Laptop screen showing a phishing attempt warning and suspicious email message
,

Shopify Payments Verification Scam: The Link-in-Bio Trap

What this email claimed:

  • Sent by the “Merchant Verification Team at Shopify” and “Shopify Trust & Safety Team”
  • A Shopify Payments verification scam requiring the store owner to confirm business information
  • Failure to comply will cause “disruptions to payments and payouts”
  • Includes a “Confirm business information” button
  • Delivered in both English and German in the same email

What was actually found:

  • The sender address belongs to a compromised Shopify store, not Shopify — the domain is myshopimarketing[.]com
  • The “Confirm business information” button routes through hoo[.]be, a link-in-bio platform, used as a redirect layer
  • Additional links in other variants use lihi2[.]me, tr[.]ee, and direct Telegram channels — all redirect or messaging services with no connection to Shopify
  • The phishing campaign operates at scale: multiple email addresses, multiple redirect domains, bilingual templates
  • This same campaign was reported on the Shopify community forum, confirming it is widespread

Step 1 — Sender Analysis

The display name reads “Shopify Support.” The actual sender address is support@myshopimarketing[.]com.

That is not a Shopify domain. The domain myshopimarketing[.]com is almost certainly a compromised Shopify store owner’s domain — someone who previously fell for this same phishing campaign. The attacker gained access to their email and is now using it to send the same phishing email to every contact and store owner they can reach.

This is the chain reaction we described in our Shopify store owner scams overview: one compromised account becomes the launchpad for hundreds more phishing attempts. The email passes basic spam filters more easily because it comes from a real domain with established sending history — not a freshly registered throwaway.

KEY TAKEAWAY
The sender domain is the first and most important check. Shopify sends email exclusively from @shopify.com. Any other domain — no matter how close it looks — is not Shopify.

Step 2 — Email Body Red Flags

The email is unusually polished. It includes the Shopify logo, Shopify’s real Ottawa headquarters address (151 O’Connor Street, Ground floor, Ottawa, ON, K2P 2L8), and a footer link reading “contact Shopify Support.” The layout mimics Shopify’s actual transactional email templates.

What gives it away:

Bilingual delivery. The email contains the same message in both German and English, side by side. Shopify sends emails in the language configured in your store settings — not both simultaneously. This double-language approach is a mass campaign tactic: cast a wider net without knowing which language the target uses.

Personal name in an impersonal email. The English version opens with “My name is Nik with the Merchant Verification Team at Shopify.” Real Shopify compliance communications don’t introduce individual employees by first name. This false personalization is designed to create a sense of direct human contact — making you feel like ignoring the email means ignoring a real person.

Vague regulatory pretext. “Due to online financial regulations, we require your assistance in confirming that the line of business related to the payment complies with our Terms & Conditions.” This sentence doesn’t reference any specific regulation, any specific term, or any specific issue with the store. It’s generic enough to apply to anyone and sound urgent to everyone.

Urgency without specifics. “It is crucial that we complete this process promptly to avoid any disruptions in our ability to process payments and payouts.” The threat is payment disruption — the one thing every store owner fears — but no timeline, no ticket number, and no account reference are provided.

The “contact Shopify Support” footer link. In a legitimate Shopify email, this would link to help.shopify.com. In this email, it likely redirects through the same obfuscation layer as the main button. The presence of a familiar footer element builds false trust.

Also read: fake Shopify compliance email the reply HELP trap

Step 3 — Extracting the Links (Without Clicking)

The primary call-to-action button reads “Confirm business information.” Across multiple variants of this email, the following URLs were found behind these buttons:

  • hxxps://hoo[.]be/patchplants/1o9cY9P1CWH
  • hxxps://hoo[.]be/patchplants/17Xn8eFqdy1
  • hxxps://hoo[.]be/shfy
  • hxxps://lihi2[.]me/eSCzs
  • hxxps://lihi2[.]me/R9XcR
  • hxxps://tr[.]ee/NJkaHiGfnR
  • hxxps://t[.]me/Shopify_Compliancecentre

None of these are Shopify domains.

The attacker is using link-in-bio services as redirect layers. hoo[.]be is an invite-only link-in-bio platform used by creators and influencers. lihi2[.]me is a marketing link tracking service. tr[.]ee is a link shortener from Linktree. The t[.]me link leads to a Telegram channel called “Shopify_Compliancecentre.”

This is a deliberate obfuscation strategy. Link-in-bio platforms and shorteners are trusted by email filters. They’re associated with legitimate marketing, not phishing. By routing through these services, the attacker achieves two things: the URLs pass spam filters, and the actual destination is hidden behind at least one redirect hop.

The hoo[.]be/patchplants path suggests a compromised or repurposed hoo.be account — “patchplants” appears to be the username of a legitimate creator whose account is being abused to host redirect links.

WARNING
Link-in-bio services like hoo.be, Linktree, and similar platforms are increasingly being abused as phishing redirect layers. The link looks clean to your email client. The destination is not.

Step 4 — Breaking the Redirect Chain

The redirect pattern across these links follows a consistent structure:

Hop 1: Email button → hoo[.]be/patchplants/[code] (link-in-bio platform) Hop 2: hoo.be redirect → intermediate tracking domain or second shortener Hop 3: Final destination → credential harvesting page mimicking the Shopify login

The Telegram link (t[.]me/Shopify_Compliancecentre) is a different variant. Instead of a phishing page, it sends the target to a Telegram channel where a “specialist” engages them directly — similar to the reply-based lead generation pipeline we’ve documented, but using Telegram instead of email replies.

The use of multiple different redirect services across different email variants suggests the attacker rotates domains when individual links get flagged or taken down. This is a resilient campaign infrastructure designed to survive individual link takedowns.


Step 5 — Decoding Hidden Data

The hoo[.]be URLs contain path segments like /1o9cY9P1CWH and /17Xn8eFqdy1 — these are short codes generated by the link-in-bio platform’s internal redirect system. They are not Base64 encoded or obfuscated in the traditional sense. They function as lookup keys in hoo.be’s database, pointing to the destination URL configured by whoever controls the “patchplants” account.

The lihi2[.]me links use a similar pattern — short hash codes that resolve server-side. lihi2 is a marketing link tracking platform that logs click data (IP, device, location, timestamp) before redirecting. This means the attacker potentially collects analytics on who clicked and from where, even before the target reaches the phishing page.

The Telegram channel name — Shopify_Compliancecentre — uses British spelling (“centre”) which is inconsistent with Shopify’s North American branding. This is a minor but telling detail.

Step 6 — Safe Environment Testing

Based on community reports and the structural analysis of these links, the final destination is a credential harvesting page that mimics Shopify’s login interface. Reports from the Shopify community forum describe the same campaign leading to a domain formatted like accounts-myshopify-admin[.]is-certified[.]com — a domain designed to look like a Shopify admin URL but hosted on an unrelated domain.

The phishing page reportedly requests:

  • Shopify login credentials (email and password)
  • Business information (store URL, business name)
  • Potentially payment-related information

The pages are designed to look identical to Shopify’s real admin login.

TIP
If you ever land on a Shopify login page, check the URL bar. The only legitimate Shopify admin URL is accounts.shopify.com. Anything else — no matter how real it looks — is a phishing page.


Step 7 — What the Endpoint Actually Does

This is a credential harvesting operation. The phishing page collects:

  1. Shopify login credentials — email address and password, giving the attacker full access to the store
  2. Business information — store URL and business details, which help the attacker identify high-value targets
  3. Session data — the click analytics from the intermediate redirect services provide the attacker with IP addresses, device types, and geographic locations of targets

Once credentials are captured, the attacker gains access to the Shopify admin. From there, they can change payout bank details and redirect revenue, access customer data including payment information, use the compromised store’s email to send the same phishing email to more targets, and install malicious apps or make unauthorized changes.

This is not passive harm. This is active credential theft with immediate financial consequences.


Step 8 — What Would Happen in a Real Scenario

A store owner receives this email, sees the Shopify branding and the Ottawa address, panics about losing payment processing, and clicks “Confirm business information.”

