E-commerce
September 3, 2026
Summary
Why do anti-fraud rules too often block good customers?
Shopify Payments and Stripe Radar automatic tools are essential for protecting your cash flow, but they operate using statistical algorithms. They identify risk profiles based on variables like inconsistent geolocation or unusual purchasing velocity.
However, this blind logic often creates false positives. An expatriate traveling in their home country, a legitimate VPN user seeking privacy, or a customer making a large first purchase can trigger security alerts without being fraudulent.
The industry reports that declining a legitimate order costs far more than a loss due to fraud. According to Chargebacks911, the cost of a lost customer includes the loss of immediate revenue, wasted marketing acquisition costs, and a negative public review that deters new prospects.
Support must therefore intervene to qualify these signals. A purely defensive approach turns your site into an impenetrable fortress where your best customers feel suspected. The challenge is to distinguish suspicious behavior from legitimate human behavior before shipping or canceling.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
What types of fraudulent orders do you need to identify specifically?
The first step in effective management is to map out threats so as not to confuse a typing error with an organized criminal attempt. We mainly distinguish third-party pre-shipment fraud, where a thief uses a stolen card to purchase products.
This type of scenario is characterized by quick purchases, high-value shopping carts, and a shipping address that differs from the registered billing address. Another common form is account takeover, where the fraudster accesses customer data and abruptly changes the shipping address.
There is also triangulation, where a third party resells your product on an external marketplace using your orders to deliver to their victims. Finally, we observe card testing, with multiple micro-transactions at €1 to check if a card works before a large purchase.
It is crucial not to confuse these cases with friendly fraud. In the first scenario, the initial customer disputes their order after receipt, which is a chargeback dispute process rather than a pre-shipment cancellation. Similarly, promotional code abuse or abusive returns are marketing issues distinct from immediate risk management.
How to interpret risk signals on Shopify and Stripe?
Platforms like Shopify and Stripe offer a centralized dashboard to analyze the risk level, often classified as low (Low), medium (Medium), or high (High). These scores are calculated from a multitude of technical factors, including AVS (Address Verification System) matching and CVV code failure.
Order velocity is a major indicator: multiple attempts on the same card within an hour immediately suggest testing or theft. Similarly, an IP address geolocation that does not match the billing or shipping country should alert the team, but without being an automatic verdict.
Stripe Radar allows you to configure action rules, often favoring manual review "review" rather than total blocking "block", except in cases of extreme doubt. This configuration is crucial to avoid unjustified cancellations.
It is also necessary to consider the device lifespan and customer history. A new account with an unknown device making a high-value purchase deserves special attention, while a loyal customer with consistent shipping histories inspires more trust.
What process structure should be adopted to validate without blocking?
A documented process prevents decisions based on intuition, which can be inconsistent from one day to the next. The process must begin with an automatic alert: any order exceeding a risk threshold or triggering a Shopify Flow rule is immediately tagged with "fraud_review".
The next phase is the temporary suspension of shipping. Never ship before the review is completed. A service-level agreement (SLA) response time must be established, typically between 4 and 24 hours depending on the average order value (AOV), to ensure responsiveness without sacrificing thoroughness.
The human assessment is based on a weighted score: customer history, address consistency, email and phone validity, and sometimes the device fingerprint. The final decision is binary or ternary: validation for shipping (tagged "fraud_cleared"), manual verification by contacting the customer, or definitive cancellation with a refund.
Each action must be documented in the Shopify order notes: who made the decision, when, why, and what evidence was examined. This ensures perfect traceability in the event of a subsequent dispute or retroactive analysis.
How to contact a suspected customer without accusing or antagonizing them?
Communication is the most sensitive step. The objective is to reassure the honest customer, not to put them on the defensive. For high-value orders (high AOV), the email and SMS duo is ideal, with a requirement to send within 30 minutes following the order to capture the customer's engagement.
The subject of the message must be neutral, for example: "[Brand] order #[X]: quick check before shipping". It is absolutely essential to avoid the term "fraud" which triggers immediate negative emotions. The body of the message explains that this check is a standard protection for the entire customer community.
We then simply ask for the last 4 digits of the card, the holder's name or confirmation by direct reply. The idea is to transform the request into a concierge service rather than a police investigation. This validates the identity while reassuring about the seriousness of the process.
It is strictly forbidden to request the full CVV code or to store sensitive banking data in a support ticket, under penalty of PCI non-compliance. In the event of customer inaction after 72 hours, a cancellation is justified, but it must be preceded by a polite reminder.
What strategy should be applied to low-value, high-frequency orders?
Repeated micro-transactions are often a sign of stolen card testing. If the same account or IP address generates multiple purchase attempts in a very short period, the rule must be automatic: block or test.
It is counterproductive to submit every small order to a manual review, as this unnecessarily saturates the support team. Velocity blocking is therefore the most effective solution for this type of fraud without harming legitimate customers who do not order in this manner.
For low-value orders coming from suspicious new accounts, a light verification policy can be applied, such as sending a 6-digit SMS code to validate the phone. This adds sufficient friction to discourage automated fraudsters while remaining smooth for a human.
Data analysis shows that failing to react quickly enough to these tests often leads to major damage later on. A differentiated strategy based on value and frequency therefore makes it possible to secure the infrastructure without weighing down the validation process for serious purchases.
How should you respond to customers whose orders were canceled by mistake?
Even with the best filters, errors happen. When an order is incorrectly cancelled, the support response must be clear and reassuring. The template message indicates that the security system was unable to validate the payment and that no final charge has been made.
It is crucial to inform the customer that if an amount temporarily appears on their account, it is a standard banking hold that will disappear within 5 to 10 business days. This prevents unnecessary panic and explains the refund delay without waiting for a complex banking intervention.
The customer should be able to place a new order immediately or contact their bank if a charge is visible. For premium customers, phrasing the cancellation as a protective measure can help maintain the relationship, emphasizing that the security of their account and data is the absolute priority.
Any accusation in the cancellation communication must be avoided. If the customer asks if they have been accused of fraud, support must reaffirm that this is a standard automatic verification procedure and not a personal suspicion, redirecting the user to a secure new attempt.
How to adapt the verification for digital products and services?
Digital products carry a risk of total loss if a link is sent before payment validation. In this case, the verification process must be strictly "review" before sending: no download link must be activated until the order is tagged "fraud_cleared".
For high-value products such as luxury watches or professional equipment, a short phone call option can be offered. The advisor directly verifies the conversation with the customer, which immediately deters fraudsters using stolen cards without access to the actual phone.
Rules must also adapt to delivery times. If a product is shipped via a 3PL or ShipStation, you must ensure that the "fraud_review" tag prevents the shipping label from being generated until the final decision is made.
This strict separation between validation and execution is vital for intangible goods where the risk of leakage is total. A quick verification, often by SMS, is enough to clear any doubt while securing the sending of the final access code.
What role do documentation and notes play in dispute management?
Traceability is your best defense against abusive claims. Every decision to block, verify, or cancel must be noted immediately in the "Notes" section of the Shopify order.
These notes must contain the name of the agent who made the decision, the precise date and time, and the justification (e.g., "Suspicious IP, new card, SMS confirmation request sent"). In the event of a subsequent chargeback, these written records prove that due diligence was exercised.
Additionally, this helps reassure customers by showing them that their file was reviewed by a human and not simply rejected by a machine. This strengthens the perception of transparency and honesty of your brand.
Finally, documentation allows for regular retrospective analyses to refine automatic rules. By identifying recurring patterns of errors (e.g., certain payment providers often resulting in false positives), you can adjust your risk thresholds for the future.
How to use intelligent automation to streamline verification?
Automation is not only useful for blocking fraud, it can also optimize the verification process. Tools like Shopify Flow allow you to automatically send alerts to support or managers when high-risk orders are identified.
This helps reduce the mental workload of the team by only submitting doubtful cases to a human, while safe transactions go through automatically. Intelligent automation thus helps maintain a high processing speed without sacrificing security.
For orders with "medium" risk, rules can be configured to initiate specific verification processes, such as sending a confirmation request via SMS at the very moment the email was sent. This creates consistency in customer communication.
By integrating these tools, you reduce processing times and improve the overall experience for the legitimate customer who sees their order processed quickly, while fraudulent attempts are filtered out with precision.
How does Qstomy help secure the process without blocking your customers?
Qstomy, your Shopify AI agent dedicated to customer support, plays a central role in this delicate balance. Unlike rigid bots, Qstomy is designed to understand the context and guide towards a purchase in complete safety. It steps in as soon as security threatens the experience.
During a fraud alert, Qstomy can initiate a proactive and reassuring interaction via chat or email to request standardized identity verification (e.g., confirming the last 4 digits of the card). This prevents the customer from having to wait for a human callback.
If the customer is indeed legitimate but confused by the block, Qstomy can clearly explain the technical reasons without accusing, while guiding toward an alternative payment solution or rapid validation. This significantly reduces cancellation tickets and cart abandonments.
For frequent false positives on specific profiles (e.g., VPN users), Qstomy learns and adjusts its responses to remain empathetic while maintaining security standards. It is a partner that transforms potential friction into a moment of reinforced trust.
What checklist should be applied before validating or canceling a suspicious order?
Before any definitive action, this checklist guarantees that no angle is forgotten. The list includes: verifying consistency between the IP address and the delivery country.
Check if the email is a disposable or inactive service. Confirm the customer account history: first order or loyal? Analyze the basket value compared to the historical average.
Contact the customer via SMS or call for dual authentication if the risk is high. Document any decision in the Shopify order notes with supporting evidence.
To go further: How to handle customer questions about web offers not available in-store - Qstomy, Email address error in an order: helping the customer retrieve tracking, invoice, and account - Qstomy, Checkout funnel help page: reassuring about payment, delivery, and customer account at the right moment - Qstomy, How to manage fraudulent orders without blocking good customers - Qstomy, How to handle customer questions about subscriptions with a free trial - Qstomy, How to reassure buyers before and after purchase on expensive products? - Qstomy, How to handle customer questions about a product seen on an influencer but out of stock - Qstomy.

Enzo
September 3, 2026


