Seeing the same.
We have only received one report so far, and the merchant was unconvinced. That said, the email was convincing and the timing overlaps with dot-dev and hackdays.
I find this alarming enough to put a banner on our homepage saying “we will never email you from a gmail account”. I recommend other theme developers do the same, at least until Monday.
This is what the phishing emails look like:
There is no “Samuel A” at Groupthought.
I am not sure what the goal these phishing attacks are trying to achieve once they get access to a merchant store.
