Zum Inhalt springen

For new clients: we design your mobile menu free of charge.See mobile designs

Article · September 18, 2023

Is Shopify secure? How to protect your store from fraud and data loss

What Shopify handles for your store's security, how to recognize fraud schemes and the five steps that protect your logins and data.

The short answer: yes, Shopify is a secure platform. Servers, payment processing, SSL certificates and protection against overload attacks are handled by Shopify. Logins, staff permissions, apps and backing up your data are your responsibility. That is where it is decided how secure your store is day to day.

Security also affects revenue and trust: customers buy where they know their data is in good hands, and mistakes damage the brand image. Security questions therefore belong in the platform selection already. If you already sell on Shopify, you should review your own settings regularly. Below we show what Shopify handles for the security of your online store, how to protect yourself against fraud and which five steps are up to you.

Is Shopify secure and reputable?

Shopify is a closed platform run as software as a service on a subscription basis. This means Shopify is responsible for the central infrastructure, meaning servers, hosting and database maintenance, and for the security of payment processing. You do not have to maintain servers or keep self-installed store software up to date.

Whether Shopify is reputable and trustworthy can be judged by verifiable points: Shopify is certified at Level 1 under the card payment standard PCI DSS and provides audit reports such as SOC 2 Type 2 and SOC 3. By its own account, millions of businesses rely on the platform.

Shopify security: what Shopify handles and what stays with you

  • Shopify: servers and hosting, protection against overload attacks, SSL certificates, a PCI DSS certified payment environment at checkout and fraud analysis for orders.
  • You: secure sign-in, access for staff and agencies, installed apps, your email account and backing up your store data. Keep track of who has access to the admin and to sensitive data.

If you are currently considering a move to Shopify, you will find the key steps in our store migration guide and in the store migration checklist.

Secure checkout: PCI DSS, SSL certificate and payment environment

At checkout, customers enter their payment details. Here Shopify meets the Payment Card Industry Data Security Standard (PCI DSS) at Level 1. This is the security standard for anyone who stores, processes or transmits card data. According to Shopify, the certification applies by default to all stores on the platform.

Shopify SSL certificate: free and automatic

Shopify provides free TLS certificates for all domains you connect to Shopify, still commonly called SSL certificates. This also applies to the myshopify address. If you buy or transfer a domain through Shopify, the certificate is issued automatically. For a domain from another provider, this happens as soon as the A record and CNAME point to Shopify. That can take up to 48 hours. Third-party certificates cannot be used.

You can see the status of your domains in the admin under Settings > Domains. There is one trap: if your theme loads images, fonts or scripts from external servers without HTTPS, the page is considered insecure.

Can the Shopify checkout be customized?

Yes. Today the checkout can be designed in the checkout editor under Settings > Checkout and extended with apps. Apps for the information, shipping and payment steps are only available on Shopify Plus. Apps for the thank you page and the order status page can be used from the Basic plan.

Important for security: according to Shopify, such checkout extensions run in a sandboxed environment, separate from the checkout page. They have no access to sensitive payment data and none to the code of the checkout page itself.

How does Shopify protect against hackers and DDoS attacks?

Two well-known types of attack on online stores are:

  • Brute-force attacks: An attacker tries to guess a password by trying out many combinations.
  • DDoS attacks (overload attacks): A server is flooded with so much traffic that it is no longer reachable.

According to its own help center, Shopify protects stores with services from Cloudflare, including a web application firewall and DDoS protection. Every request to your online store first passes through Cloudflare. This protection is always active and requires no configuration from you.

Against automated access, hCaptcha is also active by default in every store. It protects contact and comment forms as well as customer account pages from spam by bots. Stores on Shopify Plus can additionally use bot protection for the checkout during sales events.

Shopify hack: where the platform's protection ends

No firewall helps against stolen or guessed login details. Anyone who signs in with your valid password looks like you to the system. This is where two-step authentication comes in: even if someone knows your password, according to Shopify they cannot sign in without the second step. How to secure your logins is covered further below.

Fraud protection in Shopify: how to protect yourself against order fraud

Shopify checks orders with a fraud analysis. You see the result in the order details in the "Order risk" section before you ship. The analysis applies to online orders paid by credit card that Shopify can check. If you use a different payment provider, Shopify advises asking them which restrictions apply.

  • Fraud indicators are visible from the Basic plan.
  • Recommendations for individual orders are available from the Grow plan or if you use Shopify Payments.
  • No recommendation is given for test orders, free orders, orders paid entirely with a gift card, POS orders, B2B orders and subscription renewals, among others.

How Shopify recognizes risky orders

Shopify rates the risk of a chargeback due to fraud as low, medium or high. According to the Shopify Help Center, the checked characteristics include:

  • address verification (Address Verification System, AVS),
  • the card verification value (CVV),
  • whether the customer's location matches the payment method,
  • unusual activity on the device or network,
  • whether the customer tried to use more than one credit card.

Depending on the rating, the recommendation is: fulfill the order, check with the customer before shipping or consider canceling. With Shopify Payments, Shopify can also block some particularly risky checkouts before an order is even created.

