E-commerce platform provider Shopify revealed that two members of its support staff accessed customer information without authorization. The duo abused their permissions to access data related to transactions a number of merchants that are estimated to be less of 200. Data accessed by the two rogue employees included name, email address, physical address, and order details (e.g. products and services purchased) The company already notified all the impacted merchants and fired the two employees. The incident was not the result of a security vulnerability in its platform.”]
Source: https://securityaffairs.co/wordpress/108669/cyber-crime/shopify-insider-threats.html