They’re redirected through hoo.be to a page that looks exactly like Shopify’s login. They enter their email and password. The page may show a success message or redirect to the real Shopify site — making the target believe the process completed normally.

Behind the scenes, the attacker now has full access to the store. Within hours, the attacker changes the payout bank account, accesses stored customer data, and uses the compromised email to send this same phishing email to the store’s entire contact list and customer base.

The store owner may not realize anything happened until their next payout fails to arrive — or until their customers start reporting phishing emails coming from their store’s address. By then, the cycle has already replicated.

Also read: Shopify verification email scam how the redirect works

Also read: Shopify store owner scams overview


Key Takeaways

  1. Link-in-bio services are the new phishing redirect layer. Services like hoo.be, Linktree (tr.ee), and marketing link trackers (lihi2.me) are being used to hide phishing destinations from email filters. A clean-looking link to a known platform does not mean a safe destination.
  2. Compromised stores create a self-replicating phishing cycle. The sender domain in this email belongs to a store owner who already fell for this scam. Their email account is now infrastructure for the next wave. Every compromised account multiplies the attack surface.
  3. Bilingual templates signal mass campaigns. Legitimate Shopify emails match your store’s language setting. Receiving the same message in two languages is a clear indicator of a spray-and-pray approach targeting thousands of stores simultaneously.
  4. Multiple redirect domains indicate operational resilience. When an attacker uses hoo.be, lihi2.me, tr.ee, and Telegram across different email variants, they’re ensuring the campaign survives individual link takedowns. Blocking one domain doesn’t stop the campaign.
  5. The Ottawa address in the footer proves nothing. Shopify’s real address is public information. Including it in a phishing email costs nothing and proves nothing about legitimacy. Verify the sender domain, not the footer content.
CategoryFinding
Sender legitimacyFake — compromised store domain impersonating Shopify
Link transparencyHeavily obfuscated — routed through link-in-bio services and shorteners
Redirect chainEmail → hoo.be/lihi2.me/tr.ee → credential harvesting page
Final destinationFake Shopify admin login page (credential harvester)
Immediate riskHigh — active credential theft with financial consequences
Strategic intentSteal Shopify login credentials, redirect payouts, harvest customer data, replicate attack via compromised accounts

Repeatable Checklist: Whenever You Receive a “Verify Business Information” Email

  1. Check the sender address — does it end in @shopify.com? Anything else is not Shopify, regardless of the display name or branding.
  2. Do not click any buttons or links. Open a new browser tab and go directly to admin.shopify.com. If Shopify genuinely needs you to verify anything, you’ll see the notification in your dashboard.
  3. Check the email language. If you receive the message in a language you didn’t configure, or in two languages simultaneously, it’s a mass campaign.
  4. Hover over the button (don’t click). If the URL points to anything other than shopify.com, accounts.shopify.com, or help.shopify.com — it’s phishing.
  5. Report the email to Shopify at reportphishing@shopify.com.
  6. If you already clicked the link and entered credentials: change your Shopify password immediately, enable 2FA, review your payout bank details in Settings → Payments, check for unrecognized staff accounts or installed apps, and contact Shopify support through help.shopify.com.

Stay Safe With EmailClarity

Every week, we break down real scam emails targeting online store owners — the kind that land in your inbox pretending to be Shopify support, fellow entrepreneurs, or marketing geniuses who can triple your sales overnight.

Use our email analysis tool at scan.email-clarity.com to scan suspicious emails instantly, or forward anything sketchy to blog@email-clarity.com and we’ll give it our honest take.

The more emails we collect, the more store owners we can help. Your sketchy inbox is someone else’s warning sign.

Stay sharp out there.

— The EmailClarity Team

Leave a Reply

Comments (

1

)

  1. Etsy Seller Phishing Emails: Fake Verification and Buyer Scams Explained - EmailClarity

    […] Shopify Payments Verification Scam Link-in-Bio Trap […]

Discover more from EmailClarity

Subscribe now to keep reading and get access to the full archive.

Continue reading