Scam or Legit Email?

Topic summary

A user received suspicious emails from “Shopify Ecosystem Governance” connecting them with someone named Jefferson who claimed to fix store issues. The sender threatened website shutdown for non-compliance and provided a Gmail address for contact.

Community Response:

  • Confirmed this is a scam/phishing attempt
  • Legitimate Shopify communications never use Gmail accounts
  • Official Shopify emails come from verified domains only

Common Scam Patterns:

  • Fraudsters often pose as compliance, ADA, or performance experts
  • If victims grant access, scammers either do nothing useful or inject malicious code
  • These schemes frequently appear on the forum

Recommendation: Do not respond or provide access. Verify legitimate Shopify emails through official help documentation.

Summarized with AI on October 28. AI used: claude-sonnet-4-5-20250929.

I’ve been getting some emails from “Shopify Ecosystem Governance” and they put me in touch with someone named Jefferson saying he could fix things on my store to make it run more smoothly but that if i didn’t comply, my website would be shut down. Is this legit? This is the email they told me to get in contact with which was a gmail email.

Hi @arahstew

Welcome to the community.

If it is a gmail email then they could claim they are a new pope you should not belive them :slightly_smiling_face:

https://help.shopify.com/en/manual/privacy-and-security/account-security/phishing#recognizing-legitimate-shopify-emails

The Shopify team would never use GMail accounts. That and several scams are often here on forum, you can use the search and see all the different cases people had. From them, compliance, ADA, performance score and more other ideas all scams. IF you do reply and give then access, often they do nothing useful and say it is “fixed,” and in worst cases, it can actually harm your score or add some malicious code.

So watch out, and stay safe.