Why a “Low Risk” Shopify Order Can Still Be Fraud
One of the easiest mistakes a Shopify merchant can make is assuming that a low-risk order is a safe order.
I understand why it happens.
You open the order in Shopify, look at the fraud analysis, and see that reassuring green indicator. The billing address looks fine. The payment went through. Nothing immediately jumps out as suspicious.
So the order gets shipped.
A few weeks later, a chargeback appears. The cardholder claims they never authorized the purchase, and suddenly that low-risk order does not look so safe anymore.
This happens more often than many store owners realise.
Low risk does not mean no risk
Shopify’s fraud analysis is useful. It checks a number of signals and helps merchants identify orders that may need additional attention.
The problem is not the tool itself. The problem is how merchants interpret the result.
A low-risk result is not a guarantee that the person placing the order is the legitimate cardholder. It simply means the information Shopify reviewed did not trigger enough concern for the order to be marked as medium or high risk.
There is a big difference between those two things.
Fraudsters are not always careless. Many fraudulent orders are designed to look completely normal.
The fraudster may have the cardholder’s full name, billing address, telephone number and other personal information. They may place the order from the same country as the cardholder. They may even use an IP address that appears close to the billing address.
When enough of the information matches, an automated system may see very little reason to flag the order.
That does not mean the person behind the screen is genuine.
My first ecommerce sale was fraudulent
I learned this lesson very early.
When I launched eBike Generation, my first sale turned out to be fraud.
That was not exactly the start I had imagined.
As the store grew, so did the value of the orders. We were selling expensive electric bikes, often worth several thousand dollars. One fraudulent order could wipe out the profit from several legitimate sales.
Like most store owners, I initially relied heavily on the fraud tools available to me. I used several well-known fraud prevention providers over the years and spent thousands of dollars per month trying to protect the business.
The tools were helpful, but I kept running into the same problem.
They gave me a score or a recommendation, but they did not always explain the full story behind the order.
An order could be approved even though something did not make sense. Another order could be rejected even though there was a perfectly reasonable explanation for the unusual information.
Eventually, we started carrying out our own manual investigations.
That changed everything.
Automated systems can only assess the information they receive
Fraud detection systems look for patterns and inconsistencies.
They may check whether the billing address matches the card details, whether the IP address is in the correct country, whether the customer used a proxy, or whether several payment attempts were made.
These are all useful signals.
The difficulty is that a well-prepared fraudster may avoid many of the obvious warning signs.
They may use the correct billing address.
They may use a clean residential IP address.
They may enter the genuine cardholder’s telephone number.
They may place a single order without making several failed payment attempts.
They may choose ordinary shipping rather than asking for rush delivery.
On the surface, the transaction can look completely normal.
An automated system cannot always understand the relationships between the people, addresses and contact details involved.
That is often where the real answer is found.
A real identity does not always mean a real customer
This is one of the most important things I have learned from reviewing high-ticket orders.
Confirming that a person exists is not the same as confirming that they placed the order.
A name may belong to a real person.
The billing address may be their real home.
The telephone number may genuinely be connected to them.
The email address may even contain their name.
None of that proves they are the person sitting at the computer.
If someone has gained access to the customer’s personal and payment information, they can create an order that looks very convincing.
This is why simply verifying one or two pieces of information is not enough.
The details need to connect in a way that makes sense.
The shipping address often tells the real story
In many fraudulent orders, the billing information looks perfect because the fraudster is using the genuine cardholder’s details.
The shipping address is usually where the merchandise needs to be redirected.
Sometimes the shipping address belongs to a relative, a workplace, a holiday property or a recently purchased home. Those can all be legitimate explanations.
Other times, the address is connected to someone with no visible relationship to the customer.
It might be a freight forwarder, a vacant property, a short-term rental, a commercial mail receiving location or an address associated with several unrelated names.
A mismatch does not automatically mean fraud. Plenty of honest customers ship purchases somewhere other than their billing address.
The important question is whether there is a reasonable connection.
Can the customer be linked to the address?
Is the property owned by a family member?
Did the customer recently move?
Is it a business address connected to their employer?
Is the order being sent to a second home?
These details provide context that a basic risk score may not capture.
Fraud does not always look urgent or suspicious
People often expect fraudulent orders to have obvious warning signs.
