Reviewing orders with fraud analysis
You can use fraud analysis to identify orders that can be fraudulent and review them in your Shopify admin before you fulfill them. Review high-risk orders to avoid potential chargebacks. Fulfilling high-risk orders can result in a higher number of chargebacks, which can result in disabling payment processing and removal from Shopify Payments.
Credit card companies can reverse funds for stolen cards after orders are fulfilled. You can gather evidence for any disputed charges. However, the decision to reverse funds is made by the bank that issued the credit card, not by Shopify. Shopify does not cover charge reversals from banks.
On this page
Considerations for using fraud analysis
Before you use fraud analysis, review the following considerations:
- Fraud indicators and support for third-party fraud prevention apps are available on the Basic plan or higher.
- Fraud recommendations are available on the Grow plan or higher, or if you use Shopify Payments.
- Fraud analysis works with online credit card orders that Shopify can verify.
- Shopify Payments can block some high-risk checkout attempts before an order is created.
- Some orders don't receive a fraud recommendation, including test orders, free orders, orders paid in full with a gift card, Point of Sale orders, B2B orders, and subscription renewal orders. You can still simulate a fraud recommendation on a test order.
- If you use a third-party payment processor, then check with them about any fraud analysis limitations.
Understanding fraud analysis
For each order, fraud analysis provides both fraud indicators and a fraud recommendation. Use the fraud indicators to investigate the order yourself. Use the fraud recommendation to check the order's overall risk.
Fraud indicators
Fraud indicators are individual details about an order, such as address and payment checks.
The fraud indicators can be used to investigate an order that you think might be fraudulent. The fraud indicators can include information such as:
- whether the credit card used for the order passes AVS checks
- whether the customer provided the correct CVV code
- details about the IP address used to place the order
- whether the customer tried to use more than one credit card.
The full analysis for an order groups the fraud indicators under the following headings to help you highlight different behavior types:
- High risk signals display information about the order that usually happens with fraudulent orders.
- Low risk signals display information about the order that usually happens with legitimate orders.
- Other details give you additional information about the order that can be useful, such as the IP address that the order was placed from. If the IP address is the only additional information for an order, then it displays as a separate line below the other signals.
If all of an order's fraud indicators belong to the same group, then the fraud indicators are listed without a heading.
High risk signals and Low risk signals are groups of fraud indicators, not the order's overall risk level. Each fraud indicator points to one detail about the order, such as an address or payment check. For the order's overall risk, which is based on all of these details, review its fraud recommendation.
Fraud analysis recommendations
Fraud analysis provides a fraud recommendation for all online credit card orders. The fraud recommendation indicates whether an order has a low, medium, or high risk of a chargeback due to fraud. If an order has a medium or high risk, then it's flagged on the Orders page with a warning symbol next to the order number. Flagged orders are also highlighted in order notification emails when you subscribe to them.
Fraud recommendations are powered by machine learning algorithms that are trained on historical transactions across all Shopify stores. These algorithms are continuously improved to better identify fraudulent orders.
If an order is at a high risk of fraud, then you can attempt to verify the order, cancel the order, or refund the order.
Blocked high-risk checkout attempts
Shopify Payments can block some high-risk checkout attempts before an order is created. These checkout attempts don't become orders, so they don't have an order fraud recommendation.
You can review blocked checkout attempts in the Blocked view of Orders > Abandoned checkouts. If you know the customer and want to complete the sale, then you can create a draft order and send the customer an invoice.
View an order's fraud analysis
You can view fraud analysis for an order in your Shopify admin. Suspicious orders are flagged with an exclamation mark icon.
Steps:
Desktop
From your Shopify admin, go to Orders.
Click the order that you want to review for fraud.
In the Order risk section, click the
icon.
Review the full list of fraud indicators.
Mobile
- From the Shopify app, tap the
icon .
- Tap the order that you want to review for fraud.
- In the Order risk section, tap the
icon.
- Review the full list of fraud indicators.
Third-party fraud apps
You can download apps that help with fraud prevention from the Shopify App Store. You can view the fraud indicators and recommendations from these apps together with fraud analysis for each order.
Automating your fraud prevention strategies using Shopify Flow
Reviewing orders for potential fraud can be time-consuming. You can use fraud analysis to decide whether to fulfill an order. You can create fraud prevention workflows using Shopify Flow to automatically check your orders for potential fraud.
If the orders triggering your fraud analysis suggest card testing or repeat fraud, then review the guidance on responding to card testing and reducing chargeback risk.
Testing fraud analysis
You can test fraud analysis on your store and simulate an order with high, medium, or low risk. Test orders don't receive a real fraud recommendation, but you can use the following values to simulate one. To simulate a risk level, the order must have a total value greater than zero. You must also have the Shopify Payments gateway in test mode to create test orders that simulate risk level. If you use another payment gateway for your test, then your store must be on the Grow plan or higher.
Use the following email addresses to simulate an order:
- shopify.test.high@shopify.com to create high-risk recommendations
- shopify.test.medium@shopify.com to create medium-risk recommendations
- shopify.test.low@shopify.com to create low-risk recommendations
You can also use the following test values in the Apartment, suite, etc. field of the shipping address:
- shopify.test.high to create high-risk recommendations
- shopify.test.medium to create medium-risk recommendations
- shopify.test.low to create low-risk recommendations
Troubleshooting fraud analysis
Fraud analysis is pending
Fraud analysis typically happens immediately, but in rare cases it can take a few minutes. If an order has a fraud analysis isn't available yet message, then refresh the page or check back in a few minutes. Wait for the fraud analysis to finish before you fulfill the order.
A customer's IP address is on a temporary blocklist
If the abandoned checkout indicates that the customer's IP address is on a temporary blocklist, then fraud analysis has temporarily blocked that IP address. This can happen when many orders or failed payment attempts come from the same IP address in a short time.
The block is temporary and is removed automatically within 6 to 24 hours. There's no way to remove it sooner, so the person placing the order needs to wait. If they try to place another order before the block is removed, then the timer resets.
To place orders before the block is removed:
Create a draft order instead of using your storefront checkout.
For in-person sales, use Shopify Point of Sale.
A high-risk checkout attempt is blocked
If the abandoned checkout's Timeline includes Blocked due to high risk of fraud, then Shopify Payments blocked the payment before an order was created. No payment is captured.
Shopify Payments evaluates risk each time the customer submits checkout. If the customer tries again with different payment or billing details, then the payment might not be blocked.
If you know the customer and want to complete the sale, then create a draft order and send the customer an invoice.
A third-party gateway is reviewing an order
If your third-party payment gateway is reviewing an order for fraud, then the review status might not update in your Shopify admin, because some gateways don't send review updates back to Shopify.
To check the status of the order, contact your payment gateway directly, or review the order in your gateway's dashboard.