The most dangerous fraud on Shopify doesn’t look like fraud. It looks like a regular order.
You process a $300 order for six items of the same product. Same address. Legitimate-looking name. Valid card. Ships out. Two weeks later, the cardholder files a dispute: “I didn’t authorize this.” Your payment processor sides with them, reverses the transaction, and charges you a $25 chargeback fee. You’ve lost the goods, lost the revenue, and paid for the privilege.
But here’s what nobody talks about: the fraud happened before the chargeback. It happened in the pattern of the order.
The Velocity Attack Framework
Fraud networks use a technique called velocity checking. They run hundreds or thousands of stolen cards through stores in a short window, usually with different quantities. The goal isn’t to buy something specific. The goal is to identify which cards still work.
A velocity attack might look like this: an order for 7 units on Monday, an order for 3 units on Tuesday from a different email address, an order for 12 units on Wednesday. Same IP address. Same shipping address or close to it. These aren’t real customers. These are cards being tested.
The card testers use unusual quantities deliberately. Real customers order normal amounts. An order for 47 units of a single product is a red flag. An order for 1 unit that costs $2 followed immediately by an order for 15 units that costs $400 is a test to see if the system flags it.
Most Shopify stores don’t detect this pattern until the chargebacks arrive weeks later. By then, they’ve already shipped goods, lost the merchandise, and paid fees. The fraud succeeded completely.
Card Testing and the Micro-Transaction Scam
Another fraud pattern is even simpler. A fraudster orders a single low-value item. A $1 digital product. A $3 t-shirt. They use a stolen card. The order processes. Most small transactions don’t trigger fraud detection because the amount is so low it seems impossible to be fraudulent.
If the transaction goes through, the fraudster knows the card works. They’ll try it again with a higher amount at another store. If the transaction gets declined, they just test the next card. They run hundreds of these micro-transactions per day across different stores.
Some fraud networks have operations that do nothing but micro-transactions. They build databases of working cards that they then sell to other criminals who use them for bigger purchases. A store might process 50 of these micro-transactions a day and think they’re just low-value orders. In reality, they’re feeding a fraud network that will use the validated cards to steal $50,000 from other merchants.
The Bulk Purchase Pattern
Fraud that targets high-value inventory has a specific signature: bulk orders of expensive items, usually the same product in different colors or sizes.
A fraudster orders 50 high-value items all at once or within a short window. They pick items that are easy to resell. Luxury goods, tech, designer brands. The goal is to receive the merchandise before the chargeback hits, then fence it quickly on a secondary market.
The order looks real because it is a real, successful transaction, at least initially. The card wasn’t declined. The address was valid. The payment processor approved it. But the cardholder never authorized it. When they see the charge, they dispute it immediately, and your store is left with a chargeback and no merchandise.
For high-value inventory, this is devastating. You might ship out $2,000 in merchandise to a fraudster, get the chargeback, pay the chargeback fee, and also lose the items because they’re already in secondary sales channels. You’ve given away inventory and paid for the privilege.
Why Order Limits Are Your First Line of Defense
This is where purchase limits become a fraud prevention tool, not just an inventory management tool.
If you limit orders to 3 units per customer per product, a bulk purchase fraud attempt becomes impossible. A fraudster trying to steal 50 units of a high-value item can’t do it in one order. They’d have to place 17 separate orders, which triggers velocity detection systems and increases the likelihood of getting caught.
If you limit orders to 1 unit per customer per product per day, you make card testing extremely difficult. A fraud network trying to test 1,000 cards would need 1,000 days to do it. They’d need 1,000 unique customer accounts, 1,000 unique IP addresses (or at least ones that don’t cluster), and sophisticated automation to coordinate all of it. Most fraud operations aren’t that sophisticated.
Limits don’t stop all fraud. But they move the fraud to another store. If it takes twice as much effort to run a scam against you as it takes to run it against a competitor with no limits, fraud networks just move to the competitor.
The Real Cost of a Chargeback
Most merchants calculate chargeback cost as the refund plus the fee. Refund the customer $300, pay a $25 chargeback fee, total cost is $325.
But the real cost is much higher. There’s the cost of shipping goods that never should have shipped. There’s the cost of the lost merchandise if it was fraud. There’s the opportunity cost of the capital tied up in those units.
There’s also the systemic cost. Every chargeback damages your payment processor relationship. If you have too many chargebacks relative to your transaction volume, your processor can restrict your account, hold your funds, or eventually terminate your account. Getting banned from payment processing is a death sentence for an ecommerce business.
Payment processors track chargeback ratios obsessively. Anything above 0.5 percent is concerning. Above 1 percent and you’re on a watch list. Above 2 percent and you get terminated. A 0.5 percent chargeback ratio on $1,000,000 in annual sales means 5 chargebacks per month. That’s only $6,000 in fraudulent orders, but it puts you in danger of losing your ability to process payments entirely.
There’s also labor cost. Every chargeback requires documentation, disputing, communication with the processor. A merchant might spend an hour per chargeback fighting it, and most of the time they lose anyway because the burden of proof is on them.
Specific Fraud Patterns to Watch For
If you’re selling physical goods on Shopify, these patterns should raise immediate red flags:
Multiple orders in rapid succession from the same or adjacent IP addresses. If you get 5 orders in 20 minutes from addresses that are geographically very close together, that’s testing behavior.
Orders for unusually large quantities of the same product. Real customers don’t order 100 pairs of shoes. Fraudsters do.
Orders that use new email addresses with suspicious patterns ([email protected] suggests automated account creation).
Orders from high-fraud countries with shipping to the USA or EU. This doesn’t mean you should block these countries, but it’s data to combine with other risk factors.
Mixed order values in a cluster. Three orders for $1.50, then one for $500, then another for $0.99. This is card testing.
Implementing Smart Limits
Most fraud prevention happens through payment processors and tools like Sift, Kount, or your processor’s built-in fraud tools. But order limits add a layer of friction that reduces fraud velocity.
Set reasonable per-customer limits based on your product value. For low-value items, a 10-per-day limit is fine. For high-value items, a 1 or 2-per-lifetime limit makes sense.
A tool like SmartOrderLimit lets you set limits per product, per variant, or even per customer per day. You can also set minimum orders to prevent the micro-transaction card testing attacks.
Combine limits with other fraud tools. Your processor’s built-in fraud detection handles most legitimate fraud detection. Order limits catch the patterns that slip through.
The Asymmetry of Fraud
The asymmetry of fraud is brutal. A fraudster spends 5 minutes placing an order. You spend an hour or more disputing the chargeback. The fraudster risks nothing. You risk your reputation, your payment processor account, and your capital.
The fraud that happens before the chargeback, the testing and the velocity attacks, is often invisible until the damage is done. By the time you see a pattern in your chargebacks, you’ve already lost hundreds or thousands of dollars.
Order limits don’t solve fraud. But they make your store less attractive as a target. They raise the cost of attempting fraud against you. They move the fraud to someone else’s store. That’s not perfect defense, but it’s better than being an easy target.