Shopify Working With Feds to Investigate Security Breach

According to online retail platform Shopify, two employees pilfered customer data from more than 100 merchants, and now the company is working with authorities, including the Federal Bureau of Investigation, to investigate the matter.

In a statement, the Ottawa-based company said that it immediately cut off those employees’ access to the network and contacted law enforcement. Now the company is “currently working with the FBI and other international agencies in their investigation of these criminal acts,” it said, promising to keep affected retailers and their customers in the loop with any revelations.

Shopify explained that the security breach was not due to any sort of bug, backdoor or security hole in its technology, blaming instead the human activity of two “rogue” staffers. The clarification was likely made to set it apart from questions raised last year, when a security expert uncovered a glitch in Shopify software that could make revenue across thousands of stores vulnerable.

These bad actors attempted to grab customer transaction information, the company said. The effort apparently succeeded with at least some records accessed as recently as Sept. 15, according to e-mails sent by Shopify merchants to customers.

The company believes that fewer than 200 retailers were impacted by the incident, which may have compromised names, e-mail addresses, mailing addresses and purchase histories. But, Shopify noted, financial details like credit card, banking or other payment accounts were not part of the vulnerable data set.

Since its initial public offering in 2015, Shopify has become an e-commerce giant, a notable achievement in a roiling digital environment largely owned by Amazon.

The company’s core proposition to help merchants set up for online retail offered a compelling counterpoint to marketplace-driven scenarios. Demand for its subscription software and other digital tools has skyrocketed this year, as brick-and-mortar retailers flock to the Internet for sales, and it’s now considered the most valuable public Canadian company.

The platform includes more than a million merchants now, according to its latest earnings report.

Sign up for WWD's Newsletter. For the latest news, follow us on Twitter, Facebook, and Instagram.