Posting to warn other merchants, because this scam is unusually convincing and a few details made it very hard to read.
My store was deactivated after a payment was reversed (chargeback). Soon after, I started getting messages about an “outstanding balance” I had to pay to “reactivate.”
What to watch for:
A fake “invoice” email that looked like Shopify and even passed email authentication (SPF/DKIM/DMARC), but the sender was a store-notification address and the payment link pointed to an external something.myshopify.com store checkout — not the Shopify admin. Shopify does not collect reactivation/subscription balances through an external .myshopify.com link.
Requests to “verify identity” by emailing a colour photo of my government ID plus a photo of my credit card / bank statement / PayPal — via a link. Shopify’s policy says they never ask for this by email and that documents are uploaded only on a secure .shopify.com page.
Support replies (via the official Help Center) that pushed me toward the scam: more than one advisor told me the external payment link was a “special internal process,” redirected me to the email thread to pay and send documents, and told me the case could not be escalated to Trust & Safety. One advisor first said the invoice was NOT from Shopify, then reversed.
The part I can’t explain and want flagged: the requested amount matches, to the cent, the exact sum that was charged and then reversed — a figure only someone with access to the billing/chargeback details would know. And the scam emails were timed right around my support contacts. To me this suggests the information is coming from someone who already had access to the account or the case (for example a previous owner who kept access), rather than a random phishing attempt — but I’d like Shopify to investigate how the case data could be visible to whoever is doing this.
What kept me safe: I refused to pay through any external link and refused to send any ID or card photos. My two rules, no matter who said otherwise:
A genuine balance is paid only inside your own admin (Settings → Billing), with your own card.
Shopify never asks for photos of your ID or credit card by email.
Has anyone seen this exact pattern (fake “balance owing” from a .myshopify.com store + reactivation requiring an external payment link and ID/card photos)?
For a deactivated store whose billing page won’t load, what’s the official in-admin way to see and pay the real balance?
How can a case be reviewed by Trust & Safety directly, outside the standard chat queue, when I suspect the account or case data has been accessed by a third party?
Good on you for sharing! I’ll pass it onto my clients to be aware.
Do you think, because the amount matched an order (which they then reversed the payment), that perhaps that’s how they set it up? In theory, it doesn’t cost them much to find shopify stores, place a bogus order and chargeback to get their cash back, then send their scam…
Or am I reading too much into it?
Thanks for sharing it with your clients! Just to clarify, because it’s an important distinction: the chargeback here wasn’t on a customer order in my store. It was on the Shopify subscription/renewal charge itself — i.e. the payment Shopify took for the plan was reversed, which is what got the store deactivated and created the “balance owing”. So the matching amount isn’t a customer placing a bogus order and clawing it back.
That’s actually why the exact match is the suspicious part: the only people who’d know that subscription/renewal figure to the cent are those with access to the account’s billing — which points to someone who already had access to the account or the case (e.g. a previous owner who kept access), rather than a random external phisher guessing amounts.
The scam layer on top is the same either way though, and that’s the bit worth warning people about: a fake “reactivation” invoice paid via an external .myshopify.com link, plus requests to email photos of your ID and credit card. Real Shopify balances are paid only inside the admin (Settings > Billing), and Shopify never asks for ID/card photos by email.
Ahhh! Ok, thanks for the clarification.
In that case… the payment plan amount could be fairly regular for many customers of Shopify, so it may just be that the two were timed well by coincidence.
I remember having a scam email with the name of a good friend of mine, his name isn’t particularly common and it was about something we could talk about, and we don’t talk about common things. The email address was different from the usual though.
I wrote to him by SMS (when that was still a thing!) to see if he had a new email address. It wasn’t him.
When you think about all the infinite possibilities that can be generated, and the low cost to send them out, scammers just need that one “close enough” or so and they can snare a person.
You mentioned it could be former store owners… when a store transfers ownership, new owners should definitely change email/access.
Inconsistencies are pretty common in Shopify. One might say they are clueless sometimes. But I wouldn’t assume an “inside job”. Possible, but highly unlikely.
There are a lot of other possibilities to rule out first, like the actual account or email being compromised.
Hello @Tanukinerd
Thanks for sharing this. The biggest red flag is when they ask you to pay from another store’s checkout, or send identity or payment information via email. Your strategy of only clearing balances via the Billing section of your own store, and not sharing documents externally was the right one.
If a merchant’s store is disabled, they can still verify any aleged balance by their bank records, prior Shopify invoices, chargeback letters, and billing emails. Also check on staff accounts and collaborators, as well as the login history, to make sure there are no lingering users. Hopefully others who have seen similar patterns can share their experience.