Guide
A woman makes an online purchase using a credit card on her laptop, browsing an online fashion store.
Photo: Antoni Shkraba

Five to fifteen abandoned checkouts appear each day. The customer identities look invented, every card is declined, and every attempt uses the same low-priced product. It is reasonable to suspect card testing: someone may be trying payment details to see which cards work. But a repeated product and a cluster of declines are clues, not proof of who is behind them or evidence that Shopify suddenly changed its checkout. The useful response is to inspect the payment events, check whether any orders succeeded, and tighten the controls available for your payment setup.

What this pattern could mean

Card testing involves repeated payment attempts to find cards that can be charged. Shopify describes attacks using automated scripts and many small transactions; they can produce declines and, sometimes, completed orders. Repeatedly selecting an inexpensive item fits that possible pattern, but it does not establish that the product caused the activity.

There is also a limit to what the abandoned-checkout list shows. Shopify says attempts it identifies as suspected card testing or bot activity are excluded from the ordinary list. A checkout that does appear there still needs examination: failed payments can result from a processor decline, incorrect card details, an address mismatch, a technical error, or failed authentication. The payment event tells you more than the daily count.

Inspect the checkout evidence first

In Shopify admin, open Orders → Abandoned checkouts. Review several examples and expand the payment events in each checkout’s Timeline. Compare their times, failure messages, products, amounts, and recurring customer details. Check the Blocked view as well; Shopify Payments can block a high-risk attempt before it becomes an order. Keep a few checkout IDs and timestamps for a support request, but do not post customer or payment information publicly.

Then look for completed orders matching the pattern. Review their fraud indicators before fulfillment. A successful suspicious payment needs a different response from a series of declines. If you use a payment provider other than Shopify Payments, compare its transaction records and ask what its decline and fraud signals show.

Reduce the risk without blocking everyone

If you use Shopify Payments, review Settings → Payments → Shopify Payments → Manage → Fraud prevention. Shopify provides automated settings and options concerning failed CVV and AVS postal-code checks. These checks have limits: not every issuing bank supports them, and stricter AVS declines may also reject legitimate transactions. Monitor real customer checkout problems after changing a setting.

Shopify also recommends reviewing fraud analysis, considering manual capture for high-risk orders, and using Shopify Flow to flag, hold, or cancel orders matching defined conditions. Its Fraud Control app offers checkout rules based on specific details. Start with a narrow pattern supported by your records. A blanket block on a country, a product price, or every customer with one failed payment can interfere with genuine sales; no single rule guarantees complete protection.

What may not solve it

Removing the repeatedly targeted product could interrupt the current sequence, but someone testing cards could choose another item. It would not explain what happened or protect future orders on its own.

Nor is every feature called “bot protection” intended for this problem. Shopify’s additional checkout bot protection is a Shopify Plus feature for limited-inventory sales, and Shopify says it is not designed to combat fraud associated with bot activity. Shopify also describes Cloudflare and hCaptcha protections already used on its platform.

Treat suspicious failed checkouts as an investigation, rather than an abandoned-cart marketing opportunity. Shopify says recovery emails are not sent when a payment processing error occurs or a high-risk payment is blocked. A reminder campaign does not resolve repeated payment abuse.

When to escalate

If attempts continue or matching orders succeed, contact Shopify Support and your payment provider where applicable. Bring a date range, representative checkout IDs, payment-event messages, the recurring product, and details of any completed orders or disputes. Ask which protections apply to your store and gateway, whether they can see the pattern in their records, and what targeted action they recommend.

The reported mid-February start does not establish a Shopify-wide change. The evidence supports a narrower conclusion: repeated declined attempts on one inexpensive item warrant a card-testing investigation. Inspect the records first, then measure whether your response reduces suspicious activity while allowing real customers to buy.

A.
Back to articles