Shopify Inbox

Topic summary

Issue: Merchant receives “You have a new message” emails supposedly from Shopify Inbox, but no corresponding conversation appears in their Inbox—suspected phishing.

Initial guidance: Support advises forwarding the email to safety@shopify.com for investigation. If any links were clicked, change passwords and enable two-step authentication (adds a second verification step for login).

Follow-up: Merchant confirms forwarding and asks if logging in via the email’s “Reply in Inbox” link could have compromised credentials.

Latest advice: There is a possibility of compromise. Change the Shopify password immediately (if not already). Then review recent store activity via the Shopify admin Home > Timeline (shows recent actions and updates) to spot any suspicious changes.

Outcomes/next steps:

  • Password change and enable 2FA.
  • Monitor Timeline for unusual activity.
  • Phishing email forwarded to Shopify for review.

Status: Guidance provided; no confirmed breach reported. Discussion effectively addressed with security steps; merchant to monitor and secure account.

Summarized with AI on December 24. AI used: gpt-5.

I get Shopify emails like this (poss scam) but when I look in my Inbox there is nothing there…

no-reply@mailer.shopify.com
Reply
Reply all
Forward


To:​​
Tue 16/07/2024 16:04

You have a new message from chloe Frank

That is brilliant your feedback help us validate the analysis we just conducted about your store. Would you like to hear the details?

Sent via Inbox

Reply in Inbox

Why did I receive this notification?

You have email notifications turned on
This conversation hasn’t been assigned to anyone
Manage notification settings →

© Shopify, 151 O’Connor Street, Ground floor
Ottawa ON, K2P 2L8

Hey, @DaveClark .

Thanks for reaching out and bringing this to our attention.

It’s possible that you’ve received a phishing email pretending to be from Shopify, and we’d recommend forwarding the email to safety@shopify.com so that our teams can take a closer look. That being said, if you’ve clicked onto any links within the email, then we’d also recommend changing your password(s). For an added layer of security, you can also consider enabling two-step authentication to protect your account.

If you have any other questions on this topic, then don’t hesitate to let us know.

1 Like

Hi Elias

That certainly sounds the case, I have forwarded the emails to that email address.

Let’s assume I clicked the “Reply in Inbox” to that scam email and logged in. Have I potentially compromised my login details?

Hi @DaveClark .

There is a possibility that your information is compromised. Please change your password as soon as you can if you haven’t already. Once you change your password, log into your account and you will want to check your accounts recent activity. To view recent activity in your Shopify store, go to the Timeline feature in your Shopify admin. This section shows all recent actions taken in your store, helping you keep track of changes and updates. You can find the Timeline feature in your Shopify admin by navigating to the Home page. It’s usually displayed towards the bottom, showing recent activities and updates related to your store.

1 Like