Ecommerce Fraud Prevention Without Blocking Good Orders

Every store owner can tell you what fraud cost them last year. Almost none can tell you what caution cost them.

Ask an operator about chargebacks and you get a number. Ask how much revenue walked out the door because the fraud rules rejected a real customer, and you get a shrug. That second figure is usually the bigger one, and nobody sends you an invoice for it.

Four problems wearing one name

Ecommerce fraud prevention gets bought as a single product. It is four different problems, and the controls that solve one barely touch the others.

Stolen card checkout. Someone pays with card details they do not own. This is what most fraud tools are actually built for, and it is the problem the industry has got best at.

First-party misuse. A real customer, a real card, a real delivery, and then a dispute claiming otherwise. The Merchant Risk Council's 2026 survey of 1,278 merchant professionals across 37 countries found 64% reporting rising rates of first-party misuse, a quarter of them reporting increases of 25% or more. No device check stops this one. The customer really is who they say they are.

Card testing. Bots push stolen card numbers through your checkout to find which ones still work. Your store is not the target, it is the test bench. Visa attributes around US$1.1 billion of follow-on fraud in a one-year period to these enumeration attacks, with suspected attack transactions up 22% over the six months to December 2024.

Account takeover. Someone signs in as your customer, changes the delivery address, and spends the saved card.

If your answer to all four is one risk score from one vendor, three of them are getting through.

The number most stores never measure

Here is the part most owners miss.

The Merchant Risk Council's 2025 report, based on 1,082 merchant professionals in 38 countries surveyed in October and November 2024, found merchants rejected 5.0% of ecommerce orders on suspicion of fraud, while 3.0% of the orders they accepted turned out to be fraudulent. Same survey, same merchants, same twelve months.

Put those two side by side. The rejecting is bigger than the problem it exists to solve. And not all of that 5% was fraud: around six in ten merchants in the same report put their false-positive rate somewhere between 2% and 10% of disputed orders.

A wrongly declined order costs you more than the order. The shopper rarely retries. They buy the same thing somewhere else, quietly decide your checkout is broken, and you never see them again. Fraud losses show up as a line item someone can point at. False declines show up as a conversion rate that is a little worse than it should be, with no name attached, which is exactly why they survive for years.

If you cannot state your rejection rate and your fraud rate as two separate numbers, you do not have a fraud programme. You have a filter nobody is measuring.

Where the rules belong

Three systems can hold a fraud rule: the payment gateway, the store platform, and a dedicated fraud service. Most stores end up with all three, none of them aware of the others. That is how an order gets declined twice for two different reasons and nobody in the business can explain either.

Our position comes from building a payment orchestration platform where routing and risk decisions had to live in one place: one system owns the decision, everything else feeds it signals. Gateway checks like address and card security code verification belong at the gateway. Velocity and device rules belong where you can see the whole session, not just the payment call. The decision to release, hold or review an order belongs in one place that logs its reason in plain language.

The test is simple. Ask your team why order 48211 was declined. If the answer takes longer than a minute, the rules are in the wrong shape, and wiring those systems together properly will do more for you than another vendor subscription.

3-D Secure deserves its own warning, because owners consistently misread it. Authenticating a payment through 3DS generally moves liability for a fraudulent chargeback from you to the card issuer. That shift is neither automatic nor unconditional: ignore an issuer's inquiry on a 3DS-authenticated charge and the protection can be undone by what the industry calls a no-reply chargeback. Stores that treat 3DS as a switch rather than a process find this out during their first bad month.

Win the dispute at checkout, not ninety days later

This is the cheapest win in the whole category, and hardly anyone takes it.

When a dispute lands, your ability to fight it depends entirely on data you either captured at order time or did not. Visa's Compelling Evidence 3.0 rules, in force for pre-arbitration attempts since 15 April 2023, say precisely what counts: two prior undisputed transactions from the same cardholder, between 120 and 365 days old, matching the disputed one on at least two of customer account or login ID, delivery address, device ID or fingerprint, and IP address. At least one of those two matches has to be the device ID, the fingerprint, or the IP.

Read that as a technical requirement, because that is what it is. If your platform does not record a device fingerprint and an IP address against every order, and keep them for a year, you cannot use the rule at all. Most stores we open up keep the address and the account and throw the rest away. The evidence was free, it was sitting in the checkout session, and it went in the bin.

A conveyor belt carrying a sealed envelope from a shop checkout counter, under an arch of calendar pages, to a bench where a clerk opens it and stamps a document

Card testing is plumbing, not scoring

Card testing is the attack owners misdiagnose most often, because it looks like a fraud problem and behaves like a traffic problem. The tell is a spike in failed authorisations against flat order volume, usually tiny amounts, usually at unsociable hours.

A risk score will not save you here, and paying per screened transaction while a bot generates the transactions is an unusually bad deal. The fixes sit upstream of the fraud tool: rate limits per IP, device and card range on the payment endpoint, a challenge in front of it, and an alert on the ratio of declined to approved authorisations. That ratio moves days before your acquirer picks up the phone.

The damage also outlives the incident. Visa's analysis of two carding marketplaces found 85% to 93% of the exposed accounts traced back to enumeration attacks at least twelve months earlier. Cards tested through your checkout this quarter get spent somewhere else next year, and your store is in the middle of that story whether or not you lost a penny at the time.

The compliance floor

PCI DSS requirements 6.4.3 and 11.6.1 became effective on 31 March 2025. They require that the scripts running on your payment page are authorised, checked for integrity, and monitored for tampering. That is a direct answer to e-skimming, where an attacker slips a few lines of code into checkout and copies card details as customers type them, which is a quieter and far more common problem than most owners assume.

The council simplified the self-assessment questionnaire for the smallest merchants at the same time, and plenty of people read that as the requirement being cancelled. It was not. PCI SSC said plainly that the change affects how compliance is reported, not the underlying requirement.

AI shopping agents are about to trip your bot rules

One more thing is arriving faster than most fraud roadmaps allow for.

Visa reported in October 2025 that AI-driven traffic to United States retail websites had surged over 4,700% in a year, citing Adobe's measurement, and named the merchant problem in the same breath: bot detection systems that mistakenly block legitimate agentic transactions.

Every control in this article quietly assumes a human at a keyboard. An agent checking out on a customer's behalf has no mouse movement, an unfamiliar device signature, and a burst pattern that looks a lot like card testing. Stores that get this wrong will not watch fraud go up. They will watch the rejection rate climb and never find out what it cost, which is the same readiness question as whether AI agents can buy from your store at all.

Where to start

Ecommerce fraud prevention improves fastest from two measurements, not a purchase. Track the share of orders you reject and the share of accepted orders that turn out fraudulent, as separate numbers, this month. Then check whether every order record carries a device fingerprint and an IP address, and whether you still have both a year later. Most stores we look at can improve their position more by fixing those two things than by buying anything.

If this is on your list and the team is already stretched, it is the sort of work we do at Encomage. Fraud, payments and checkout usually sit across the gateway, the platform and a few third-party services at once, so we tend to start by mapping how an order really flows through all of them before recommending a single change.

Let's discuss your project

By submitting this form, you agree to the processing of your personal data in line with our Privacy Policy.

Frequently Asked Questions

Explore more on this topic

A shopfront still lit and trading at night while its outer facade stands stripped back inside scaffolding, with one person outside holding a rolled plan and looking up

Shopify Hydrogen Is Being Rebuilt. Should You Build on It?

Shopify and Vercel are rebuilding Hydrogen, Shopify's toolkit for custom storefronts. Here is what that means if you are weighing a headless Shopify build right now: what Hydrogen is, what it really costs to run, what you lose when you leave the theme, and when a theme is still the better business decision.

Loose supplier paperwork feeding into a single labelled sorting cabinet, which sends four clean tracks out to a shopfront, a market stall, a phone and a printed catalogue

What Is a PIM System, and Does Your Store Need One?

Almost everything written about PIM is published by companies selling PIM software, so it all ends the same way. Here is the version from the integration side: what a product information management system actually does, how it differs from your ERP and from your platform's own product fields, what messy product data costs in abandoned carts and returns, and the specific point at which a store stops being able to manage without one.

A small shop building sealed inside a large glass display case, with the only key hanging on a hook on the outside of the case

What Is a Cloud-Based Ecommerce Platform? An Owner's Guide

Cloud is not one product. It's three different arrangements with very different consequences for what you control, what you pay, and how hard it is to leave. Here is what a cloud-based ecommerce platform actually covers, the fees that scale with your sales rather than your plan, and what an uptime promise is really worth once you read the terms attached to it.

A storefront nameplate being replaced with a new one while a person below consults a map that still shows the old name

Adobe LLM Optimizer Is Now Brand Visibility: What Changed

Adobe LLM Optimizer no longer exists under that name. In June 2026 it became Adobe Brand Visibility, and the old product, pricing, and announcement pages now redirect. What the tool actually did, what the rebuild added, why the price is not published, and what an owner can do about AI visibility without an enterprise contract.

Layered cutaway showing a small storefront resting on cache, server, and database layers drawn in line art

Ecommerce Hosting in 2026: A No-Nonsense Buyer's Guide

Almost every guide to ecommerce hosting is written by someone selling hosting. Here is the vendor-neutral version: the three hosting models, what actually matters once a store has real traffic, what hosting genuinely costs in 2026, and a short decision path for choosing without the affiliate noise.

Split line-art scene contrasting a vending machine dispensing finished answers with a tutor guiding a student through one step of a worksheet

AI Tutoring in 2026: What the Research Actually Shows

AI tutoring is one of the few AI applications with rigorous evidence behind it: a Harvard experiment and a World Bank pilot both found outsized learning gains. Here is what the research really says, what it costs, and what it takes for an edtech product team to ship a tutor that works.

Inspired by what you’ve read?

Let’s build something powerful together - with AI and strategy.

By submitting this form, you agree to the processing of your personal data in line with our Privacy Policy.

messages
mechanizm
folder
gray background