store’s security and compliance with our platform’s standards. Kindly be informed that willful ignorance may result in further action, including store suspension or termination, within 48 hours.

To address these issues, please contact our verified and duly vetted Partner through our official support channel. Provide your Ticket ID: _____________ , and they will guide you through the necessary steps to secure your store and replace any compromised software.

Our support team is available to assist you with any questions or concerns you may have. Please take immediate action to avoid further complications.

Thank you for your prompt attention to this matter.

Signed

Chief Solutions Engineer
Shopify

1 Like

Hi @Okannaday

Thank you for sharing a copy of this email and the email address it was sent from. I can say that any email sent from a gmail/yahoo/hotmail/outlook/msn (etc) email address will never be a legitimate support email from Shopify. Please ensure you are not following any links in the email you received. If you have any concerns about the security of your account please reach out to our authenticated support in our Help Center.

If you still have this email, can you please forward it to safety@shopify.com so that our team can investigate this further. We also offer some great information on recognizing phishing and scam emails in our Help Center: Phishing, Vishing, Smishing.

If you have any other questions or concerns about this matter, please let us know!

3 Likes

The same email was sent to be but it was sent by Shopify compliance team and it is pretty much exactly like this but it was because of an API issue. So I don’t know if I should be worried because they sent screenshots of me reaching my API limit. should I be worried Shopify .Also they want me to pay them.

This is the email

I think I’m good because they sent it in a Gmail.

I have replied to these guys to retrain from email or telegram and go thru the shopify app but I’ve yet to get anything in it. The email address is what got me questioning the validity of the email. I’m sick of getting these tho I block em and they keep coming…

Just got this same email. Almost believed it at first because they sent it to me twice and said it was urgent lol luckily I noticed a spelling error and it immediately hit me that this was a scammer trying to get the login details to my store.

I just got one today , is it real ? From shopifybusinessadvisory@gmail.com

Dear Merchant,

We have detected significant compliance concerns on your Shopify store that may affect critical operations, including payment processing and search visibility. It is essential to address these matters within 24 hours to prevent potential disruptions, such as store suspension, legal ramifications, or the permanent loss of associated resources.

To ensure prompt resolution, kindly confirm your preferred communication method (Telegram or WhatsApp) so that our certified compliance experts can provide you with the necessary assistance. Please note, failure to act within the given timeframe may result in outcomes that cannot be reversed, and additional support will not be available after this period.

We urge you to take immediate steps to protect your business and ensure continued operations.

Sincerely,

Shopify Legal & Compliance Team