Updates on Security Incident
Latest information about the recent security incident affecting Qikify Sticky Add to Cart & Qikify Mega Menu, Navigation.
Who this page is for: This page is intended for stores we identified as being within the scope of this issue. If your store was affected, you will have seen a notice inside your Qikify app admin directing you here. If you did not see that in-app notice, your store was not identified as affected.
Latest Update – August 21, 2026
We're pleased to confirm that Qikify Sticky Add to Cart and Qikify Smart Menu & Navigation are now listed back in the Shopify App Store as of today. We thank Shopify for their partnership in completing the security review process.
Compensation & next steps: We want to reassure you that every affected store that is currently active will receive compensation as part of our responsibility. This comes in two parts:
- The first is the immediate compensation already outlined in the email we sent you in late July.
- The second will follow as we finalize our assessment with Shopify. We originally planned to share the full details between August 24 and 30, 2026. However, since the security review process has been completed earlier than expected, we're now working to send you this update as soon as possible.
Table of content
1. What happened
On 22 July, 2026, we identified a security incident affecting two of our apps, Qikify Sticky Add to Cart and Qikify Mega Menu & Navigation. Based on our current investigation, a group of stores was affected.
The vulnerability allowed an unauthorized third party to redirect some customers to a fraudulent page during their purchase. The issue was detected and fully resolved between 12:30 and 22:40 on 22 July, 2026 (UTC). We removed the malicious scripts from all affected stores. Exact detection and fix times for each app are listed below:
1. Qikify Sticky Add to Cart:
On affected stores, customers who clicked the Checkout button from the cart drawer could be redirected to a fraudulent page that is not part of your Shopify store, hosted by an unauthorized third party. This issue was first detected between 12:30 and 12:58 on 22 July, 2026 (UTC), and was fixed between 16:10 and 17:40 on 22 July, 2026 (UTC).
2. Qikify Mega Menu & Navigation:
On affected stores, customers who clicked either the Add to Cart button or the Checkout button could be redirected to the same type of fraudulent page that is not part of your Shopify store, hosted by an unauthorized third party. This issue was first detected at 14:15 on 22 July, 2026 (UTC), and was completely fixed between 19:30 and 22:40 on 22 July, 2026 (UTC).
NOTICE:
- This fraudulent page could not place a real order or charge your customers in either case.
- All of our other Qikify apps were NOT affected by this incident. We recently sent an email asking you to re-authenticate your Qikify apps — this is only part of our security enhancement process, not a new issue.
2. Scope for your store
In both cases, if a customer submitted their details on the fraudulent page, they were then redirected back to the real checkout page on your store. Because the customer ended up on the genuine checkout afterwards, the redirect could easily go unnoticed.
WHAT DATA WAS INVOLVED:
We analyzed both the injected script and the fraudulent page to determine exactly what data was and was not involved. Here is what we found.
Your Shopify data was not touched. No store data, no customer records held in Shopify, and no data accessible through the Shopify API was read, accessed, or transmitted. The injected script did not interact with Shopify's APIs or with any data held by Qikify or Shopify. We can state this with confidence.
Data a customer may have typed into the fraudulent page is the area that requires your attention, and we want to be precise about what we know:
- The fraudulent page displayed these fields: Customer information (email, first name, last name, shipping address, phone number); Payment information (card number, name on card, expiration date, security code). Based on our investigation to date, only the payment information could be collected — and only if a shopper filled in the fields and clicked the "Submit" button.
- During the exposure window, Cloudflare's phishing and fraud protections were active on the attacker's domain and interrupted attempts to reach the page. We confirmed this ourselves by attempting to load the page during our analysis. This means a portion of customers who were redirected would have been stopped before reaching the form — though we cannot measure what portion.
One point that may help as you assess risk: we found no mechanism on the fraudulent page that would charge a payment at the moment of submission or place an order through that external page. The concern is the capture of entered details, not an immediate charge on the page itself.
Theme-level code: no code was written into your Shopify theme by our apps in connection with this incident. The injected content was confined to the app settings record, and its removal was completed after our fixing process.
