Request for Clarification Regarding Compliance Patch Procedure

Topic summary

A store owner received a compliance communication about a mandatory security patch for their Shopify store (modna.sk), but the implementation process raised several red flags:

Key concerns:

  • An assigned “expert” initially offered the patch as a paid service ($60) without mentioning free alternatives or providing official documentation
  • The contact requested an alternative Gmail address unlinked to Shopify/Upwork accounts for contract purposes
  • The freelancer was not identity-verified on Upwork when making these requests
  • After pushback, the expert said the existing Upwork account could be used instead, making the Gmail request more suspicious

Questions seeking clarification:

  • Whether the patch is truly mandatory for compliance
  • If official, secure implementation methods exist through verified Shopify channels
  • Whether these developer interactions are formally monitored by Shopify

A community member responded suggesting this appears to be a scam similar to previous attempts, requesting the sender’s email address for verification and questioning the Upwork connection.

Status: Unresolved; awaiting official clarification and investigating potential fraudulent contact.

Summarized with AI on October 28. AI used: claude-sonnet-4-5-20250929.

Dear Shopify Audit Team,

I’m writing in response to the recent compliance communication regarding my store (modna.sk), specifically the mandatory implementation of a security patch.

While I fully respect Shopify’s efforts to maintain high platform standards, I would like to raise some concerns about how this process has been handled:

  1. I was contacted by an assigned “expert” who initially presented the patch as a paid solution ($60) with no mention of an officially supported free alternative. Only after multiple follow-ups did they confirm that I could implement the changes myself, although no clear technical documentation was provided.

  2. I was asked to create or provide an alternative Gmail address not linked to my Shopify or Upwork accounts, allegedly for the purpose of receiving a contract. This request came from a freelancer who was not identity-verified on Upwork at the time, and the message raised additional questions about security and transparency.

  3. After expressing concern, I was told I could instead proceed using my existing Upwork account — which makes the original Gmail request even more questionable.

I want to comply fully with Shopify’s standards and maintain the integrity of my store. However, I believe these redirections outside verified systems (Shopify Experts, official support, or Upwork-protected workflows) warrant your attention.

I would greatly appreciate clarification on the following:

  • Is the patch indeed mandatory for continued compliance and visibility?

  • Is there an officially documented, secure method for applying it — preferably through a verified Shopify channel?

  • Are these developer interactions formally monitored or sanctioned by Shopify?

Thank you for your time and for helping to ensure a safe and fair process for small businesses like mine.

Best regards,
Inna Pozharska
Owner, modna.sk

HI @Inna_MODNA

Welcome to the community.

First, I must ask what is an email of the sender. The first email you got from an “expert” that asks for $60 for a “patch”?

That sounds to me like a scam, as there were a lot of similar attempts before, maybe a new variant.

Also, I did not understand what Upwork has to do with everything.