REDDIT 原始帖子

Someone has a bot "sitting" on my website and placing orders, what to do?

I have a relatively new Shopify store (about two weeks old) using Authorize.net as the payment processor. Everything was running smoothly until yesterday. Around 9:00 AM, orders started coming in nonstop—literally one every 3–5 seconds. I received around 500…

原帖正文r/shopify

I have a relatively new Shopify store (about two weeks old) using Authorize.net as the payment processor. Everything was running smoothly until yesterday. Around 9:00 AM, orders started coming in nonstop—literally one every 3–5 seconds. I received around 500 orders before I had to make the store private just to stop the attack. It appears to be a bot placing orders with fake addresses and fake or stolen credit cards. Has anyone experienced something like this? Is this a known issue with Shopify? I recently migrated the store from BigCommerce, where it had been running for eight years without anything like this ever happening. I discovered that requiring customers to create an account before checking out completely stops the bot. The problem is that I don't want to force account creation, since many legitimate customers prefer to check out as guests and might abandon their purchase if they're required to sign up. Today I turned guest checkout back on, and within less than two minutes, the bot started placing orders again. Has anyone found a good solution that stops these bot orders without requiring customer accounts? Is this some kind of a "protection" service where you have to pay the bot creator to stop doing it ? I have been getting 5-8 spam emails on a daily basis asking me question about the website. something like "who is managing this store" "is there anyone available regarding this store ?" "can i purchase with confidence ? " hello " "can i show you something you may find useful ? " this is so wild

已收录讨论

25 条评论

u/HedgehogNOWOP

thank you for the information. unfortunately the captcha is a feature available only for the Plus plan, which is $400 / month. i am on the "grow" plan, and don't have the feature available to me. also searched "Fraud Filter " in the app store, and found similar named apps, but not an "official app" ? is there a direct link you could share ?

u/HedgehogNOWOP

ok i think i found that app https://apps.shopify.com/fraud-control

u/Plastic_Stable8927

I know, did the bot follow them over here too? lol

u/_kashew_12

Do you have captchas enabled in your checkout? Looks like Shopify has that feature to prevent these bot attacks.

u/HedgehogNOWOP

It's only for the Plus plan, which is $400/month

u/VillageHomeF

have not heard of 500 orders in a day from a bot. that's awful. make sure you are set to manually accept the funds so you don't have to refund all the money and lost the payment processing fees.

u/wilkobecks

As a start, turn payment capture to "manuali" or "capture on fulfillment". This will prevent you from having to do refunds and losing the fees. You can have flow look at each order and either a) capture funds if it is a good order b) cancel the order if fraudulent. (They may stop testing in your store if they are unable to successfully test cards)

u/marauders56

Utilize Cloudflare to help mitigate once you've identified the problem actors. Read: https://community.shopify.com/t/how-can-i-add-captcha-to-my-checkout-to-prevent-bot-attacks/6433

u/hundaddyd

I am having a similar problem. One day, about 50 orders came in that were high risk. I also use authorize.net. Any update on the possible resolution?

u/Ok-Avocado-57

That sounds awful! Can Shopify not do anything? I feel like it should be their responsibility to ensure their platform is safe and secure.

u/shithappenswhy

That sounds more like a card testing attack than a Shopify issue. I'd enable Shopify's bot protection/CAPTCHA, add fraud filtering, and contact your payment processor (Authorize.net) since they may have additional fraud prevention rules you can enable.

u/xtarga

Welcome to the world of carding attacks. It is very common. I am not on shopify so the protections we put in place are different and may not be applicable, but IP and behavioral based throttling (same IP hitting checkout multiple times in a row, someone creating a cart and immediately checking out within 30 secs etc) or installing a fraud protection layer between you and gateway, because if it gets large enough not only you are dealing with losses from fraud, your gateway will place pressure on you to fix it.

u/lespooner

I am working on a unique bot solution for the App Store currently. I would love to hear more about your problem, my app might be a unique solution from what’s available to combat the problem. It’s not live yet but hoping to launch in the next couple weeks.

u/felixding

This sounds like card testing. If they’re buying cheap items every few seconds, they may be using your checkout to test stolen cards. I’d check Authorize.net fraud settings first: AVS/CVV mismatch rules, velocity limits, transaction limits, and maybe a minimum order amount. Also, did all the orders target the same low-priced SKU? Besides, try to turn on manual payment capture temporarily (Settings → Payments → Payment capture method → Manually → Save).

u/Background_Bid_6726

Remove the item from your store or make it very expensive and turn on manual capture for payments

u/HolyLiaison

Have you tried using the Flow app to block (or limit) the bots from ordering?

u/luanfernandes

I have a client who had the same issue, Authorize.net but on Woocommerce. What it solved for her is blocking the attack on cloudflare by creating a custom set of rules that block the bot. It's been 2 weeks without an attack so I think it worked

u/davidmansaray

Yes — treat this as an active fraud burst first, then work backwards from the evidence. Keep the store locked or private for now, and in Shopify export the affected orders so you can spot repeated names, shipping details, IP patterns if available, and the exact timing of the burst. In Authorize.net, check gateway logs for whether these were authorisations, declines, AVS or CVV failures, or actual captures; that will tell you whether you are dealing with payment testing or just noisy order attempts. I’ve seen this sort of thing overwhelm a fresh store before, and the fastest wins are usually to reduce how much can be completed automatically and to stop the repeat pattern. Review any recent app installs, checkout setting changes, and admin access, then put every suspicious order through manual review before fulfilment. If you can, also note whether the same browser fingerprint or user agent keeps appearing. Once the immediate fire is out, the next step is prevention: tighter fraud screening, address verification, and any storefront bot protection your plan already supports. The key is to separate real card activity from automated checkout noise before you start refunding or cancelling everything blindly.

u/whooooosah

I had a similar problem, but it was 40 orders total within a couple days. I found someone on Reddit say to enable requiring customers to sign in before checkout. Shopify has a message that says it’s discouraged because customers won’t wanna checkout, but since I enabled it, I haven’t had this problem going on 3 months now

u/[deleted]

这条评论已被删除。

u/[deleted]

这条评论已被删除。

u/[deleted]

这条评论已被删除。

u/[deleted]

这条评论已被删除。

u/[deleted]

这条评论已被删除。