They imagine a fraudster placing a huge order in the middle of the night, using an overseas IP address, trying several cards and demanding next-day delivery.
That certainly happens.
But many fraudulent orders are much quieter.
The order value may be typical for the store.
The customer may choose standard delivery.
The email address may look normal.
The fraudster may answer the phone calmly and confidently.
They may know enough about the cardholder to pass basic verification questions.
Some fraudulent orders look safer than legitimate ones because the person placing them has made a deliberate effort to avoid attention.
That is why relying on appearance alone can be dangerous.
Low-risk orders can still lead to fraud chargebacks
A fraud chargeback is based on the cardholder disputing the transaction, not on the risk rating the merchant saw when the order was placed.
The bank does not treat the Shopify risk indicator as proof that the customer authorized the purchase.
From the merchant’s point of view, this can feel incredibly frustrating.
You accepted the payment.
The order was marked low risk.
The product was delivered.
You may even have a signature.
Then the cardholder claims they did not place the order, and the money is removed from your account.
Delivery confirmation can help during a chargeback dispute, but it does not always prove that the cardholder authorized the transaction. It may only prove that the package reached the shipping address.
If the shipping address was controlled by the fraudster, that evidence may not be enough.
High-ticket merchants have more to lose
For a store selling inexpensive products, accepting a small percentage of fraud may be treated as a cost of doing business.
High-ticket merchants do not have the same margin for error.
Losing a $40 order is painful.
Losing a $4,000 order is a serious problem.
The merchant does not only lose the product. There may also be shipping costs, payment fees, chargeback fees, advertising costs and staff time involved.
Replacing the profit from one large fraudulent order could require several additional legitimate sales.
This is why high-ticket merchants cannot treat a low-risk label as the final decision.
The value of the order has to influence the level of verification.
The more money at risk, the more confidence you should have before shipping.
What should you check before shipping?
You do not need to treat every customer like a criminal.
You do need to make sure the order tells a consistent story.
Start by looking at the customer’s identity, phone number, email address, billing address, shipping address and IP information.
Do the details connect?
Does the customer have a reasonable relationship with the shipping address?
Does the phone number belong to the person named on the order?
Has the email address existed long enough to be credible?
Does the IP location make sense when compared with the other information?
Are there signs that a VPN, proxy or hosting provider was used?
Has the customer provided conflicting information?
One unusual detail may have a simple explanation.
Several unrelated inconsistencies are more concerning.
The goal is not to find a perfect order. Very few orders are perfect.
The goal is to understand whether the person, payment and delivery information fit together.
Speaking to the customer can help, but it is not enough
Calling the customer is sometimes a useful part of the review process.
A genuine customer can often clear up an address mismatch or unusual order very quickly.
However, a successful phone call should not automatically clear the order.
Fraudsters can answer phones too.
They may sound confident. They may have researched the cardholder. They may know exactly what was ordered and where it is being delivered.
The conversation should be considered alongside the rest of the evidence.
It is one piece of the review, not the entire review.
Automated tools and manual reviews serve different purposes
I do not believe merchants should ignore automated fraud tools.
They are useful for identifying patterns, gathering data and pointing out obvious warning signs.
The problem begins when the automated result is treated as the final answer.
Software can tell you that two addresses are different.
A manual review may explain why they are different.
Software can tell you that an IP address is hundreds of miles from the billing address.
A manual review may discover that the customer is travelling, recently moved or is placing the order from work.
Software can confirm that a telephone number is valid.
A manual review may find that it belongs to somebody completely unrelated to the customer.
The strongest fraud prevention process combines data with context.
Do not ship based on the color of an indicator
The green low-risk indicator can provide reassurance, but it should never replace judgement.
Most low-risk orders will be legitimate.
The issue is that some will not be, and those are often the orders that catch merchants by surprise.
Before shipping an expensive product, ask whether you understand who the customer is, how they are connected to the payment details and why the order is being delivered to that address.
When the value of the order is high, it is worth taking a few extra minutes to find the answers.
That is the work we now do at FRIQ Labs.
We review the information behind each order, investigate the connections and provide merchants with a clear recommendation before the product leaves their warehouse.
Because low risk is helpful information.
It is not proof.