Our Shopify account was hacked today with an unauthorized log in. The hacker was able to access our Shopify payout account and the associated Shopify digital debit card to make a payment to themselves. We have 2 step authentication enabled so how did they get into our account? They had access to our recovery codes! Even with 2 step authentication set up, anyone with your recovery codes can bypass the 2 step authentication and access your account. There is absolutely no way anyone could have accessed those codes from me as the codes were physically written down and locked away. This means the recovery codes on the Shopify platform have been compromised. To check if any of your recovery codes were used, you must go to your security dashboard, and either turn on 2 step authentication if you haven’t already or if you already have, create a back up authentication method. Afterwards, your recovery codes will be revealed and there will be an indication of any codes that have been used. For example, when I checked mine after the hack, it showed one of the codes was used 3 hours earlier which corresponds with the time our account was hacked. Recovery codes is another security weakpoint and Shopify must get rid of them. THIS IS A SERIOUS ISSUE AS IT NEGATES THE 2 STEP AUTHENTICATION, PASSKEYS, AND PASSWORDS. If a hacker is able to access your recovery codes, they CAN get into your account and drain your payout balance. Anyone who has been hacked, please check your recovery codes. SHOPIFY, PLEASE REMOVE RECOVERY CODES!
Really sorry this happened to you, Ejo. Having your account compromised and watching funds drain out is awful, and I completely understand why you’re frustrated.
julie_w9 has given you good advice on checking your active sessions and trusted devices. Definitely do that if you haven’t already.
I wanted to add something that might help explain what happened, because I think the platform compromise theory is unlikely. If Shopify’s recovery code system was breached at infrastructure level, we’d be seeing thousands of merchants hit simultaneously. Recovery codes are typically hashed server-side rather than stored in retrievable plaintext.
Here’s the thing though. You mention your codes were physically written down and locked away, which is good practice. But they were first generated and displayed on your screen. That’s the vulnerability window most people don’t think about.
If you had any kind of infostealer malware on your device when those codes were originally generated, it could have captured them via screenshot or screen recording. Same goes for browser extensions with broad permissions. Some of these can read everything on the page. There’s also the possibility of session token theft, which is particularly nasty. If an attacker stole your browser cookies through malware, they could log into your account using your already-authenticated session. No 2FA prompt needed because the session was already trusted. From there, they could simply view your recovery codes from within your account settings.
It might be worth running a full malware scan, auditing your browser extensions (remove anything you’re not actively using), and checking haveibeenpwned.com for your email addresses. Going forward, hardware security keys like YubiKey are worth considering. They can’t be phished or captured by screen-scraping malware the way recovery codes can.
None of this diminishes how serious the attack was. I hope Shopify support or your bank can help you recover the funds. Ensure you report this to law enforcement as well.