Shopify marked fraudulent order as LOW RISK despite multiple failed payment attempts – has anyone else experienced this?

Hi everyone,

I’m looking for advice from other Shopify merchants after experiencing a fraudulent order that Shopify’s fraud analysis classified as LOW RISK.

We are a UK online retailer using Shopify Payments.

On 18 August, the customer attempted to make a purchase, but there were multiple unsuccessful/declined payment attempts.

On 19 August, a payment for £108.99 was successfully processed for two electrical products.

When we reviewed the order, Shopify classified it as LOW RISK. There was therefore nothing obvious from Shopify’s overall risk assessment telling us not to fulfil the order.

We dispatched the order using Royal Mail Tracked and have tracking information, delivery confirmation and photographic delivery evidence.

Several days later, we received a fraudulent transaction chargeback.

We challenged the chargeback and supplied our evidence, including proof of delivery. However, the cardholder’s bank rejected our dispute and confirmed that the genuine cardholder did not recognise the transaction. The bank also stated that the name, email address, billing address, shipping address and IP information associated with the transaction did not belong to their cardholder.

We have consequently lost the £108.99 transaction plus a £10 chargeback fee, despite fulfilling an order that Shopify had assessed as Low Risk.

I have since reported the incident to the police/fraud reporting service and have obtained a crime/report reference. I have also contacted Shopify Support about the case.

My main concern is prevention.

Looking back through the information available to us, there were warning signs — particularly the multiple payment attempts before the successful transaction — but the final successful order was nevertheless assessed as Low Risk.

I’d really appreciate hearing from other Shopify merchants:

  • Has anyone had a fraudulent chargeback where Shopify originally classified the order as Low Risk?

  • Do you manually investigate multiple failed payment attempts even when the eventual order is Low Risk?

  • Is there a Shopify Flow you’ve successfully used to detect multiple payment attempts/cards?

  • Do you use manual payment capture?

  • Are there any third-party fraud prevention or chargeback protection apps you would recommend?

  • Is there a way to automatically place an order on hold when several payment methods/cards have been attempted?

  • What additional checks do you now perform before dispatching higher-value orders?

I’m not looking to criticise the chargeback process or the genuine cardholder — I’m trying to understand how another small business can prevent this happening again when Shopify’s overall assessment tells the merchant that the order is Low Risk.

Any advice or experience from other UK Shopify merchants would be greatly appreciated.

Thanks.

Sorry you got hit with that. Low Risk is Shopify’s chargeback-risk recommendation from fraud analysis, not a promise the order is safe. The bank still decides the dispute. Shopify’s docs say they aren’t liable for chargebacks and they aren’t involved in the outcome.

Treat the recommendation and the indicators as two different things. On the order, open Order risk and read the full indicator list. Indicators include AVS, CVV, IP details, and whether the customer tried more than one credit card. Those indicators don’t score likelihood. The Low / Medium / High badge does. Multiple failed cards can show in the indicators even when the badge says Low Risk.

Practical native setup:

  1. Settings > Payments > Shopify Payments > Manage > Fraud prevention. You can decline charges that fail AVS postal code or CVV. AVS is off by default on Shopify Payments. Turning it on can also increase false declines.
  2. Switch credit card capture to manual so you can review Order risk before you capture and before you pick/pack.
  3. Shopify Flow with the Order risk analyzed trigger can tag, hold fulfillment, or cancel when risk is high.

Proof of delivery can still lose an unauthorized-use dispute. The durable fix is pausing fulfillment when the pre-order signals look off, not leaning on the Low Risk badge alone.

The thing that decided this was probably not the risk badge at all. It was whether the charge carried a 3D Secure authentication.

You are UK on Shopify Payments, so SCA applies. A payment successfully authenticated with 3DS gets a liability shift, and a fraudulent chargeback lands on the issuer instead of on you. The catch is you do not control when it happens. Shopify’s own PSD2 page says Shopify Payments only uses 3D Secure when the issuing bank requires it for the transaction to be authorized. A card the bank waves through without a challenge leaves you fully liable, and there is no setting to force it on.

So worth checking whether that specific order went through 3DS. If it did and you still lost a fraud dispute, that is worth taking back to support with the authentication data, because the shift should have applied.

If it did not, then your evidence lost because it answered a different question than the one being asked. On a fraud reason code the issuer wants to know whether the cardholder authorized the purchase. Tracking, delivery confirmation and a delivery photo prove a parcel arrived somewhere. None of that proves the cardholder ordered it. Under Visa Compelling Evidence 3.0 what actually wins is two earlier undisputed transactions from the same buyer, at least 120 days old and no older than 365, matching the disputed one on at least two data points, and one of those has to be IP address or device ID. A first time buyer has no such history, so that route does not exist, which is why a one off fraud order is close to unwinnable once it ships.

Since the goods went out to an address, did the billing address on the order match where you shipped it? That mismatch is usually the tell on this pattern, and it is also the thing that decides whether the AVS decline setting would have caught it.

The technical advice above is solid. Let me add a simpler checklist for merchants who don’t want to rely on automation alone.

Before shipping any order that feels slightly off, check these:

1. Billing vs shipping address If they don’t match or one looks suspicious (P.O. box, vacant address), pause and contact the customer.

2. Multiple failed payment attempts If you see 2+ failed attempts before a successful one, treat that as a red flag. Gotinker’s right even if the final badge is Low Risk, the history matters.

3. Email and phone – Does the email look real? Does the phone number work? A quick call to confirm the order can save a chargeback.

4. Order value vs typical order – Is this much higher than your usual order value? If so, extra scrutiny.

You don’t need to check every order just the ones that have one or more of these flags. For a £109 order, a 2-minute check could have saved you the chargeback.

