Online stores attract more than customers. Automated bots probe checkouts with stolen card numbers, try leaked passwords against your login page, scrape your prices, snap up limited stock and create fake accounts to abuse promotions. Payment fraud also costs merchants directly through chargebacks, fees and lost goods. The challenge is to stop the bad traffic without adding friction that costs real sales. This guide describes the main threats and a layered approach to defending against them.

Know your threats
Card testing. Criminals with lists of stolen card numbers use small transactions, or the payment form itself, to find which cards still work. You may see hundreds of failed attempts with small amounts. Even when most fail, you pay per-attempt fees, can trigger penalties from your payment processor and risk being shut down.
Stolen-card orders. Fraudsters buy goods, often high-value and easily resold, with stolen credentials. The genuine cardholder disputes the charge later, and you lose the goods and the sale, plus a chargeback fee.
Account takeover. Attackers use username and password pairs leaked elsewhere, since people reuse them, to log in and spend stored balances, redeem loyalty points or use saved payment methods.
Fake accounts and promotion abuse. Bots or people create many accounts to claim sign-up discounts, referral bonuses or free trials, and to post fake reviews.
Scraping and inventory hoarding. Competitors scrape prices and catalogue data; resale bots add limited items to carts faster than humans and hold them.
Denial of service. Floods of traffic aimed at making the site unavailable, sometimes to extort payment.

Layer one: the edge
Put a content delivery network with a web application firewall in front of the store. It absorbs volumetric attacks, blocks known malicious patterns and provides managed rules against common exploits. Enable bot management features that distinguish humans from automation using behavioural and fingerprint signals, and apply rate limits per IP, session and endpoint. Block or challenge traffic from clearly hostile sources, and use geographic rules with care so legitimate customers are not shut out. Our note on the edge explains what can run there.
Layer two: application controls
- Rate limit sensitive endpoints: login, registration, password reset, coupon application, address lookup and payment attempts. Use limits per account, IP and device, and progressively slow down repeated failures.
- Add bot challenges where risk is high. Modern challenge systems can often verify humans invisibly, only presenting a puzzle when behaviour looks suspicious.
- Protect login. Offer multi-factor authentication, check passwords against known-breach lists, and alert customers to unfamiliar logins. Consider passkeys as a phishing-resistant option.
- Validate everything on the server, including prices, quantities and discount eligibility. Never trust values from the browser.
- Protect promotions: single-use codes, limits per customer and per payment method, and checks for duplicate identities.
- Harden forms and APIs against injection and abuse; see our note on common web vulnerabilities.
Layer three: payment safeguards
Use the tools your payment provider gives you: strong customer authentication such as 3-D Secure, which also shifts liability for fraudulent chargebacks in many cases; address and security code verification; and the provider's built-in risk engine. Set velocity rules, for instance limiting the number of failed cards per IP or per session, blocking multiple different cards from one device, and flagging unusual order sizes. Require CAPTCHA or email verification before allowing multiple failed payment attempts, and avoid providing detailed decline reasons that help attackers refine their lists. Our guide to payment integration covers how the pieces fit.
Layer four: risk scoring and review
Combine signals into a risk score for each order: mismatch between billing and shipping countries, freight forwarder addresses, disposable email domains, new accounts placing large orders, high-risk product categories, unusual velocity, device and IP reputation. Automatically approve low-risk orders, decline clearly fraudulent ones and route the middle band to manual review with the evidence at hand. Keep the false-positive rate visible, because wrongly blocking good customers is also a cost. Learn from outcomes: feed confirmed chargebacks back into the rules.
Protect limited-release and high-demand items
For product drops, add a queue or waiting room, per-customer purchase limits, verified accounts and bot challenges at add-to-cart and checkout. Consider delayed reservation confirmation and post-purchase fraud review before shipping. These measures also protect fairness for real fans and customers. Our guide to traffic spikes covers the load side.


Detect and respond
Attacks are easier to handle when you see them early. Monitor payment decline rates, authorisation rates, login failure rates, new account creation rates and unusual spikes by IP range or user agent. Set alerts on sudden changes. Prepare a playbook: who can tighten rate limits, enable stricter challenges, pause a promotion or temporarily disable guest checkout, and how to contact your payment provider. After each incident, review what worked, and update controls. The monitoring practices in our article on application health apply.
Balance security and conversion
Every control adds potential friction. Aim for invisible defences first: edge protection, bot signals and risk scoring, and reserve visible challenges for suspicious cases. Measure conversion, false declines and abandonment as you tune. Communicate honestly with customers when extra verification is needed, using clear language and easy steps.
Data protection and compliance
Fraud controls involve personal data, such as device information, IP addresses and behaviour. Collect only what is needed, disclose it in your privacy policy, and follow applicable privacy laws. Keep card data out of your systems entirely by using tokenised payments; see our PCI-DSS overview.
A practical starting list
- Put a CDN and WAF with bot management in front of the store.
- Rate limit and protect login, registration, promo and payment endpoints.
- Enable 3-D Secure and address and security code checks.
- Add velocity rules and a simple risk score with manual review.
- Monitor decline, login-failure and sign-up rates with alerts.
- Review chargebacks monthly and refine the rules.
If your store is under attack or you would like to prevent it, our development team can implement and tune these layers, and our maintenance plans include monitoring so unusual patterns are caught early.
Put this into practice with CodeLuma
CodeLuma designs layered defences for online stores, including rate limiting, bot detection, risk scoring and monitoring, tuned so fraud drops while genuine customers glide through.
- Custom software development - tailored systems, integrations and internal tools.
- Website and web application development - fast, accessible, search-friendly builds.
- Maintenance and support plans - updates, monitoring and ongoing improvement.
Start a conversation. Tell us about your project and we will reply with practical next steps, or browse all CodeLuma services. CodeLuma Development Inc. is based in Nova Scotia and works with teams across Canada and remotely.