What to do with a risky order

  • Ask: Have the customer confirm the order before you ship.
  • Cancel and refund: According to Shopify, canceling can lower the risk of a chargeback. It does not prevent the cardholder's bank from initiating a chargeback anyway.
  • Capture payment manually: With manual payment capture you review risky orders before the money is collected.
  • Automate: With Shopify Flow, orders with certain risk patterns can be flagged, held or canceled automatically.

Shopify fraud and scams: how to recognize phishing

One scam Shopify explicitly warns about is fake messages in Shopify's name: by email, by SMS (smishing) or by phone (vishing). They ask you, for example, to open a link, download a file or send personal data and confirmation codes for two-step authentication.

How to recognize genuine Shopify messages

  • Shopify sends emails only from official domains such as @shopify.com, @email.shopify.com, @em.shopify.com and @shopify-billpay.melio.com. Messages from public email services such as Gmail, Yahoo, Apple Mail or Hotmail do not come from Shopify.
  • Shopify never asks for sensitive information directly in an email, neither in the text, as an image nor as an attachment. Shopify requests sensitive documents only through a secure upload page at app.shopify.com or another shopify.com address.
  • Warning signs are time pressure, threatening wording, impersonal greetings such as "Dear account holder", spelling mistakes and links to unknown sites.
  • By phone and SMS: do not give out sensitive data and do not open links from unexpected messages.
  1. Change the password of your Shopify account immediately.
  2. Enable two-step authentication if you have not already done so.
  3. Ask Shopify Support to check whether someone accessed your account without authorization.

Forward suspicious messages to phishing@shopify.com.

For shoppers: is a store on Shopify reputable?

Shopify provides the technology, the stores themselves are run by independent merchants. Under Shopify's Acceptable Use Policy, every merchant is responsible for complying with rules and laws. The fact that a store runs on Shopify therefore says nothing about whether the merchant is reputable. If you suspect a store violates the policies, you can report it through Shopify's report form.

How can you secure your online store?

Shopify takes care of a large part of your online store's security. Five steps are up to you.

1. Sign in securely: password, passkey and two-step authentication

Use a dedicated password for Shopify that you use for no other account, ideally generated and managed with a password manager. An alternative is passkeys: with them you sign in via face recognition, fingerprint, PIN or screen lock, without any password. According to Shopify, passkeys help prevent phishing and stolen passwords.

Two-step authentication adds further protection: anyone who wants to sign in needs your device in addition to the password, such as an authenticator app or a security key. In some cases Shopify requires it at the next sign-in even if you did not enable it yourself. For Shopify Payments it is mandatory. SMS can no longer be set up as a new method.

On Shopify Plus, you can specify in the settings under Users > Security that all users in your organization must use a secure sign-in method. Without this requirement, each user decides for themselves.

2. Separate logins for staff and agencies

Do not share your own login. Shopify recommends creating staff as separate users in the store so that everyone works with their own credentials, and giving them only the permissions they need for their tasks. Agencies and freelancers work through their own partner access (collaborator accounts). Require everyone involved to use secure passwords and two-step authentication.

Review regularly who has access and adjust permissions when tasks change or a project ends. You can spot suspicious sign-ins in your Shopify user account and unknown changes to the store in the activity log.

3. Check apps before and after installation

Every app gets access to parts of your store. When installing, check carefully which permissions an app requests and whether they fit its purpose. On the details page of an installed app, Shopify shows under Privacy which personal data it can access, and under Activity and permissions which areas it can view or edit. Permissions an app has not used in the last 30 days are listed separately by Shopify as unused access.

Review the list of your apps in the settings regularly and uninstall apps you no longer need. Every installed app is another access point to your data.

4. Back up your data regularly

Shopify does not back up your store data for you by default, the Shopify Help Center points this out explicitly. You have several options:

  • CSV export: Products, customers, orders, gift card codes, discount codes and financial data can be exported from the admin as CSV files.
  • Theme copy: Download your theme before making major changes.
  • Backup app: For regular backups there are apps in the Shopify App Store.
  • Store copy: Shopify describes in its help center how to transfer your data to a second store. Not everything can be taken along, however.

Keep in mind: not everything can be restored later. According to Shopify, orders cannot be imported into a store through the admin, only via apps or the API. Discount codes, issued gift cards and saved custom reports cannot be transferred to a store copy. All the more reason to have a backup solution in place before something goes wrong.

5. Secure your email account

Passwords can be reset through your email inbox. Whoever controls it often gets into other accounts as well. Shopify therefore recommends securing your email account with its own strong password too and enabling two-step authentication there as well.

Conclusion

Shopify takes many security steps off your hands that would be yours with a self-hosted store system, such as an open-source solution on your own server: servers, firewall, DDoS protection, SSL certificates and a PCI DSS certified payment environment. The question "Is Shopify secure?" can therefore be answered with yes, as long as you do your part: secure sign-in, clean access management, vetted apps and regular backups. Then you can focus on your business.

  • Shopify

Keep reading

From the agency.

All press releases
Clicking loads the chat of our provider. No data is sent to them before that.