One question: do you currently use a manual capture flow for higher-value orders? Or is everything automated?"

You are right to be frustrated. A “Low Risk” label naturally gives merchants confidence to fulfil, even though Shopify treats it only as a recommendation.

I would separate two questions here:

  1. Why did Shopify classify the order as Low Risk despite the failed attempts?

  2. Was there actually any evidence capable of winning this particular chargeback?

For an unauthorized-payment dispute, delivery photos and tracking normally prove only that the parcel arrived—not that the genuine cardholder placed the order. The important details are whether 3D Secure/SCA created a liability shift, the precise dispute reason and card network, the AVS/CVV results, whether different cards or identities were tried, and whether there was qualifying previous transaction history. The available evidence routes also differ between Visa and Mastercard.

If you can share redacted screenshots of the payment timeline, fraud indicators and dispute reason code, I’d be happy to look through them and tell you whether the case was realistically unwinnable or whether something important may have been missed. Just remove all customer, address and card information before posting.

Multiple declined attempts before a successful payment would make me uncomfortable relying only on the final “Low Risk” label. I’d preserve the failed-attempt timeline, delivery proof and subsequent chargeback together, because the sequence tells a much stronger story than any one signal.

Founder disclosure: I’m building VedaSuite for Shopify around this broader problem — connecting operational/customer signals and surfacing evidence-backed risks or losses that might otherwise stay hidden. Cases like yours are exactly why I think merchants need more context than a single risk score.

If useful, you can see what we’re building at vedasuite.in.

Automatic capture is just asking for trouble. You should have a workflow with order created trigger and have several conditions already in place before capture. You should add a workflow with order risk analyzed trigger too.

In the workflow you could possibly put a condition that looks at the actual assessment facts not the low,med,high. Something like order.risk.assessments.facts.description and includes There were

Since “There were” is only used in payment attempt counts, and doesn’t include 1 (There was), there shouldn’t be any false positives.

Then cancel. If capture is manual (or anytime after this) then you won’t incur a transaction fee either.

There are actually quite a lot of conditions you can set to cancel a suspicious order. There are a number of specific addresses and names associated with fraudulent orders, and it’s a good idea to protect yourself before you get hit by them. This forum is full of posts on this subject. Look through them and you’ll see some of the flows I’m talking about.

Yes I would add all of that. You can use Shopify Flow for that:

  • use the trigger “Order Created”
  • check billing & shipping address mismatch
  • check if customer order count is 0

I would then send an internal email to check it manual and hold the fulfillment not cancelling automatically.

But you could also automate that with (Disclaimer: I’ve built this app) FraudFalcon.

FraudFalcon does the same idea with a few conditions Flow does not have, like

  • past chargebacks on that customer
  • disposable email domains

And more. We can automatically not just cancel orders after it was done. But also at the checkout level.

In case you’re intersted: :slight_smile:

I’d stop treating the final Low Risk badge as the final decision and start flagging the pattern before that, because the repeated declines are often the real warning.

An easy way to do that is to set a manual review rule for orders where the same checkout session has multiple failed attempts. Then check a couple of extra things before capture or dispatch, like whether the billing country, shipping country, and IP line up, whether the email looks real, and whether the order is for a first-time customer buying higher-value items.

If you’re on Shopify Payments, I’d also look at whether the payment was 3D Secure authenticated, because that matters more than the fraud badge when you’re trying to understand who is likely to eat the loss.

If you want to automate part of it, I’d use Flow or a fraud app to tag orders with repeated declines so they land in a review queue instead of going straight out the door.

Hi,

Sorry you’ve been hit with this. The part of your experience that stands out to me is that the final Low Risk classification effectively gave you confidence to fulfil, despite there being other warning signs in the payment history.

A slightly different way of approaching this is to separate fraud detection from permission to fulfil.

If you don’t want Shopify’s Low/Medium/High classification to be the final decision, you can introduce a human approval step:

Order created → fulfilment held → someone reviews the order/customer/payment information → Approve or Reject → only approved orders are released

Full disclosure: I’m involved with SampleGuard, a paid Shopify app built around this approval-before-fulfilment workflow.

It isn’t a fraud-detection app and it wouldn’t have automatically identified the multiple failed card attempts in your example. The value here is giving you an additional human checkpoint before goods leave the business.

You can even configure all orders to require approval if your order volume makes that practical. That means every order gets human visibility before fulfilment, regardless of whether Shopify labels it Low, Medium or High Risk.

Alternatively, you can narrow the approval requirement using rules such as order value, specific products, customer tags, requester email/domain, discount codes, etc.

When an order needs approval, the approver automatically receives an email containing the approval request and can Approve or Reject with a single click directly from the email. They don’t need to log into Shopify Admin, and fulfilment remains held while the decision is outstanding.

So rather than trying to build a system that perfectly predicts every fraudulent transaction, another option is simply:

“For orders where the financial risk justifies it, a human must say yes before we ship.”

That obviously adds an operational step, so it won’t suit every merchant. But for higher-value orders, or lower-volume businesses where a chargeback is particularly painful, it can provide a useful additional safety net.

The Low Risk rating does not mean that the order is legitimate, so I would consider it just one signal rather than an approval to fulfill. Several declined attempts should certainly be added to your scrutiny list. Shopify Flow can be used to generate an internal notification or hold workflow when an order meets specific conditions related to the order or payment. For orders of higher value, apply include fraud analysis as well as AVS, CVV, billing and shipping address match and suspicious payment activity prior to shipment. You can also leverage manual capture to help investigate suspicius orders prior to charging the payment.