3. How we responded
Our Support and Engineering teams began investigating and resolving the issue immediately to minimize any potential impact.
We identified the root cause, fully resolved it in our system, and performed a comprehensive review across all affected stores, removing every malicious script identified.
The incident was strictly limited to two customizable HTML content fields within the apps settings:
- For Qikify Sticky Add to Cart: Empty cart text, Sticky cart message.
- For Qikify Mega Menu, Navigation: Item title.
Based on our investigation to date, no Shopify account credentials were accessed, exposed, or compromised through the Qikify system.
4. Current status, next updates & compensation
*Lastest update: We have done the security review with Shopify and both apps are listed on Shopify App Store today (21st August, 2026).
We have shared our initial investigation findings with Shopify, and Shopify has confirmed receipt as part of their review process for restoring the apps and assessing any impact together with us.
We are now working closely with them to complete two additional independent security reviews:
1. Incident Report (IR): A detailed report explaining the incident, its root cause, impact, and remediation actions.
Detailed timeline:
- Jul 29: Kick-off, evidence collection & access setup
- Jul 30 - Jul 31: Evidence triage & IOC analysis
- Aug 3 - Aug 4: Log correlation, timeline reconstruction & root cause analysis
- Aug 5 - Aug 6: Remediation validation & draft Incident Report
- Aug 6: Preliminary Independent IR
- Aug 7 - Aug 11: Final review & Final Indepedent IR
- Aug 12 - Aug 13: Contigency buffer (Contigency for additional investigation, evidence validation, or Shopify follow-up questions)
2. Vulnerability Assessment & Penetration Testing (VAPT): An independent security assessment to verify that the application is secure and free from additional vulnerabilities.
Detailed timeline:
- Jul 29 - Aug 11: Vulnerability Assessment & Penetration Testing
- Aug 12 - Aug 17: Retesting after remediation (if required)
- Aug 18 - Aug 19: Final VAPT report
- Aug 20 - Aug 21: Contigency buffer (Contigency for additional investigation, evidence validation, or Shopify follow-up questions)
We have engaged a specialized third-party security firm to perform both reviews, and the work is currently underway.
NEXT UPDATES & COMPENSATION:
We know waiting for answers is difficult, so we want to be clear about what comes next. Between August 21 and 30, 2026, we will provide a full update here and via email. This will include our assessment of any impact on your store, along with the second part of your compensation — determined once we finalize our assessment of the impact together with Shopify. The first part, the immediate compensation, was already outlined in the email we sent you.
If we are able to share these details sooner, we will reach out immediately.
5. What we're doing to prevent this type of security incident in the future
1. The vulnerability has been fixed.
We identified the root cause of this issue and resolved it in our system, and we removed every malicious script we identified across affected stores.
2. A full security audit across our entire Qikify apps system.
We are now conducting a comprehensive audit of every element and feature across all Qikify apps — not only the two involved in this incident — to identify and close any vulnerability that could be exploited. As part of this process, on 29 July, 2026, we completely reset the authentication for all Qikify apps as a security enhancement. If you received an email notification asking you to re-authenticate your Qikify apps, please be assured this is a routine part of that process and not a sign of new issue.
3. Independent security specialists.
We are engaging certified security partners to carry out this audit alongside our own team, so that our systems are verified independently rather than relying solely on our internal assessment.
6. What you should do next
Although we have already removed all known malicious scripts from your store, we recommend that you perform a quick verification by:
- Opening your storefront.
- Testing the Add to Cart buttons.
- Testing the Checkout button to confirm it redirects to your normal Shopify checkout.
If you notice any unexpected behavior or have any concerns, please contact our priority support team immediately — see below.
7. Priority support
We sincerely apologize for the inconvenience this incident may have caused. Protecting your store and your customers is our highest priority, and we remain committed to working closely with Shopify to ensure the security of our application.
We are currently collecting incident case report to better prioritize these as support tickets and to factor in our final review. Hence, please don't hesitate to leave your message, concerns, or any questions in the form below.
Our support team is ready to assist with any questions or concerns.
Send email here: contact@qikify.com
Or use the contact form below to submit your case: