Carding Attack on Shopify: What to Do When Bots Hit First
Why High-Ticket Merchants Need to Understand Bot Traffic Before the Orders Arrive
One evening the analytics dashboard for eBike Generation lit up, thousands of sessions rolling in, traffic numbers that would normally mean a record sales day. But the purchases weren't coming. The visitors were from cities we'd never sold to, their time on page was measured in seconds, and the conversion rate was close to zero.
It looked like noise, so I went to bed.
The next morning, three orders had come through. Two of them were fraud. Two stolen cards. Two electric bikes we couldn't get back. Over two thousand dollars gone before the morning coffee.
That traffic spike wasn't a win. It was a warning I didn't know how to read yet.
What Is a Carding Attack?
A carding attack, sometimes called card testing or credit card stuffing, is when a fraudster uses automated bots to test a large list of stolen credit card numbers against a live payment system. The goal isn't always to buy something. Often the goal is simply to find out which cards are still active.
Here's the basic logic: when a card is stolen, the fraudster doesn't know its status. Has it been cancelled? Is the credit limit exhausted? Is it still active? Testing each card manually would take forever and raise immediate red flags. So they automate it. They send bots to ecommerce stores, either completing micro-transactions or just probing the checkout flow, to sort the working cards from the dead ones.
Your Shopify store, in this scenario, is being used as a tool. You didn't invite it. You may not even notice it until the damage is done.
The Traffic Pattern to Watch For
A carding attack leaves a specific fingerprint in your analytics. Once you've seen it, it's hard to miss.
Unusual session volume with near-zero conversion. Thousands of visits in a short window, far above your normal daily traffic, with almost nothing converting. Not a few percentage points down, we're talking conversion rates close to zero.
Unfamiliar geography. Sessions rolling in from cities, states, or countries you've never seen in your customer base. Not one or two, a concentration of traffic from unusual locations all arriving at the same time.
Extremely short time on page. Bots don't browse. They arrive, they hit the target endpoint, usually a product page or checkout, and they leave in seconds. Your average session duration will collapse.
No referral source or unusual referral patterns. Much of the bot traffic will appear as direct traffic or from unfamiliar referrers. It doesn't look like your organic traffic or paid campaigns.
Checkout activity without completion. In more sophisticated attacks, you may see unusually high checkout initiation rates with very low completion. The bots are probing the payment gateway without completing a purchase.
These signals don't guarantee a carding attack is underway, but when several of them appear together, in a tight time window, they deserve your attention before orders start arriving.
Why High-Ticket Shopify Stores Are Targeted
It's a reasonable question. If fraudsters are just testing cards, why not use a store selling five-dollar items?
The answer is that card testing and fraud go hand in hand. Once a fraudster confirms a card is active, the next step is often to use it, and high-ticket stores are exactly where they want to spend stolen credit. A single successful transaction on a $2,000 electric bike, a $1,500 piece of fitness equipment, or a $3,000 watch is worth far more than dozens of small purchases.
High-ticket merchants are doubly exposed. First as the testing ground. Then as the target.
There's also a secondary factor. Many high-ticket Shopify stores don't have the same fraud infrastructure as large retailers. Fraudsters know this. A mid-size store with average order values in the thousands is attractive because the reward is high and the defenses are often lighter.
What Happens If You Don't Catch It
The session spike comes and goes. You might dismiss it as a traffic anomaly. Then, one or two or three orders arrive that look mostly normal on the surface. A name, an address, a card that cleared. Shopify gave it a green score or a cautious amber. The order sits in your queue.
You ship it.
A few days later, or a few weeks later, the true cardholder notices the charge and files a dispute. You've lost the product. You've lost the shipping cost. You'll pay a chargeback fee. And if your chargeback rate climbs high enough, your payment processor will take notice.
A single fraudulent order on a high-ticket item can erase the margin from ten or twenty legitimate sales. In a business where you're doing a few hundred orders a month, that's not a rounding error. That's a real hit to your bottom line.
What to Do When You See the Pattern
Don't panic, but don't ignore it. A surge in sessions without sales is worth ten minutes of your time before orders start arriving.
Check your analytics immediately. Pull session data by geography, traffic source, and average time on page. If you see the combination described above, assume you're in or near a carding event.
Review orders placed in the window. Any orders that arrived during or shortly after the traffic spike deserve a closer look before they ship. This isn't about cancelling everything, it's about applying more scrutiny to a specific set of transactions.
Look beyond the Shopify risk score. Shopify's built-in fraud analysis will give you a color and a score. That score is a starting point, not a verdict. An order that came in during a confirmed bot traffic window needs more than a green light from a risk algorithm to earn your confidence.
Look for the full picture behind the transaction. This means checking the shipping address against known fraud databases. It means looking at the email address, how old is it, does it have a history, does it match the name on the card? It means reviewing the IP address against the billing address. No single signal tells you whether to ship. The whole story does.
Consider temporary rate limiting or checkout protection. If you're in the middle of an active attack, your developer or a Shopify app like Recharge or a bot-protection tool can help throttle bot traffic to your checkout. This won't catch orders already in your queue, but it can limit new testing activity.
After the Attack: What to Document
If you suspect a carding attack resulted in fraudulent orders, even if you caught them before shipping, document everything.
Keep records of the traffic anomaly, the order details, the IP addresses, the billing and shipping information, and any notes on why the order was flagged. If a chargeback later follows on an order you did ship, this documentation becomes your evidence for a dispute response.
A well-documented chargeback dispute, one that shows you performed due diligence and had legitimate reason to fulfill the order, gives you a fighting chance with your payment processor and the card networks. A bare transaction record with nothing behind it almost never wins.
The Bigger Picture
Carding attacks are not rare. They happen to stores of all sizes, across every product category. But high-ticket merchants feel them more acutely because each compromised order carries more weight.
The stores that get through these events without serious loss are not necessarily the ones with the most sophisticated technology. They're the ones that pay attention to signals other merchants dismiss as background noise, that take a few minutes to look at the orders that arrived during an unusual traffic window, and that understand what a fraud score is actually telling them, and what it isn't.
A green checkmark from Shopify doesn't mean the order is clean. It means the order passed the checks Shopify ran. That's a different thing.
If you want to know what's actually behind an order before it ships, the investigation has to go deeper than the score. That's exactly what FRIQ Labs does, and why merchants who sell expensive products shouldn't rely on a single data point to make a decision that could cost them thousands.
John Murphy is the founder of FRIQ Labs, a done-for-you fraud prevention service for high-ticket Shopify merchants. FRIQ investigates approximately $1 million in orders every month, catching confirmed fraud before shipment and identifying legitimate orders that standard systems would have blocked.
Learn more at FRIQLabs.com