Dev Advisory: Phishing campaign targeting WooCommerce stores

We’ve identified a phishing campaign targeting WooCommerce store owners. These emails falsely claim to be from WooCommerce and alert users about critical security vulnerabilities that don’t exist.

How to identify these fake emails

The phishing emails:

  • Come from suspicious domains like help@security-woocommerce.com, incident@notify-woocommerce.com, or help@support-woocommerce.com
  • May use punycode domains that appear similar to legitimate WooCommerce domains (example: https://xn--woocommere-7ib.com which can display as woocommerċe.com in some browsers)
  • Claim a “critical security vulnerability” was found on or around April 14, 2025
  • Mention a specific store URL and claim it’s directly impacted
  • Ask users to download and install a “security patch” (which is actually malware)

These emails are not from WooCommerce

WooCommerce security communications always come from official sources like WooCommerce.com or Automattic.com email addresses and direct users to an official download page or WordPress.org repository with clear documentation and verification steps.

What to do if you receive these emails

  1. Do not click any links or download any files
  2. Do not install any plugins from these emails
  3. Report the domains to your email provider as phishing

Keeping your store secure

The best ways to keep your WooCommerce store secure:

  • Install updates directly from your WordPress dashboard or WooCommerce.com
  • Enable auto-updates for security patches
  • Use strong, unique passwords and two-factor authentication
  • Only install plugins from trusted sources (WordPress.org or WooCommerce.com)

We’re actively working to shut down these phishing domains. If you have concerns about your store’s security, please contact our support team through your WooCommerce.com account.

Your security is our priority.

Update: Comments now closed

Thank you to everyone who reported additional phishing domains and suspicious emails. Your vigilance has been incredibly helpful in tracking this ongoing campaign.

We’ve compiled a comprehensive list of known phishing domains from your reports and are actively working with registrars to take these sites down. The purpose of this post was to alert the community about these phishing attempts and provide guidance on how to identify them.

If you encounter any new suspicious emails claiming to be from WooCommerce, please report them directly to our support team through your WooCommerce.com account rather than commenting here.

As a reminder:

  • WooCommerce will never send security patches via email attachments
  • Official communications always come from WooCommerce.com or Automattic.com email addresses
  • Always verify security notifications through official WooCommerce channels

Your security remains our top priority. Thank you for helping protect the WooCommerce community.


37 responses to “Dev Advisory: Phishing campaign targeting WooCommerce stores”

  1. An additional URL has been shown to be woocommėrce.com – Note the small accent on the ‘e’ within woocommerce, as a ‘ė’.

    This is a different character, and thus, a different site.

  2. I’ve just received two of these emails, from noreply@woocommerce-monitor.com and noreply@woocommerce-updates.com

  3. FYI: no-reply@mail-woocommerce.com is the email that was used in an attempted phishing scam for my website. The link in the email for downloading a patch was a bitly link, which I copied out of curiosity but did not visit after seeing it was a shortened link.

    1. Kenix Avatar

      I received from this email no-reply@woocommerce-care.com asking me to download plugin because of critical security vulnerability.

  4. Just had one from security@mail-woocommerce.com – another variation.

  5. We received a similar email from: security@news-woocommerce.com

  6. Brent MacKinnon Avatar
    Brent MacKinnon

    Thanks everyone for sharing these additional phishing domains. We’re continuing to track this campaign and have identified several more malicious domains beyond what was initially reported:

    woocommėrce.com (with an accent mark on the ‘e’)
    noreply@news-woocommerce.com
    noreply@woocommerce-secure.com
    security@mail-woocommerce.com
    security@news-woocommerce.com
    noreply@woocommerce-monitor.com
    noreply@woocommerce-updates.com

    We’re actively filing reports against these domains and working with registrars to take them down. Many of these domains were registered very recently, showing this is an active and evolving campaign.

    If you spot any additional suspicious domains or emails claiming to be from WooCommerce, please continue reporting them here or directly to our support team. Your vigilance helps protect the entire WooCommerce community.

    Remember: WooCommerce will never send security patches via email attachments or ask you to download files from unfamiliar domains. Always verify security communications through official WooCommerce channels.

  7. Where do we report these phishing scams? I just received one and initially I looked it over, but noticed the weird little accent over the e and my gut said “NOPE!”

    I still have it and would love to report it. Thank you!

  8. Thanks for this! Got one today from no-reply@mailer-woocommerce.com

  9. HI,

    Just got one today from support@woocommerce-scan.com.

  10. Another site seems to be wooċommerce.com. Please also keep an eye out for this one!

  11. Debra Sawyers Avatar
    Debra Sawyers

    One of our clients got one yesterday
    From: Woo no-reply@woocommerce-shield.com

  12. Hi got this from Woo support@woocommerce-secure.com

  13. Just received an email from the domain “woocommerce-safety.com”

  14. no-reply@woocommerce-alert.com

    I just received this email… and clicked it… thinking it was a 100% legit…

  15. I got this one this morning.
    no-reply@woocommerce-verify.com

  16. Mahfuzur Rahman Avatar
    Mahfuzur Rahman
  17. C Going Avatar

    support@woocommerce-alert.com is defiantly a fake email.

  18. Is support@woocommerce.com legit? They are asking for more information on my account to continue to receive payments.

    1. Marie,

      WooCommerce.com is indeed our domain, so emails originating from there should be legit.

      However, I searched our support system and could not find any existing support requests from you (which I should be able to see if you’ve already been in communication with us).

      If you’re in any doubt at all, contacting us via the support form is the best way to be sure you’re talking to our staff. 🙂

      https://woocommerce.com/my-account/contact-support/

      Thanks!

  19. I received one from mail-woocommerce.com, pointing to the domain woocommerċe.com.

  20. Hélène Viandier Avatar
    Hélène Viandier

    Voici une autre adresse mail (reçu aujourd’hui )
    no-reply@woocommerce-client.com

  21. Ivan Vidaković Avatar
    Ivan Vidaković
  22. I got today 5 /5 /2025 at 16h04 : no-reply@news-woocommerce.com

  23. Brodie Avatar

    Hi
    Just to add to the list I received an email from:
    no-reply@support-woocommerce.com
    stating a critical vulnerability was detected on my website and to download the patch (which I didnt).
    Thx

  24. no-reply@woocommerce-client.com

    Here’s another one if you don’t have it.

  25. Stu S Avatar

    Hi, received an email today from no-reply@woocommerce-sec.com “We are contacting you about a critical security vulnerability reported in the WooCommerce platform on April 28, 2025”

    i’m upto date anyways

  26. Got this mail today from woocommerce-sec.com

  27. Just got one from woocommerce-mailer.com