Fraud monitoring for Shopify

Monitor your
Shopify store.Investigate
every attack.

The accounts look different.
CommerceGuard reveals the connections
and gives you the evidence.

Scan 60 days of orders · Free · Read-only

Identity resolutionIllustrative finding

Seven accounts. The same shipping address.

7accounts
1linked identity
Explore the evidence
Visibility first. Your store stays in your hands. See how an attack unfolds
Multi-accounting◆Promo abuse◆ Refund abuse◆Account takeover◆ Card testing◆Chargeback fraud◆ Interception fraud◆Reshipping◆ Bot checkout◆Insider abuse◆ Vendor breach◆Credential stuffing◆
Illustrative case · CG-2481
One morning, connected

One person. Seven accounts.

Your Shopify store, one morning. Every parcel is an order. Scroll to watch one person arrive as seven.

Open case
09:14 Account 1 created gmail alias, new device
Read the attack timeline
  1. Account 1 createdNew email alias and device.
  2. Promotion abuse detectedA second linked account redeems the code at the same address.
  3. Seven accounts linkedEleven orders consumed $418 in discounts.
Attack patterns

Look beyond
the promo code.

Explore three illustrative attack patterns, from repeated discounts to refunds and account takeover.

01

The promo ring

CG-2481 · From the replay
Shared address7 of 7

All seven accounts share one shipping address. An address match is evidence to review, not a verdict on its own.

Reused phone3 of 7

Three accounts reuse a phone number, adding another connection to the address match.

Email aliases6 of 7

Six accounts use email aliases. Together with the address and phone, they form a pattern worth investigating.

How the attack unfolds
  1. One person opens 7 accounts with +alias emails
  2. All ship to the same address, minutes apart
  3. Each redeems the single-use welcome code
  4. Orders ship before anyone joins the dots
$41811 orders · $38 per redemption

The connection: a shared address, reused phone and email aliases.

Continue the investigation
02

The refund farmer

Serial refund abuse
How the attack unfolds
  1. A household orders across three accounts
  2. Every order is refunded on the same reason code
  3. Refund rate sits 6x above their own baseline
  4. Support clears each one on its own merits
$1,240refunded per month, quietly

Repeated refund reasons and a rate six times the household's baseline.

Explore the evidence
03

The takeover wave

Credential stuffing to ATO
How the attack unfolds
  1. Leaked passwords are tried against your logins
  2. A handful land on real customer accounts
  3. Delivery address is changed after payment
  4. Goods ship to an address the customer never used
$2,100at risk before anyone notices

A new device, exposed credentials and a delivery change after payment.

Explore the evidence
Your store, in perspectiveEstimate your exposure.Explore the estimate
Illustrative estimate

Start with your order volume.

Adjust the sliders to explore the cost of a promo ring. The assumptions stay visible beside the result.

Estimated annual exposure $18,360

Assumes 15% of orders carry a promotion, 6% of those are coordinated, at a 20% discount. Your real number is whatever the scan finds.

Find my real number
How CommerceGuard works

From store data
to a decision.

  1. 01

    Connect

    Connect your store with read-only access. Review the requested permissions before approving.

  2. 02

    Scan

    Review the previous 60 days of orders, customers and discounts in one pass.

  3. 03

    Resolve

    See which accounts belong together, with the signals behind each connection.

  4. 04

    Detect

    Understand which rule matched and why. Every finding keeps its supporting evidence.

  5. 05

    Decide

    Open the case, inspect the order trail and choose your next step.

Illustrative workspaceCG-2481
Permission request
  • read_ordersOrders, discounts, refunds
  • read_customersAccount history
  • read_discountsPromotion rules
write accessnot requested
Historical scan · 60 days
0orders
0customers
0discounts
  • bulkorders/2026-07 · 4,096 rowsok
  • bulkcustomers · 2,048 rowsok
  • normaddress canonicalisedok
  • tokenhm_9f41…c7e2ok
CG-2481 · Identity resolution

7 accounts connect to 1 identity

09:44 · Second redemption
match: promotion = restricted
match: 2 accounts, same shipping address
never: client_ip alone
→ linked WELCOME20 redemptions
Incident CG-2481 openedWELCOME20 ring · $418 consumed
CG-2481 · Ready to investigate
7 accounts. 11 orders.$418 in discounts, connected.
  • Shared shipping address
  • Reused phone number
  • Email alias pattern
Open this case

Read-only evidence. Your store stays in your hands.

The product

Your next move.

Open a case. Follow a connection. Try a review decision. Illustrative data throughout.

Open the interactive demo
CommerceGuard Illustrative Shopify store Interactive demo

Incidents

IncidentAccountsImpactRiskStatus

Pick any row to open the case

Illustrative data. Explore a case, its accounts and the evidence.

Find your evidence

    See this on your own Shopify store.

    The scan is free and read-only. If there is nothing there, we will tell you that too.

    Scan my store free
    What it does

    Monitor. Detect.
    Investigate. Respond.

    From an ordinary order to a decision you can explain.

    Monitor

    Keep orders, accounts and refunds in view.

    • Continuous monitoring
    • History reconciled automatically
    • Visible coverage and last sync

    Detect

    Find the patterns that order-by-order review misses.

    • Risk and confidence kept separate
    • A reason behind every finding
    • Versioned detection rules

    Investigate

    Follow one case from connected accounts to financial impact.

    • Accounts and their shared signals
    • Impact with its supporting orders
    • A record of each review

    Respond

    Choose your next step with the evidence in front of you.

    • Prioritise cases for review
    • Read-only first release
    • Store actions stay in your hands
    Scan your previous 60 days of orders, free Scan my store free
    Why it works

    Built to be argued with.

    Evidence, not a score

    Every incident shows the exact rows behind it. No black box to trust.

    Risk ≠ confidence

    Severity and strength of evidence, shown separately.

    Risk
    82
    Confidence
    64

    Your store, your decision

    The first release reads your store. It cannot block a customer or change an order.

    Never merges on IP

    Households and offices share networks. That is not evidence.

    Money you can act on

    CG-2481: $152 of the $418 total sits on orders awaiting review. It is a subset, not an extra loss.

    Discount consumed
    $418
    Awaiting review
    $152
    What it catches

    Four fronts.

    Explore each area. Highlighted techniques are the first-release focus.

    001Customer fraud
    Multi-accountingPromo abuseRefund abuseAccount takeoverCard testingChargeback fraudInterceptionReshippingBot checkout
    002Staff and operations
    Social-engineered refundsPost-payment address changesSuspicious staff actionsDormant accessApproval policies
    003Exposure and vendors
    Leaked customer credentialsStealer logsVendor breachesApp permission driftLeaked API keys
    004Investigate and respond
    Identity graphEvidence trailFinancial impactAudit logReversible actionsChargeback packs
    Security

    We hold your customer data.
    So we hold ourselves to this.

    01

    Read only

    Three scopes, all read. CommerceGuard cannot change anything in your store, because it never asks for the permission to.

    read_ordersread_customersread_discountsno write
    02

    Tokenised on arrival

    Emails, phones and addresses become store-scoped HMAC tokens the moment they land. Raw values never join the graph.

    Illustration: an email becomes a token. The connection remains.

    03

    EU only

    Hosted in Falkenstein, Germany. Raw payloads expire after 7 days, normalised facts after 180.

    DEFalkenstein
    04

    No card data, ever

    Card numbers and CVV stay outside the evidence graph. Detection uses the permitted payment identifiers.

    4242 4242 4242 4242
    05

    A traceable decision

    Every state change and every sensitive read writes an append-only record with actor, timestamp and policy version.

    14:31:02 · analyst · viewed CG-248114:32:10 · analyst · marked for review14:32:10 · system · review recorded

    Questions.

    Will it slow my store down?

    No. There is no storefront script and no checkout extension. Everything runs in our backend, off Shopify's critical path.

    Can it block a good customer?

    It cannot block anyone. The first release holds no write scopes, so the worst case is a wrong recommendation.

    What if it gets something wrong?

    Mark it a false positive with a reason. That is recorded against the rule version and feeds calibration.

    Do you train AI on my data?

    No. AI only rewrites an incident the rules already found, using redacted evidence. It cannot create a finding.

    How fast do I see something?

    The scan reviews your previous 60 days of orders. Completion time depends on your store history. We confirm the scope before you connect.

    Design partner pilot

    Find out who is working your store.

    A free scan of your previous 60 days of Shopify orders. Read-only access, no card required.

    Request a free scan

    Preview form. Requests are not sent yet.

    1. 1Confirm your store and scan scope
    2. 2Connect with read-only access
    3. 3Review your findings together