TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Shopify employees accessed customer databases without authorization

175 pointsby synunlimitedabout 4 years ago
Got this email from Fangamer about Shopify earlier today. ---- Dear Fangamer customer,<p>Shopify, the company whose software runs the Fangamer store (and more than a million others online), has informed us that an internal security event it has been investigating since late last year included Fangamer customer data. Information regarding customer financial accounts and payment cards was not affected, but we are writing to make you aware of the situation.<p>According to Shopify, certain members of its support team used their Shopify credentials to obtain archived customer data from several hundred stores without authorization. The team members accessed data associated with order fulfillment — names, addresses, email addresses, cart contents, and phone numbers — but did not access or acquire any financial-account or payment-card information.<p>We are extremely frustrated and sorry to be sending you this email; Fangamer&#x27;s internal development team takes data security extremely seriously. Data not in Fangamer&#x27;s Shopify store — including Kickstarter backer information, account information and passwords, and email addresses used to sign up for our newsletter — was not accessed, and the store continues to operate as normal. Fangamer Japan, which operates as a separate store, was also not affected.<p>Shopify has terminated the employees who did this and eliminated the vulnerabilities that made it possible. Shopify has also reported that it will be providing any other relevant information to us as its investigation continues, and we&#x27;ll pass along any new material details. If you have any questions, though, please contact us at orders@fangamer.com.<p>Thank you, Fangamer

10 comments

wyxuanabout 4 years ago
The only icing in the cake is that at least Shopify has been both transparent and quick - it&#x27;s only taken a couple months and they&#x27;ve managed to get bottom of the case. Couple months might seem long but from what I&#x27;ve seen it takes about a year of lag time from the start of the breach to when the company finds out&#x2F;acknowledges.<p>In any case I&#x27;m wondering - how did Shopify discover this intrusion? Do they check logs regularly? Did they receive a tip off?
评论 #26289022 未加载
dgudkovabout 4 years ago
It seems like employees are becoming the weakest link in cloud security. If Google will be breached one day, most probably it will happen not because of a technical vulnerability, but due to employee sabotage.<p>I&#x27;m pretty sure that at exactly this moment somewhere someone criminal is already analyzing organization structures, employee profiles, internal security policies and tools of the cloud giants.
评论 #26293028 未加载
评论 #26285079 未加载
manbackharryabout 4 years ago
Didn&#x27;t receive an email, but are they just now referring to the incident that took place September 23 2020?<p><a href="https:&#x2F;&#x2F;www.cbc.ca&#x2F;news&#x2F;business&#x2F;shopify-data-breach-1.5735191" rel="nofollow">https:&#x2F;&#x2F;www.cbc.ca&#x2F;news&#x2F;business&#x2F;shopify-data-breach-1.57351...</a>
评论 #26282290 未加载
评论 #26283685 未加载
motohagiographyabout 4 years ago
We have recourse against platform employees who snoop user data for personal reasons, and even share it with their friends or political organizations? Literally thought that was a perk of their jobs.<p>Someone should tell reddit&#x2F;google&#x2F;facebook&#x2F;amazon as that will blow things up pretty badly.<p>Wait until they are subject to normal privacy regulations that require the companies to list the names of people who have accessed their user data.
评论 #26283241 未加载
评论 #26288982 未加载
thebrainabout 4 years ago
I got the same email from Fangamer, I&#x27;m surprised I haven&#x27;t gotten similar emails from other Shopify stores I&#x27;ve used.
评论 #26282346 未加载
jasfiabout 4 years ago
How do you protect against this sort of thing as a SaaS developer?
评论 #26287874 未加载
评论 #26283445 未加载
评论 #26287984 未加载
notadevabout 4 years ago
I sometimes go out of my way to hide my identity from sites&#x2F;services I sign up with. Easiest way to get doxxed is for someone to ask one of their polticially-aligned buddies working at a site to pull up your info.
thinkingkongabout 4 years ago
I mean... its only news because it got out. If you seriously believe companies arent accessing your data its borderline delusional.
评论 #26285063 未加载
评论 #26282284 未加载
krthkvabout 4 years ago
The &quot;employee access to customer data isn&#x27;t protected&quot; sits as unsolved an opportunity canvas&#x2F;brief in almost every SaaS company. You can get to a fair amount of controls with little to no code and only with process changes (aka SoC and ISO certifications), which is also what SaaS security teams spend quite a bit of time on. There are a fair amount of problems to be solved here.
评论 #26284278 未加载
xtiansimonabout 4 years ago
How was the event discovered?