Ecommerce Fraud Detection: How to Identify Suspicious Transactions
How ecommerce fraud detection works: fraud types, identity, device, behaviour and order signals, rules and machine learning risk scores, manual review, false positives and how to measure results.
Quick answer
Ecommerce fraud detection combines signals about identity, device, behaviour and the order itself into a risk decision: approve, authenticate (for example with 3D Secure), review or decline. Use your payment provider's or a specialist's machine learning score as the base, add a few store-specific rules, keep manual review for genuinely ambiguous high-value orders and feed outcomes (chargebacks, confirmed fraud and wrongly declined customers) back into thresholds. Measure false positives as carefully as fraud losses, because declining good customers is often the larger cost.
Where This Fits
Fraud detection decides which orders are risky. Authentication is covered in 3D Secure, disputes after the fact in chargeback management, and broader store protection in ecommerce security. On marketplaces, seller-side fraud is part of marketplace trust and safety.
Types of Ecommerce Fraud
| Fraud type | What happens | Typical signals |
|---|---|---|
| Stolen card (third-party) fraud | A fraudster pays with someone else's card | Mismatched details, risky device, rush shipping, resellable goods |
| Card testing | Many small attempts to validate stolen cards | Bursts of declines, same device or IP, small amounts |
| Account takeover | A fraudster logs into a real customer's account | New device, password reset, changed address or email before ordering |
| Friendly fraud | A genuine customer disputes a valid charge | Prior disputes, delivered orders disputed as not received |
| Refund and returns abuse | Empty boxes, wardrobing, false not-received claims | Claim patterns by customer or address |
| Promotion abuse | Multiple accounts to reuse first-order discounts | Shared devices, addresses or payment methods |
Fraud Signals
No single signal proves fraud. A mismatch between billing and shipping addresses is common for gifts; a new account is normal for new customers. Signals become useful in combination.
- Identity: email age and domain, phone validity, account age and history, name consistency across billing, shipping and card
- Device and network: device fingerprint, IP reputation, proxy or VPN use, distance between IP location and addresses
- Velocity: orders, cards or accounts per device, IP, email or address over short periods
- Behaviour: number of card attempts, pasted card details, unusually fast form completion, direct navigation to high-value items
- Order: basket value relative to normal, resellable goods such as electronics or gift cards, rush shipping, freight forwarder addresses
- Payment results: AVS and CVV checks, 3DS outcomes, issuer responses
Risk Scoring: Rules and Models
Most payment providers and fraud specialists offer a machine learning score trained on data across many merchants, which sees patterns no single store can. Add rules for what is specific to your business: block shipping to known reshipper addresses for high-value electronics, require review above a value threshold for new customers, or allow trusted repeat customers through. Keep rules few, documented and reviewed; hundreds of overlapping rules become impossible to reason about.
Decisions: Approve, Authenticate, Review, Decline
Map score bands to actions. Low-risk orders are approved automatically. Medium-risk orders can be sent to 3D Secure where available, which adds a check and often shifts liability. Higher-risk orders with mixed signals go to manual review if the value justifies it. Clearly fraudulent orders are declined. Card testing is better handled before payment, with rate limits and bot protection on the checkout.
Manual Review That Works
Manual review is expensive, slow and inconsistent unless it is designed. Give reviewers one screen with all signals, the customer's history and the reasons the order was flagged; a short checklist; clear authority to approve, decline or contact the customer; and time targets so legitimate orders are not delayed for days. Record every decision and reason so they can become training data and rule refinements.
Spending too long reviewing orders, or losing too much to fraud?
ZSpace Labs can integrate fraud scoring, build focused review tools and wire outcome data back into your rules.
False Positives: The Hidden Cost
Every genuine order declined as fraud is lost revenue and often a lost customer, and most stores never measure it. Estimate false positives by reviewing a sample of declined orders, running a small holdout where some medium-risk orders are approved and tracked, and watching complaints from customers who were declined. Tune thresholds for overall profit, not for the lowest fraud rate.
Account Takeover and Card Testing Controls
- Rate limits on login, password reset and payment attempts per IP, device and account
- Bot protection on checkout and payment endpoints
- Step-up verification when a new device changes email, address or payment method
- Notifications to customers when account details change
- Monitoring for spikes in small failed payments
- Multi-factor authentication options for customer accounts
Feeding Outcomes Back
Fraud models and rules improve only with outcomes. Record chargebacks with their reason codes, confirmed fraud reports, review decisions and customer complaints about declines, and link them to the original order and its signals. Most fraud providers accept feedback on outcomes; send it. Review rule performance monthly.
Measuring Fraud Prevention
- Fraud chargeback rate by count and value
- Fraud losses including goods and shipping
- Decline rate from fraud rules and models
- Manual review rate, decision time and approval share
- Estimated false-positive rate from samples or holdouts
- Card network monitoring program thresholds your acquirer applies
Build, Buy or Use Your Provider's Tools?
Most stores should start with the fraud screening built into their payment provider or platform, add a specialist fraud tool when volume, losses or manual review load justify it, and build custom models only with a data science team and enough labelled outcomes.
| Option | Strengths | Limitations |
|---|---|---|
| Provider or platform screening | Already integrated, network-wide data | Limited customization and visibility |
| Specialist fraud tool | More signals, review tools, sometimes chargeback guarantees | Extra cost and integration |
| Custom rules on top | Captures store-specific patterns | Needs maintenance and discipline |
| In-house models | Full control | Requires data scientists and labelled outcomes |
How to Build a Fraud Process Step by Step
- 1. Measure today: fraud chargebacks, declines, review volume and complaints from declined customers
- 2. Make sure signals reach your fraud tool: device data, account history, full addresses
- 3. Define score bands and actions: approve, authenticate, review, decline
- 4. Add a small number of business rules with owners and review dates
- 5. Set up review tooling and time targets
- 6. Protect payment endpoints against card testing with rate limits and bot controls
- 7. Feed outcomes back: chargebacks, confirmed fraud and false positives
- 8. Review thresholds monthly for overall profit, using dispute data and authentication results
Worked Example
An illustrative scenario, not a client case: an electronics store declines any order where billing and shipping differ. Fraud is low, but so is gifting revenue, and support hears from frustrated customers. The team replaces the rule with the provider's risk score, sends medium-risk mismatched orders to 3D Secure, and reviews only high-value cases. Approved orders rise while fraud chargebacks stay within target.
Common Mistakes
- Blocking on single signals such as address mismatch
- Hundreds of unreviewed rules
- Sending most orders to manual review
- Not measuring false positives
- No outcome feedback to the fraud provider
- No rate limits on payment attempts
Want fraud controls tuned for revenue, not just risk?
Talk to ZSpace Labs about fraud tool integration, review automation and case summaries and Shopify fraud workflows.
Conclusion
Good fraud detection is layered, measured and humble about false positives. Combine signals, use provider scores plus a few rules, route decisions by risk, review only where it helps and close the loop with outcomes. Related: 3D Secure, chargeback management and payment security.
Common questions
The process of identifying orders, accounts and payments that are likely fraudulent, using signals about the customer, device, behaviour and order, so they can be blocked, authenticated or reviewed before goods ship.