Shopify points to third-party app for data breach

Editorial use only. September 13, 2022, Brazil. In this photo illustration, a silhouetted woman holds a smartphone with the Shopify logo displayed on the screen
(Image credit: Shutterstock / rafapress)

A hacker has advertised selling a database allegedly stolen from one of the best ecommerce platforms Shopify - however, the company says the archives did not come from its systems, but rather a third party.

A threat actor with the alias ‘888’ recently took to BreachForums to try and sell a database containing roughly 180,000 rows of user information.

This information apparently contains people’s Shopify IDs, full names, email addresses, mobile phones, orders counts, total money spent, email subscriptions, email subscription dates, SMS subscriptions, and SMS subscription dates.

Phishing material

The breach was said to have taken place on July 4, 2024. Soon after the news broke, Shopify released a statement denying it had been breached, and claiming the information was obtained elsewhere.

"Shopify systems have not experienced a security incident," Shopify told BleepingComputer. "The data loss reported was caused by a third-party app. The app developer intends to notify affected customers."

On BreachForums, the hacker released a small sample of the stolen data, as proof of its legitimacy. They are selling the archive as a one-time sale, meaning multiple purchases were not possible. Interested parties were told to reach out to 888 via DMs and offer a sum in Monero (XMR).

Monero is a cryptocurrency popular among cybercriminals due to its enhanced privacy and anonymity features. 

The hacker has a long track record of successful leaks, multiple media outlets have confirmed. Just this year, 888 leaked sensitive data from Credit Suisse, Assurified, Heineken, and Accenture.

We will know more details once the third-party app steps forward and notifies its customers. In the meantime, all Shopify users would be wise to pay extra attention to incoming emails, and be wary of potential phishing or identity theft attacks. 

Shopify’s last data breach was roughly four years ago.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
HPE
HPE investigating claims that hacker breached developer environments, source code
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Oracle
Oracle denies data breach after hacker claims to hold six million records
Data leak
Top collectibles site leaks personal data of nearly a million users
A hacker wearing a hoodie sitting at a computer, his face hidden.
North Pole Company data breach exposes details on half a million users
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring