John Doe Abandoned Checkouts on Shopify: How to Stop Them
Why am I getting fake abandoned checkouts?
They are usually card-testing bots: scripts that push stolen card numbers through your checkout to learn which still work, often under the name John Doe. Many skip your storefront entirely, so a storefront blocker never sees them. Shopify’s checkout-level defences, such as Shopify Payments’ card testing protection and Fraud Control rules, are the first line.
Merchants in the Shopify Community describe the same pattern: thousands of abandoned checkouts, a new email on each, and repeated failed payments (thread). One store reported more than 2,000 “John Doe” customers and 1,000 abandoned carts (thread). The customers come with the checkouts: Shopify creates a customer profile whenever someone starts an order but abandons the checkout (managing customers).
Bots that only add products to a cart show up elsewhere: in your add-to-cart rate and, if you run one, your email tool’s abandoned-cart flow. Shopify lists a checkout as abandoned only once an email has been entered and ten minutes have passed (abandoned checkouts).
Is it card testing?
Probably, if the checkouts share a pattern: the same fake name, a new email each time, failed payments in the timeline and a cheap product in the cart. Shopify describes card testing as fraud “where someone uses automated scripts to test whether stolen card details are valid” (preventing fraud).
| Sign | What you’ll see | Where to look |
|---|---|---|
| A fake name | John Doe, or strings of letters and numbers | Orders → Abandoned checkouts, and Customers |
| A new email every time | Addresses nobody will ever read | Abandoned checkouts |
| Failed payments | Several payment attempts per checkout: declined cards, wrong security codes, postcode mismatches | The checkout’s Timeline |
| A cheap product | Merchants report a single unit of the lowest-priced item | The checkout’s items |
| A reused address | In some attacks, one shipping address repeats while the emails change | Abandoned checkouts |
Two details from Shopify’s documentation change how you read that list. Checkout attempts Shopify identifies as card testing or bot activity “aren’t included in abandoned checkouts”, so the fakes you still see are the ones it didn’t catch. And “some attacks involve attempts to save card details rather than complete a purchase”, so there may be no order at all.
It costs you even without orders. Shopify warns that a surge of declines “can also increase your decline rate for legitimate customers, even after an attack stops”, and that an uncaptured authorisation can still appear on the real cardholder’s statement and lead to a chargeback, which counts towards your chargeback rate “regardless of whether you win or lose the dispute”. If some test orders did go through, handle them as high-risk orders: see what “high risk of fraud detected” means.
What stops it inside Shopify?
Your payment settings do most of the work. With Shopify Payments, card testing protection and high-risk blocking are already on; add Fraud Control rules and stricter card checks, and capture payments manually while an attack lasts.
| Tool | What it does | Needs |
|---|---|---|
| Card testing protection | Built-in protection against card testing at checkout; no settings | Shopify Payments |
| High-risk payment blocking | Stops risky payments before an order exists and lists them in the Blocked view of abandoned checkouts | Shopify Payments |
| Fraud Control checkout rules | Blocks checkouts that match an email, address or IP you choose | Shopify Payments |
| CVV and AVS checks | Declines charges that fail the security-code or postcode check | Shopify Payments |
| Manual payment capture | Lets you review orders before any money is taken | Settings → Payments |
| Shopify Flow | Holds, cancels or tags risky orders automatically | Basic plan or higher |
| Checkout bot protection | Challenges bots at checkout during a scheduled sale of up to 60 minutes, but “isn’t meant to combat forms of fraud that are related to bot activity” | Shopify Plus, activated by Plus Support |
Checked 24 September 2026 against Shopify’s pages on preventing fraud, fraud analysis, the Fraud Control app, Shopify Flow and checkout bot protection.
Tighten Shopify Payments’ card checks
- From your Shopify admin, go to Settings → Payments.
- In the Shopify Payments section, click Manage.
- In Fraud prevention, click Reduce credit and debit card fraud.
- Keep Use automated settings, or turn it off and activate Decline charges that fail CVV verification and Decline charges that fail AVS postal code verification.
Note: Not every card-issuing bank supports these checks, and Shopify notes that turning on AVS checks can increase failed transactions, including real customers’ (configuring Shopify Payments).
Block the pattern with Fraud Control
- Install Fraud Control from the Shopify App Store, then go to Apps → Fraud Control.
- Click Rules, then Create rule.
- Add checkout conditions that match the attack, such as a shipping address the bot keeps reusing or the email addresses it has used.
- Click Save. The rule turns on straight away.
Rules work only with Shopify Payments, and the bots rotate emails: one merchant was keeping more than 700 addresses blocked (thread). A checkout a rule blocks still shows in your abandoned checkouts, so rules stop the payments, not the list from growing.
Capture payments manually while it lasts
- Go to Settings → Payments.
- In Payment capture method, select Manually.
