CSIDB logo
Threat actor

Two rogue Shopify employees

Attribution profile

Type
Insider - Disgruntled
Location
Canada
Known incidents
1 incident
First seen
2020-09-22
Last seen
2020-09-22
Updated
2026-07-31 19:46
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Two individuals identified only as “rogue” Shopify employees were implicated in a data breach disclosed on September 22 2020, when they illegitimately accessed customer transactional records belonging to certain merchants. The actors were based in Ottawa, Canada, and were members of the company’s support team before their network access was terminated following the discovery of the unauthorized activity. Shopify confirmed that the breach involved the acquisition of merchant customer data, though the exact scope of the records obtained was not made public. The company reported the incident to law enforcement, engaging the FBI to investigate the matter, and the employees were subsequently dismissed from their positions. No additional aliases or affiliations beyond their status as Shopify support staff have been publicly attributed to the actors.

The actors’ targeting was limited to internal Shopify systems, specifically exploiting their privileged access within the support team to retrieve transactional data from merchant accounts. Their observed objective, as stated in the breach summary, was to obtain customer transactional records, indicating a focus on data acquisition rather than disruption or espionage. No malware families, exploit tools, or initial‑access vectors were described in the available reporting, so no specific TTPs can be outlined. Attribution remains confined to the individuals’ employment at Shopify, with no evidence linking them to state sponsors, criminal consortia, or broader threat‑actor groups. The September 2020 incident represents the sole publicly documented operation associated with these insiders, highlighting the risk posed by trusted personnel with access to sensitive merchant information.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB