Advertisement
Australia markets closed
  • ALL ORDS

    8,022.70
    +28.50 (+0.36%)
     
  • ASX 200

    7,749.00
    +27.40 (+0.35%)
     
  • AUD/USD

    0.6604
    -0.0017 (-0.26%)
     
  • OIL

    78.20
    -1.06 (-1.34%)
     
  • GOLD

    2,366.90
    +26.60 (+1.14%)
     
  • Bitcoin AUD

    92,068.41
    -2,892.53 (-3.05%)
     
  • CMC Crypto 200

    1,264.07
    -93.94 (-6.92%)
     
  • AUD/EUR

    0.6128
    -0.0010 (-0.16%)
     
  • AUD/NZD

    1.0963
    -0.0006 (-0.05%)
     
  • NZX 50

    11,755.17
    +8.59 (+0.07%)
     
  • NASDAQ

    18,161.18
    +47.72 (+0.26%)
     
  • FTSE

    8,433.76
    +52.41 (+0.63%)
     
  • Dow Jones

    39,512.84
    +125.08 (+0.32%)
     
  • DAX

    18,772.85
    +86.25 (+0.46%)
     
  • Hang Seng

    18,963.68
    +425.87 (+2.30%)
     
  • NIKKEI 225

    38,229.11
    +155.13 (+0.41%)
     

Shopify says two support staff stole customer data from sellers

Shopify has confirmed a data breach, in which two "rogue members" of its support team stole customer data from at least 100 merchants.

In a blog post, the online shopping site said that its investigation so far showed that the two employees, who have since been fired, were "engaged in a scheme to obtain customer transactional records of certain merchants."

Shopify said it had referred the matter to the FBI.

The employees allegedly stole customer data, including names, postal addresses and order details, from "less than 200 merchants," but financial data was unaffected.

ADVERTISEMENT

Shopify said that it does not have any evidence to suggest that the data was used, but that it had notified affected merchants of the incident.

One merchant shared with TechCrunch a copy of Shopify's email notification, which said the company first became aware of the breach on September 15, and that the two employees obtained data that was accessible using Shopify's Orders API, which lets merchants process orders on behalf of their customers. The email also said that the last four digits of the customers’ payment card was taken in the incident.

Shopify did not say how many end customers were affected by the theft of data from merchants, but the email sent by Shopify contained the specific number of customer records taken in the breach. In this merchant's case, more than 1.3 million customer records; over 4,900 were accessed.

A spokesperson for Shopify didn't respond to a request for comment.

Just last month, Instacart admitted two of its third-party support staff improperly accessed the information for shoppers who deliver grocery orders to customers.