Then capture only the orders you’ve checked, within the authorisation period: seven days with Shopify Payments (payment authorisation). Cancelling a test order before capture helps, but Shopify notes it “doesn’t prevent the cardholder’s bank from filing” a chargeback.
Take away the target
Merchants report the bots go for the cheapest product, and Shopify lists a high volume of free orders as a sign of bot activity. While an attack runs, unpublish the low-price or free item it keeps using.
Use the emergency brake: required sign-in
In Settings → Checkout, under Customer contact method, you can turn on Require customers to sign in to their account before checkout. Checkout then accepts email only, and accelerated buttons such as Apple Pay no longer appear in the cart (checkout form options). With new customer accounts, signing in needs a one-time code sent to that email (customer accounts), which a bot using invented addresses can’t receive. It can also cost you real orders, so keep it temporary.
Not on Shopify Payments?
Card testing protection, high-risk blocking and Fraud Control rules are Shopify Payments features. Use your payment provider’s own fraud settings, and consider manual capture: Shopify notes that third-party transaction fees “aren’t returned to you when you issue a refund” (preventing fraud).
Still flooded? Tell Shopify
A product manager on Shopify’s Checkout team wrote in April 2026 that Shopify is “continuing to strengthen our bot protections to reduce this activity at the source”, and asked merchants still seeing the problem to “contact Shopify Support and include your store URL along with examples from a recent timeframe” (thread).
Can a storefront blocker app stop it?
Not directly. Shopify hosts the checkout and storefront apps run in your theme, so a bot that goes straight to checkout from a cart link never meets them. X Shield, which we build, says so in its own FAQ: “X Shield cannot control the hosted Checkout (including Shop Pay) or block payment authorizations.”
Storefront blocking helps only at the edges:
- Bots that browse first. If a bot loads your storefront before checking out, from a cloud network or a country you don’t sell to, blocking it there can end the visit before the cart, unless it then follows a direct cart or checkout link. Bots that never run your page’s JavaScript aren’t stopped; see what a storefront blocker can’t stop.
- Evidence once an order exists. On paid plans, X Shield’s order protection checks each new order against its storefront block history and the order’s network, and flags risky ones in Shopify’s fraud analysis. Higher plans can also tag the order or hold its fulfilment. It never cancels anything, and it acts only after the order is placed.
If bots that browse first are part of your problem, X Shield, a free country and bot blocker for Shopify, covers that storefront layer; keep Shopify’s checkout defences for the rest.
Apps that act at checkout work differently. They add checkout rules, built on Shopify Functions, that run inside Shopify’s own checkout, so they don’t depend on the buyer loading your theme. You manage them under Settings → Checkout → Checkout rules (checkout customisation).
How do I protect my email list and sender reputation?
Stop emailing the bots. Keep abandoned-checkout emails to marketing subscribers, suppress the fake profiles in your email platform, and keep hCaptcha on your forms.
Shopify lists bots that mass-create customer sign-ups as harmful, because they degrade “domain and email reputation” (bot types). Merchants add that recovery emails to invented addresses bounce, and the bounces can drag down delivery of real order emails too.
- From your Shopify admin, go to Apps → Messaging → Automations and open the Abandoned checkout automation.
- Click Edit → Edit email and check the To: field. By default the email goes only to customers subscribed to email marketing; if it says All customers, switch it back while the attack lasts.
- If you still use Shopify’s legacy abandoned checkout email, check its Send to setting too (abandoned checkouts).
Checkouts that Shopify Payments blocked as high risk never get a recovery email (new abandoned checkout automation).
The fakes reach your email platform too: one merchant found them in Klaviyo, unsubscribed from marketing (thread). Build a segment on the bot’s name or reused address, suppress it, and exclude it from cart and checkout flows. If your platform bills by profile count, the fakes cost money until you remove them.
For sign-up spam, go to Online Store → Preferences → Spam protection and keep both hCaptcha boxes ticked. They cover contact, newsletter and comment forms and the legacy account pages, not checkout, and a third-party CAPTCHA app can conflict with them (preferences).
Can I delete the fake checkouts?
No. Shopify says there is “no way to manually delete a specific abandoned checkout”; they are deleted automatically after three months. You can delete the fake customer profiles, though.
- Go to Customers and search for the bot’s name.
- Select the fake profiles.
- Click the icon next to Bulk edit, then Delete customers.
- Click Delete to confirm. The profiles disappear from your customer list.
Profiles linked to an order can’t be deleted, and deleting can’t be undone (managing customers). For a steady stream, a Shopify Flow workflow can do it: the Customer created trigger, a condition that matches the bot’s name, and the Delete customer action. Tag instead of deleting for the first week, to make sure no real customer matches.
When you compare periods, leave the attack out. Session reports now hide the bots Shopify identifies by default, as explained in Shopify bot traffic from Singapore and China.