Skip to main content
Email Security Updated

Business Email Compromise for Shopify Teams

How business email compromise works, which requests require a second check, and where sender authentication helps.

What is business email compromise?

Business email compromise, often called BEC, is an impersonation attack that tries to change a payment, account, or sensitive-information decision. It can target your team by pretending to be a supplier or platform, or target customers by pretending to be your store.

The defining feature is the decision the message tries to change: pay a new bank account, disclose credentials, alter a shipping address, or approve a request outside the normal process.

Common Shopify scenarios

Supplier payment changes

An email that appears to come from a supplier asks you to use a new bank account or pay an urgent invoice. The sender may use a compromised mailbox, a lookalike domain, or a familiar name with a different address.

Platform or app impersonation

An attacker claims to be Shopify, a payment provider, a shipping service, or an app partner. The message asks an operator to sign in, install something, or verify a payment method through a link that is not part of the usual workflow.

Customer-facing order messages

A fake order confirmation, shipment notice, or support reply uses your brand to push a customer to a copied checkout or credential page.

Red flags worth a second check

  • A request to change payment details, banking, or account ownership
  • A new sender address or a close-looking domain
  • A deadline meant to bypass your normal approval process
  • A link that sends you to a domain you do not recognize
  • A request for credentials, recovery codes, or payment details by email
  • An invoice or order change that does not match a known order or contract

Any one signal can be innocent. The safe response is to verify high-impact changes through a separate, known channel, such as a saved phone number or the vendor portal you normally use.

Controls that reduce the risk

Use a separate verification step for money and access

Write down who can approve payment-detail changes and how they are verified. Do not use the contact information provided in the questionable email to complete that verification.

Authenticate the mail you send

SPF, DKIM, and DMARC make exact-domain spoofing harder. They do not stop a lookalike domain or a compromised legitimate mailbox, so combine them with a clear sender inventory and customer education.

Limit and review permissions

Use the least access needed for mail, Shopify, finance, and apps. Review admin access, forwarding rules, and high-privilege accounts after staff or vendor changes.

Make the official route obvious to customers

Publish your official domain, support address, and account-help process. Tell customers what you will not ask for by email, especially passwords, recovery codes, and off-site payment.

Lookalike domains can be used in invoices, support replies, and customer campaigns. Treat a new variation as a lead and verify its content before reporting it.

If you suspect a BEC incident

  1. Pause the payment, access change, or data disclosure
  2. Contact the real supplier, bank, or platform through a known channel
  3. Preserve the email with headers and the linked URL
  4. Reset compromised credentials and revoke active sessions if an account may have been accessed
  5. Contact your bank promptly if money was sent
  6. Notify affected customers or partners with a factual, approved message when needed
  7. Report the incident to the relevant platform, provider, and local authority as appropriate

An incident involving money, personal data, or a disputed identity can require legal, banking, and breach-notification advice. Escalate early rather than relying on a generic checklist.

How Recon fits

Recon checks the email-authentication configuration on your domain and watches for lookalike domains that could be used in impersonation. It does not decide whether a payment request is legitimate. Your payment and approval controls do that work.

FAQ

Q: Is BEC just phishing?

A: BEC is a form of targeted impersonation. It is usually focused on changing a financial or access decision rather than distributing a generic message at scale.

Q: Can DMARC prevent BEC?

A: DMARC helps prevent unauthenticated mail from using your exact domain. It does not stop messages from lookalike domains or a compromised real mailbox.

Q: What should customers do after entering details on a fake site?

A: Tell them to contact their bank or card provider, change reused passwords, and contact your official support channel. Avoid asking them to send sensitive details back over email.

Want us to monitor this for you?

Get automated brand security monitoring for your Shopify store with Recon.

Install on Shopify