Posted on behalf of Arnold Law Firm
on October 8, 2020 in Data Breach
Updated on February 24, 2022
On September 22, 2020, e-commerce platform Shopify disclosed a security incident on their blog. Shopify reported that two “rogue” support team employees illegitimately accessed and stole customer transactional records of certain merchants, including Thrive Causemetics and Kylie Cosmetics.
Apparently, the two employees accessed shopper data using Shopify’s Orders API, which lets merchants process orders on behalf of their customers. Shopify did not say how many end customers were affected by the theft of data from merchants, but the emails sent to merchants reportedly contained the specific number of customer records stolen in the breach. One affected merchant claims that more than 4,900 customer records were accessed.
Shopify claims to be notifying affected merchants “as relevant,” but has not yet disclosed a list of those companies. So far, nearly 200 companies have reportedly been notified of their exposure to the data breach.
The unauthorized access reportedly spans from August 15 to September 15, 2020. Shopify claims to have terminated these individuals’ access to their network and has reported the incident to law enforcement.
Compromised customer information may include:
Shopify currently claims that only the last four digits of credit cards were stolen in the security incident. However, online discussions reveal multiple shoppers who received Shopify data breach notices and claim to have suffered fraudulent credit card charges that correspond with the data breach time window.
Even without full financial information, hackers could potentially use such data to launch targeted phishing attacks. So far, Shopify has not offered identity monitoring services to affected individuals.
Unfortunately, this is not Shopify’s first breach of customer payment information. On May 20, 2020, popular startup Bombas learned that malicious code in their Shopify e-commerce platform may have scraped personal information as customers purchased product online. The sock retailer reports that consumer data was exposed during a window from November 11, 2016, to February 16, 2017.
Shopify was originally founded in 2004 as Snowdevil, an online store for snowboarding equipment, which led to the development and launch of the Shopify platform two years later. The Canadian company now employs over 5,000 and claims to be an all-in-one commerce vendor, providing tools for payments, marketing, shipping and customer engagement for over one million businesses worldwide. Shopify’s estimated annual revenues are over 1.5 billion USD.
If you received a NOTICE OF DATA BREACH for one of these data breaches and a class action lawsuit has been filed, you will be included automatically in the class unless you opt-out and no further action will be required by you. Class members have a passive role throughout class action litigation. If the lawsuit is successful, all class members receive equal compensation which is awarded to all class members, regardless of the degree of harm they suffered.
"*" indicates required fields
The Arnold Law Firm reached a settlement in the Morgan Stanley data breach class action lawsuit. The settlement resulted in a $60 million settlement fund to benefit class members.
Learn MoreA whistleblower case exposing fraudulent practices in the state of California resulted in an $18.275 million settlement.
Learn MoreThe Arnold Law Firm reached a settlement in the Kemper and Infinity data breach class action lawsuit. The settlement is valued at over $17 million.
Learn MoreThe Arnold Law Firm is pleased to report that our attorneys received a $10.2 million verdict handed down in Modesto. Defense counsel was Kevin Cholakian of San Francisco. The defense rejected a 998 within the $1 million policy limits three years ago. The highest defense offer was $350k. The case involved a blind corner dirt […]
Learn MoreLate one spring afternoon, the Arnold Law Firm received a call from Angela, a young mother of three. She was calling from the hospital where her husband Christopher had been air-lifted for treatment of severe injuries from a tragic motor vehicle accident earlier that day. Angela’s mother, a past client of our firm, had encouraged […]
Learn MoreThe fatal collision between plaintiff’s Jeep Liberty and defendant’s Volvo truck left Ryan Eisenbrandt’s surviving wife and parents with a judgment of $3.9 million, but the defendant’s insurance company refused to pay. This resulted in a second, intense legal battle between Plaintiffs and Defendant’s insurance company. During the pendency of the wrongful death case, Defendant’s […]
Learn More