E-commerce
June 28, 2026
E-commerce support can be targeted by fraudsters: fake customers, fake proofs of payment, urgent refund requests, phishing links, or identity theft. Responding too quickly can expose both the brand and its customers.
The chatbot must recognize risk signals, never ask for secrets, and transfer sensitive requests to a secure procedure.
This guide shows how to secure support against phishing, fake orders, and fake refunds without blocking genuine customers.
Summary
Why is support a target?
Support has access to useful information: orders, emails, refunds, addresses, proof, and goodwill gestures. A fraudster may try to create a sense of urgency to push the agent to act quickly.
The chatbot must help slow down sensitive decisions and request the proper verifications.
Support security means helping real customers quickly without opening the door to fake claims.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
Which signals to monitor?
Risk signals include strong pressure, refund requests to another payment method, different email addresses, suspicious screenshots, external links, order inconsistencies, urgent address changes, and refusal of verification.
A single signal does not prove fraud, but multiple signals should trigger an escalation.
How to authenticate safely?
The bot may request the information required by the procedure, such as email, order number, or secure verification. It must never request password, 2FA code, full card number, or access to an external account.
The customer must understand that these limits also protect them.
How do you manage fake refunds?
A refund must be returned to the original payment method when the policy so provides. A request for a refund to another account, wallet, or card must be considered sensitive.
The bot must escalate any financial request that falls outside of the standard framework.
This rule prevents a fraudster from diverting a financial decision by impersonating the customer.
How to protect the workers?
Agents must know which links not to open, what evidence to verify, which thresholds to escalate, and what information never to ask for. The chatbot can pre-filter requests and flag inconsistencies.
Security must be simple to apply, otherwise it will be bypassed during peak volumes.
Procedures must also explain how to reassure a genuine customer blocked by a security check. A poorly phrased security message can give the impression of personal suspicion, whereas the objective is to protect the account and the order.
Education reduces frustration and increases the acceptance of controls.
Which flow to follow?
The flow must secure before acting.
Identify the order, account, email, request, amount, proof, and reported urgency.
Detect inconsistencies, external links, pressure, changes in payment/refund method, or refusal of verification.
Apply the designated authentication without asking for secrets in the chat.
Block or transfer refunds, addresses, accounts, and sensitive access.
Document signals to improve filters, training, and security procedures.
Which messages should be used?
For security: “To protect your account, I will never ask for your password or a verification code here.”
For refund: “A change in refund method requires human verification.”
For link: “Avoid sending links containing sensitive information; a masked screenshot is often enough.”
When to transfer?
The transfer is necessary for a refund outside the original payment method, suspicious account, different email, doubtful link, high pressure, inconsistent order, or sensitive access attempt.
The bot must transmit signals, order, account, proof, request, amount, verification performed, and risk.
Which KPIs should be monitored?
Track suspicious attempts, blocked refunds, accounts at risk, flagged links, prevented errors, security escalations, and confirmed incidents.
This data shows whether support protection is improving.
Which mistakes should be avoided?
Avoid acting under pressure, clicking unverified links, refunding to a new method, asking for secrets, or downplaying an inconsistency.
Support must remain fast, but not reckless.
How can Qstomy help?
Qstomy can connect the chatbot to difficult cases, escalation matrixes, response templates, security rules, SLAs, orders, payments, and support procedures to answer clearly, then transfer sensitive cases with an actionable summary.
The chatbot helps the customer move forward without inventing a sensitive decision, a guaranteed response time, a refund validation, a proof of safety, or an escalation that still needs to be confirmed by a reliable source.
Explore AI support, the AI sales agent, or request a demo.
Key takeaways
Key Takeaways
Support security must detect phishing, impersonation, fake refunds, suspicious links, and order inconsistencies.
What the customer must understand
The legitimate customer must be protected through clear and non-intrusive verifications.
The chatbot's correct boundary
The chatbot can pre-filter and collect information, but it must transfer any refund requests or sensitive access.

Enzo
June 28, 2026


