Skip to content

Shopify says two 'rogue' employees involved in data breach to obtain customer records

OTTAWA — Shopify Inc. is working with the FBI after two "rogue members" of its support team engaged in a scheme to illegitimately obtain customer transactional records of some merchants.

The Ottawa-based tech firm says it terminated the employees' access to its network and referred the data breach to law enforcement.

Shopify says it doesn't have evidence at this point in the investigation that the data was used.

It says fewer than 200 merchants whose stores were illegitimately accessed are at risk of having had their customer data exposed. This data includes basic contact information, such as email, name, and address, as well as order details, like products and services purchased. 

Complete payment card numbers or other sensitive personal or financial information were not involved.

Shopify, which is Canada's most valuable company, says the incident was not the result of a technical vulnerability in its platform, and emphasized that the vast majority its customers are not affected.

"We don’t take these events lightly at Shopify. We have zero tolerance for platform abuse and will take action to preserve the confidence of our community and the integrity of our product," it said in a company message board.

"To put it simply, we are committed to protecting our platform, our merchants, and their customers. We will continue to work hard to earn your trust every day."

This report by The Canadian Press was first published Sept. 22, 2020.

Companies in this story: (TSX:SHOP).

The Canadian Press


Looking for National Business News?

VillageReport.ca viewed on a mobile phone

Check out Village Report - the news that matters most to Canada, updated throughout the day.  Or, subscribe to Village Report's free daily newsletter: a compilation of the news you need to know, sent to your inbox at 6AM.

Subscribe