Skip to main content
Back to overview
High

Shopify Customer Data Breach by Rogue Support Agents

On September 22, 2020, Canadian multinational e-commerce company Shopify Inc.

Key points

  • On September 22, 2020, Canadian multinational e-commerce company Shopify Inc. disclosed a security incident where "two employees went 'rogue' and stole customer information." These insider threat actors illegitimately accessed records connected to fe
  • Shopify Customer Data Breach by Rogue Support Agents

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Confidentiality impact

Possible insider activity

03

Potential impact

Data Exposure

Confidentiality

Published
Jan 1, 2020
Updated
Aug 5, 2026
Confidence
High
Evidence
5 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible insider activity

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: possible insider or internal misuse

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

ShopData DisclosureRogue Support Agents On SeptemberCanadianShopify IncTheseShopifyFBI andOn SeptemberRogue Support Agents

Quick context

Questions about this signal

What happened in this signal?

On September 22, 2020, Canadian multinational e-commerce company Shopify Inc. disclosed a security incident where "two employees went 'rogue' and stole customer information." These insider threat actors illegitimately accessed records connected to fewer than 200 of Shopify's merchants. The compromised customer data included email addresses, names, addresses, and order details. Shopify immediately terminated the individuals' access to their network and referred the incident to law enforcement, working with the FBI and other international agencies in their investigation of these criminal acts. At the time of disclosure, there was no evidence to suggest that the stolen data had been used. Shopify notified the affected merchants about the incident.

When was this signal reported?

Shadow Tier lists Jan 1, 2020 as the signal date.

Which organization is connected to this signal?

Shop is the organization connected to this public signal.

Explore Shop
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence