· Dash Checkout · security-and-fraud  · 7 min read

Cart jacking and fraud: How to protect your Shopify store from fake orders and inventory loss

Fraudsters use stolen cards and bots to clear your inventory during sales. Learn how purchase limits, customer tracking, and smart rules keep your stock for real customers.

Fraudsters use stolen cards and bots to clear your inventory during sales. Learn how purchase limits, customer tracking, and smart rules keep your stock for real customers.

A trading card shop owner messaged us in May 2026 after losing $12,000 worth of Pokemon booster boxes during a restock. The orders looked normal at first: different names, different addresses, different payment methods. But by the time the chargebacks started rolling in three weeks later, the cards were gone and reselling on secondary markets.

This pattern has a name: cart jacking. Bad actors use stolen credit cards or compromised accounts to place large orders on high-demand products. By the time the fraud is detected, the inventory is shipped and the merchant is left with chargebacks, lost product, and no recourse.

The problem has grown more sophisticated in 2026. Fraudsters now use AI-generated fake identities, rotating residential IP addresses, and even “clean” prepaid cards purchased with cryptocurrency. Traditional fraud detection struggles because each order, viewed in isolation, looks legitimate.

For the technical side of how bots exploit your inventory data, see why you need to protect your Shopify inventory from cart scraping.

How cart jacking actually works

Cart jacking typically follows one of three patterns, each targeting different store vulnerabilities:

Pattern 1: The bulk clearout

A fraudster with multiple stolen cards places 5-10 large orders within minutes of a product going live. Each order uses a different card and shipping address. By the time Shopify’s fraud analysis flags them, your inventory is already committed or shipped.

A sneaker boutique we talked to lost their entire Air Jordan restock (48 pairs) in under 4 minutes to this pattern. The orders came from 6 different “customers” who turned out to be the same person using purchased shipping addresses.

Pattern 2: The slow burn

Instead of bulk orders, sophisticated fraudsters place smaller, spread-out orders over days or weeks. They stay under fraud thresholds, use legitimate-looking checkout behavior, and wait until the chargeback window is almost closed before the merchant realizes what happened.

One coffee equipment merchant noticed chargebacks clustering 60-80 days after purchase, all for high-value espresso machines. The orders had been placed over a three-week period by what appeared to be different customers in different states.

Pattern 3: The bot swarm

Automated scripts place dozens of simultaneous orders the moment a limited product drops. Some are fraud attempts, others are resellers using bots. Either way, real customers never had a chance.

This pattern is especially common for trading cards, streetwear drops, and limited edition collectibles. One Pokemon card shop reported that 73% of their Scarlet and Violet release went to just 8 customer accounts, with bots placing orders within seconds of the drop.

Three rules that actually reduce fraud exposure

Based on patterns we’ve seen across hundreds of stores, here are the specific rules that make the biggest difference.

Rule 1: Lifetime purchase limits per customer

This is the single most effective fraud deterrent for limited or high-value products.

Cart limits alone don’t help because fraudsters just place multiple orders. A customer limit of “max 2 per order” means nothing when someone can place 10 orders in 10 minutes.

Customer lifetime limits track purchases across all orders. Set a limit of 2 units per customer for a product, and that limit holds whether they buy today, tomorrow, or next month. Each additional order requires a new verified customer account.

How to set this up in DC Order Limits:

  1. Create a Customer Purchase Limit rule
  2. Set the maximum quantity (we recommend 2 for limited items, 1 for ultra-rare products)
  3. Apply to your high-risk products using tags or collections
  4. Require logged-in customers (so the limit can be tracked)

The Pokemon card shop that lost $12,000? After implementing customer purchase limits, their next restock went to 340 unique customers instead of 12. Same inventory, far more distribution, dramatically lower fraud rate.

Rule 2: Login requirements for high-risk products

Guest checkout is convenient, but it’s also what fraudsters prefer. No account means no purchase history, no tracking, and no way to enforce customer-level limits.

For limited drops and high-value items, requiring customer accounts adds meaningful friction for bad actors while barely affecting real customers. Most genuine buyers are happy to create an account for products they actually want.

