shopify hacked

Shopify stores and databases hack ? Shopify eBay Integration ok

jlee2027_yv75wi72

Arrived at work today and had an email notice from Shopify to reset my password for their ecommerce forums. Seemed like not a big deal, so I put it on the back burner and ignored it. Locally, Shopify eBay Integration is running fine. Because I have three Shopify accounts, and the one least used is the forum.  So, one for their forums. and one as a Shopify Partner and one as a Shopify test store, which partners get. Here is the email admission:

Recently, there was an unauthorized access to the Ecommerce University database.
No financial data or sensitive personal data was accessed, however, as a precaution
Ecommerce University user passwords have been reset.

A couple hours later, I attempted to sign into my Shopify Partner Account (which is separate), and surprise, surprise.  Hence, I have to change the password. The Shopify test store also required a password change. I quickly changed all my passwords and restored access.

Because, what’s going on guys? Maybe this all boils down to a simple reset.

The hack may be may be more severe than Shopify wants to say. Most of all just protect yourselves with a a password reset.  Your Shopify eBay integration remains unaffected.

Finally, Shopify has posted an update here:

https://ecommerce.shopify.com/c/announcements/t/ecommerce-university-security-notification-393020

What happened?

Our investigation determined that an attacker used compromised administrator credentials to gain access to Ecommerce University. After gaining access, the attacker downloaded user data from the Ecommerce University database. Name, email address, URL, and bcrypt hash were accessed. 

In conclusion, they fail to fully explain why the Partner and apparently store accounts also needed passwords reset.  As a result, we still don’t know the full story. Seems the update is suggesting the use of a password vault. Due to, password vaults have unique passwords for every account you have. I find this un-necessary and cumbersome. And dangerous. Because with even a dozen accounts you need to write it all down somewhere. Rather, I would ask Shopify to prevent intrusions like this first.

Shopify ebay integration

ebay + Shopify

Shopify ebay integration

ebay + Shopify

Shopify ebay integration

ebay + Shopify

Shopify ebay integration

ebay + Shopify

Shopify ebay integration

ebay + Shopify

Shopify ebay integration

 

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *