Card Testing Bot Attack Flooding Our Store With Hundreds of Fake Abandoned Checkouts – No Way to Remove Them

Shopify Platform Failure: Card Testing Bot Attack Flooding Our Store With Fake Abandoned Checkouts

We are currently experiencing a serious platform issue on Shopify that is actively damaging our business operations.

A card testing bot attack is generating hundreds of fraudulent abandoned checkouts every day, and Shopify currently provides no way to remove them from the system.

This has made our abandoned checkout data essentially unusable.

What Is Happening

Bots are targeting our store to test stolen credit cards.

The attack pattern is consistent:

• Bots create new customer accounts with different email addresses each time
• They target newly added $5 products
• They rapidly create checkouts and abandon them
• This repeats hundreds of times per day

Each attempt creates a permanent abandoned checkout record in Shopify.

Shopify’s Security Is Not Stopping It

We have already enabled every recommended Shopify protection, including:

• Google reCAPTCHA
• Shopify fraud detection
• Shopify Flow automation

Yet the bots still reach the checkout stage.

Fraud detection only flags completed fraudulent orders, but it does nothing to stop checkout creation.

The Biggest Problem: Shopify Won’t Let Merchants Delete Abandoned Checkouts

Even when these are clearly bot-generated, Shopify provides no way to remove them.

Not through:

• Shopify Flow
• Admin tools
• API access

This means hundreds of fraudulent records remain permanently in the system.

The Business Impact

This attack is creating serious operational problems:

• Hundreds of fake abandoned checkouts polluting our data
• Legitimate abandoned carts buried in bot noise
• Staff forced to manually sort through bot activity
• Abandoned cart recovery becoming unreliable

For a platform we pay significant monthly fees for, basic bot protection should prevent this from happening.

What Shopify Needs to Fix

At minimum, Shopify should immediately provide:

  1. Server-side bot blocking for high-frequency checkout attempts

  2. The ability for merchants to delete abandoned checkout records

  3. Stronger checkout verification before abandoned checkouts are created

Right now, merchants are paying for a platform that allows bots to generate unlimited fake checkout records with no cleanup tools.

This Needs an Engineering-Level Fix

This is not a store configuration issue.

This is a platform vulnerability.

Until Shopify addresses it, merchants remain exposed to card testing bot attacks that corrupt critical store data and waste operational time.

We hope Shopify engineering takes this issue seriously and implements a solution quickly.

welcome to the club, bots have been testing cards on my site daily since june 2025

Obviously it’s not really a problem for Shopify as a company. The more fraud that happens, the more fees they collect. The more you shell out for apps, the more fees they collect. To help you sort it out would severely hurt the bottom dollar.

Have you checked to see where your bot traffic is originating from? (IP Address?)

I don’t have a Shopify store, but I regularly check my GA to see where I am getting traffic from. I have seen an uptick from Nigeria. I also see they are trying to use Social Logins to access my site. Facebook flags it, and requests a user data delete.

Transactional data (even abandoned ones) is generally immutable for audit, compliance, and security forensics. Instead of a delete button that which could allow malicious actors to hide their tracks or disrupt accounting; try the industry standard is to provide robust filtering, tagging, or archiving tools to separate clean data from bot noise. Native e-commerce tools are rarely sufficient against sophisticated, distributed botnets. You need to look into necessity of routing traffic through a dedicated WAF like Cloudflare, or integrating specialised bot-management software.

Worth_Analyst already pointed at the right path (you can’t delete these, so filter and tag), and I won’t rehash that. But two specifics about your pattern jumped out that I think are worth adding.

The card testers targeting your newly-added $5 products is a pretty tight signature to work with. Card testing bots hit cheap skus because small amounts clear issuer fraud checks at a higher rate, and all they need is a successful authorization to confirm the card is valid (the product doesn’t really matter to them). Newly-listed ones get picked up pretty
fast once they go live, which is why the attack tracks new additions. The flipside is that checkouts hitting that newly-added sku, each with a fresh email address, at hundreds per day, is about as clean a fingerprint as you’ll get. Which means you can probably automate most of the cleanup instead of trying to do it by hand.

You’ve got Flow running, which can tag matching customers for visibility in Shopify itself, but most of the real cleanup can happen downstream in your abandoned cart flow. Most ESPs (klaviyo, mailchimp, omnisend, etc.) get enough checkout data from Shopify to filter: if the customer is brand-new, the cart hits your targeted sku, and the total is low, skip
the send. That gets the pollution out of your email platform and stops it from tanking your sender reputation. Set it once, leave it alone. Won’t catch every single one, but on a signature this tight it catches most.

The other angle worth looking at… the card testing side has a risk that goes past analytics. If your processor sees a high rate of failed authorizations from similar signatures, there’s real exposure around account-level flags or chargeback rate, especially if any of the testers eventually succeed and the real cardholder disputes later. Worth knowing it’s
in the picture even if the analytics cleanup is the more visible pain.

Happy to compare notes if you want another set of eyes on the signature… always useful to see what different merchants are actually running into.

Thanks,
Jason

I have spent hours, days, thousands of dollars trying to dix this issie, every app, even cloudfare, hired developers to try and help me and still i cant fix this problem. it’s appalling that Shopify havent fixed this, shopify needs to apply stricter fraud filters, and monitor abuse patters at platform level, they need to be offering more protections.

Hi @David_Customer_Servi and everyone else in this thread,

I’m Simon, a Product Manager on the Checkout team.

Thanks for raising this. We know fake abandoned checkouts caused by bots can be disruptive. To address this, we’re continuing to strengthen our bot protections to reduce this activity at the source, rather than relying on removing these records manually. We recently rolled out additional measures that should help reduce the number of fake abandoned carts.

If you’re still seeing a high volume of suspicious abandoned checkouts, please contact Shopify Support and include your store URL along with examples from a recent timeframe so the team can investigate those sessions more closely.

Your claim doesn’t hold up for our store — abandoned checkouts have actually increased 18.4% in the most recent 4 weeks vs. the prior period. Shopify is full of double talk and bul.

Hitting me hard this morning. hundreds of accounts and abandoned checkouts, luckily none are going through.

Same fight here, and your breakdown is the clearest one in this thread. The point that fraud detection only flags completed orders while doing nothing to stop checkout creation is exactly the gap.

I saw Simon’s reply about strengthening bot protection “at the source,” but the +18.4% over four weeks you posted says it isn’t landing on the ground yet. Cindy spending thousands on apps, Cloudflare and hired developers with no fix says the same thing.

I’m digging into this specific problem seriously right now, and I’m not selling anything. One genuine question, to size how bad it really is: what is this actually costing you per month? Ad budget spent on poisoned retargeting audiences, processor or chargeback exposure, email deliverability, staff hours spent cleaning data.

And what have you already tried or paid to stop it?

Trying to understand the real cost for stores in your situation. Happy to compare notes.

The part that traps most people here is that this specific attack hits the checkout URL directly, and Shopify doesn’t let apps run on the checkout page (unless you’re on Plus with checkout extensibility). So an app that blocks by IP or country at the storefront level won’t catch a bot that never touches your storefront. That’s why the usual ““install a blocker”” advice often disappoints for card testing specifically.

Two things actually move the needle:

First, switch your payment capture to manual if it isn’t already (Settings > Payments > Manual capture). Card testers want an instant authorization signal. When capture is manual, you can void anything suspicious before money moves, and it takes a lot of the value out of hitting you.

Second, if you can put Cloudflare (or another WAF) in front of your domain, that’s the only layer that sees the request before it reaches Shopify, so it can rate-limit or challenge the checkout endpoint. On non-Plus plans this is the realistic ceiling for direct-to-checkout bots.

For cleaning up the fake abandoned checkouts already in your admin, there’s no bulk delete natively. A Shopify Flow workflow that tags/archives checkouts matching the bot pattern (same name, failed payment, no line-item history) is the least painful route.