Combine login requirements with customer purchase limits, and fraudsters need to create and verify new accounts for every order they want to place. That’s time, effort, and a higher chance of getting caught.

Rule 3: Segmented limits for new vs. returning customers

Not every customer carries the same risk. A first-time buyer ordering 5 units of your most expensive product is statistically riskier than a customer who’s been shopping with you for two years.

DC Order Limits lets you set different limits based on customer tags. Here’s a setup that several merchants use:

  • New customers (no tag): Max 1 unit of any limited product
  • Returning customers (tag: “verified”): Max 2 units
  • VIP customers (tag: “vip”): Max 4 units

You can apply the “verified” tag automatically using Shopify Flow after a customer’s first successful order (no chargeback within 30 days). This creates a trust ladder: new customers prove themselves before getting higher limits.

For implementation details, see our guide on using customer tags and geolocation to tailor limits.

Blocking common fraud signals before checkout

Purchase limits are your primary defense, but you can layer additional protections that catch fraud earlier.

Minimum order values for international orders

Fraudsters often test stolen cards with small international orders before placing larger ones. A $15 order to an international forwarding address costs you shipping, handling, and payment processing, all for a product that gets bundled with other fraudulent purchases and reshipped.

Set a minimum order value of $50-100 for international orders to filter out card testing and low-value fraud attempts. Legitimate international customers usually place larger orders anyway since they’re already paying for shipping.

Price limits for tagged high-risk accounts

If you’ve identified accounts that show suspicious behavior, like multiple failed payment attempts, disputed orders, or flagged by Shopify’s fraud analysis, you can restrict what they can purchase without banning them outright.

Apply a “high-risk” tag (manually or through Shopify Flow), then create a rule that limits those accounts to a maximum cart value of $50. They can still shop, but they can’t place the large orders that cause real damage.

Cart limits as a scraping defense

Bots probe your inventory by adding huge quantities to cart and reading the error message. If they try to add 999 units and you have 47 in stock, they now know your exact inventory level.

Setting a cart maximum of 10-20 units per product variant makes this scraping useless. They’ll hit your limit before they hit your real inventory, and competitors or resellers can’t see your actual stock levels.

What to do during BFCM and high-traffic sales

Peak shopping periods are when fraud attempts spike. Here’s a pre-sale checklist:

One week before:

  • Set customer purchase limits on your top 20 best-selling products
  • Require login for any limited or high-value items
  • Set a minimum order value for international orders
  • Review and tag any accounts with previous fraud indicators

Day of sale:

  • Monitor orders in real-time for clustering patterns (multiple orders from similar addresses or sequential emails)
  • Have a process ready to hold suspicious orders for manual review before shipping
  • Know your cancellation policy and when you can safely cancel flagged orders

After the sale:

  • Review any orders with mismatched billing and shipping addresses
  • Check for multiple orders to the same shipping address under different names
  • Flag accounts that placed orders at inhuman speeds (sub-2-second checkout completion)

For a complete seasonal checklist, see how to use order limits to stay in control during busy sales months.

Building a fraud-resistant store

Fraud prevention works best as layers. No single measure stops all fraud, but combining purchase limits, login requirements, customer segmentation, and order monitoring creates enough friction that most bad actors move to easier targets.

The trading card shop we mentioned earlier now uses:

  • Customer purchase limits of 2 units for sealed product
  • Required login for all purchases over $100
  • Automatic “verified” tagging after successful first order
  • Minimum $75 order value for international shipping

Their fraud rate dropped from roughly 8% of revenue to under 1%. More importantly, their regular customers noticed the difference: products stayed in stock longer, and more people got access to limited releases.

DC Order Limits handles the purchase limits and customer tracking. You can install it here and set up your first rule in a few minutes. Start with your highest-risk products, the ones that sell out fast or have high resale value, and expand from there.

The goal is keeping your inventory for the customers who actually want your products. Every unit that goes to fraud is a unit that a real customer couldn’t buy.

Back to Blog

Related Posts

View All Posts »
Install App