Your Shopify admin controls customer data, storefront changes, apps, payments and staff access. That makes phishing, account takeover and risky app access more important than most merchants realize.
What you'll learn
- How Shopify phishing attacks usually present themselves.
- What to check in staff and account security.
- Why app permissions and admin identity matter.
- How to respond if a merchant or staff account may be compromised.
Current watch item
What should you check?
- Enable two-step authentication for owners and staff wherever available.
- Review staff accounts and remove access that is no longer required.
- Review installed apps and permissions, especially apps with customer, order or payment-related access.
- Verify recovery and contact details for the store owner account.
- Treat unexpected requests for credentials, 2FA codes, documents or urgent billing action as suspicious until independently verified.
- If compromise is suspected, review recent admin activity and secure the associated email account.
What not to do
- Do not send 2FA codes or credentials in response to email, text or phone requests.
- Do not call a phone number supplied in a suspicious Shopify message.
- Do not upload confidential documents into public Shopify Files storage.
- Do not remove evidence before you understand what account activity occurred.
Official sources CompFlorida reviewed
Shopify Help Center account-security and phishing guidance.
What you should know when you're finished
You should know whether this technology is current, who owns its security and recovery settings, what needs attention now, and whether an issue belongs to the product, the account, the device, the network, or another dependency.
← Back to Technology Risk Center
Last reviewed: September 22, 2026. This resource is educational and does not replace the vendor's current advisory or a review of your specific environment.