If alongside this you’re also seeing fake accounts and storefront-level junk, a fraud/IP app like Blockify can handle the country/IP/VPN side and keep analytics cleaner, but I’d be honest that for the direct-checkout card testing itself, the WAF + manual capture combo is what stops it. Set expectations there so you don’t burn time on the wrong layer.

Well whatever they are doing is certainly not working. It’s gotten worse than ever before this week. I’ve had nearly 10 fraudulent orders come through this week alone by the bots. Before this week, I had maybe 2-3 over all time. Most weren’t even marked as having risk.

Same! This past week has been insane! They are more successful than ever, and most aren’t even marked as having any risk!

Hi all,

Most apps built to stop bots work at the browser level, they can’t detect the majority of bots which hit the cart URL directly. There is a new app on the Shopify app store called CartWatch which was built to detect these kinds of bots and removes them from connected abandoned cart email providers like Klaviyo and also provides clean abandoned cart lists / analyitics with the bot noise removed. Has anyone tried this yet?

The card testing bot attacks are getting more sophisticated and I have 100s of orders that are flagged as “Low Risk” that are definitely card attack orders.

Problem here is an invalid email address should at the very least be classified is medium risk.

I sell digital products. People expect to get this straight away. Setting a manual payment capture is going to cause a major problem for me especially for orders coming through in the middle of the night.

As a store owner I am penalised $25 per chargeback on a digital product that cost $2 while Shopify makes a profit for each of these and pays no penalty.

The solution is simple verify that the email is valid at minimum and work with the store owners that have the data with urgency.

Shopify has the data of 100000s of credit card details that have been potentially compromised. But nothing gets done until the credit card holder calls the bank.

@David_Customer_Servi Your description makes this sound like more than an ordinary analytics problem. Hundreds of fake abandoned checkouts per day can create separate costs in fraud review, payment operations, reporting, and manual cleanup.

One way to make the impact easier to compare is to separate it into:

  • staff time spent reviewing or cleaning records
  • payment-provider warnings, restrictions, or chargeback work
  • abandoned-checkout and conversion reporting becoming unreliable
  • email or customer-profile pollution
  • legitimate customers being blocked by attempted countermeasures

Without sharing customer or payment data, which of these is currently the largest cost for your business?

Approximately how many staff hours does the problem consume each week, and would a useful first step need to prevent every fake checkout, or would reliably detecting and separating them from legitimate customers already have value?

I’m researching the operational workflow around this problem and do not have a finished product to promote.

The worst part is there’s no way to delete abandoned checkouts, no API for it either, so the list stays polluted long after the attack stops. What makes them easy to spot: they rotate emails (often real, stolen ones) but keep reusing the same shipping address.

I’m the developer of a cart recovery app (Efsun) and ended up building that exact check into it. It flags them, hides them from the list and skips them in automation. Doesn’t stop the attack itself, but switching to three-page checkout and unpublishing $0/gift card products cuts most of the volume at the source.

Hi @Maxineholder
CartWatch was designed to deal with this problem of bot attacks - every spam order gets a medium or high risk classification and you can use Shopify Flow to only auto capture Low - Risk orders.

Alternately if you want to handle this yourself, why don’t you turn off auto capture and set it up that the customers receive the product immediately regardless of payment capture? Why does the customer receiving the digital product have to be dependent on payment capture?

Yeah, this is one of the nastier parts of card testing on Shopify. Once they start hammering checkout, the abandoned checkout list becomes basically unusable, and as you mentioned there isn’t really a clean way to bulk-remove that history afterward.

I’ve been working on this problem from the prevention side with Blockio. Instead of trying to clean up the fake checkouts after the fact, we try to identify suspicious traffic before it gets that far, repeated attempts, bad IPs, VPN/proxy traffic, bot-like patterns, etc. and block or challenge it early.

It’s definitely not a magic “stop every card tester” button, since attackers rotate IPs/devices pretty aggressively, but cutting them off upstream seems much more effective than dealing with hundreds of abandoned checkouts afterward.

Happy to share what patterns we’ve been seeing if useful.