The owner says all of their Black Friday and Small Business Saturday sales are now gone.
That this is happening during the most critical time of the year is devastating, and it’s a reminder of the security features that everyone should make sure they are in place.
Ali’s Wagon, a gift shop, has been a staple on Fairmount Avenue for 15 years.
âWe opened when my daughter was a year old, and she’s about to turn 16,â Jessie Menken said.
âAnd that’s what was deleted. Our bank account was no longer connected to our Shopify,â she explained.
Menken said the cyber thieves stole more than $ 30,000 by replacing his bank account with three different accounts.
âThree new accounts really should have raised a major alarm,â she said. “And so everything should have been frozen until Shopify heard from me.”
But Menken said Shopify only sent an email saying their bank account had been changed. A message she received too late because cyber thieves had also hacked her email.
âI want to say that no customer card has been compromised in any way,â she said.
Cyber ââsecurity expert Rob D’Ovidio said it was a lesson for everyone on the importance of two-factor authentication.
He says it’s the best form of protection in the industry.
âIt should be a standard,â D’Ovidio said.
Two-factor or multi-factor authentication requires a second form of validation before access is granted to an account.
âIf you work with one service and you don’t, they don’t have that two-factor authenticationâ¦ run for the hills. Find another service that does that,â he said.
D’Ovidio said this applies to business owners and consumers alike, and not only do you need to make sure multi-factor authentication is available, but also that it is enabled.
âI don’t think we’ll be able to regain half of what was lost. And it’s really difficult and scary,â Menken said.
Shopify has released a statement regarding this incident:
At Shopify, we take the privacy and security of our merchants very seriously. We strive to help merchants manage their accounts more securely by providing them with guidelines and recommendations. We recommend that all merchants enable two-factor authentication to provide a more secure login process and to help prevent unauthorized access by a merchant administrator.
Copyright Â© 2021 WPVI-TV. All rights reserved.