
We’re all familiar with bots — computer programs that automate tasks, then perform them in a fraction of the time it would take a human being.
Bots have all kinds of practical applications (like indexing web pages or helping customers when a live person isn’t available). But bad actors have found ways to use bots for their own devious ends, including testing stolen credit card numbers. The impact hits smaller businesses particularly hard, since they often have fewer resources and personnel to devote to fighting bot attacks.
Tracking Bot Behavior
Shop owners typically discover bot activity when they notice strange patterns on their e-commerce sites. Lauren Scott* who sells craft tools and accessories on her website, noticed that a wholesale catalog on her site was being downloaded numerous times by the same customer. She couldn’t imagine why a customer would keep downloading the same PDF repeatedly. She was able to stop the downloads by changing online access to the catalog, but it alerted her that bots were active in her shop.
Scott next saw an increase in the number of abandoned shopping carts on her site. While it’s not unusual for a customer to start adding items to a cart and then get distracted, the number of abandoned carts became unusually high – as many as fifty abandoned carts in a day.
Diane Scarponi, who sells sewing patterns on her website StyleFalcon, saw a similar trend on her e-commerce site – including a day when seven or eight carts were abandoned within the space of an hour. Her platform automatically sends a reminder email within a few hours of a potential shopper abandoning their cart. She disabled this setting to stop the platform from sending large batches of emails at the same time. When Scarponi looked more closely, she saw that many of the abandoned carts were transactions rejected by her platform’s credit card processor.
Both shop owners noticed patterns in the specific products placed in the abandoned carts. Initially, Scott’s phantom shoppers were putting $200 gift cards in the cart. When she marked $200 gift cards as out of stock, the “customers” began adding $100 gift cards to the cart. Later the pattern shifted to small items with low prices, a single tapestry needle, say, or a $10 sale item. “As soon as I deactivate the product, the problem goes away for a little while,” she explains, “but then it pops up eventually with a different item. It’s like Whack-A-Mole!”
Scarponi, who sells PDF and paper sewing patterns, noticed that bots were adding only PDF patterns to their carts. PDF products, of course, don’t need to be shipped, and orders are processed nearly instantaneously, allowing scammers to get in and out of the platform quickly.
How Card Cracking Works
The patterns described above are signs of card cracking, a way to test and verify stolen credit card numbers. The scam begins when a bad actor obtains a stolen credit card number along with the card owner’s name. (Scammers get lists of stolen card numbers from the dark web, from associates in retail, or via phishing calls.) The problem: the scammer usually is given only the customer’s name and card number. Yet most card processors require corroborating information — the customer’s address or ZIP code, the card expiration date, and the validation number printed on the card (the CCV). Another potential problem: by the time the scammer gets the name and card number, the customer may have already reported the card missing, deactivating it.
Bots help bad actors solve both problems. The scammer sends an army of bots posing as customers to online shopping sites. The bots add small, low-cost items or a downloadable product to the cart. They then enter a stolen credit card number, along with a random combination of ZIP code, expiration date, and CCV. If the transaction goes through, the scammer has the information necessary to make larger purchases elsewhere and knows the card number is still active.
It’s not very easy to guess these three security measures right off the bat. Repeatedly trying different variations of zip code, expiration date, and CCV would take months or years if one individual person were to try them. By automating the task, bots can test thousands of combinations quickly. Each abandoned cart likely corresponds to an attempt by a bot to discover the magic numbers that will enable the scammer to make fraudulent charges.
Battling the Bots
Bot traffic like this creates all kinds of headaches for small business owners. Scarponi, for example, who deactivated automated follow-up emails when customers abandon carts, potentially loses out on legitimate transactions that might result from sending reminder emails. Scott worries that when Shopify sends out a rash of abandoned cart emails in a short time, they will be tagged as spam. Of course, the time and aggravation that site operators experience is wearying — time they could have used to develop new products, ship orders, or provide customer service.
Scarponi and Scott have had some success in tackling the bots that plague them. Both now review emails and transaction data each month, looking for sketchy activity. They may notice a name that seems off or find that the same name is attached to multiple addresses. Occasionally a bot will use a name or address that raises alarm bells (is there really a guy named John Smith living at 123 Main St.?). Scott recently noticed a rash of phantom customers who all identified themselves as doctors — quite a coincidence to have twenty doctors all shopping on the same day!. Given that both Scott and Scarponi have customer bases which are predominantly women, an excess of male names may also trigger a second look.
While blocking specific names or addresses can provide temporary relief, you’ll need some site-wide fixes to deter card-cracking bots:
- Add CAPTCHA technology to your site. If you’re concerned that using CAPTCHA will annoy regular customers, you can use technology that runs risk assessment in the background, only requiring CAPTCHA for transactions that look suspicious.
- Use geoblocking software, which allows you to block specific IP addresses or addresses located in specific countries. Once she saw that clusters of bot activity could be traced to just four or five countries, Scarponi blocked transactions from those countries and saw a noticeable decrease in the number of bots. Some software allows you to create a list of trusted emails that won’t get blocked or flag customers using VPNs or proxies.
- Take advantage of fraud-tracking alerts that your platform provides. For example, some platforms will flag high-risk transactions, allowing you to manually approve or reject them if they appear sketchy.
- Make sure that you keep up with updates and security patches for your software. While it may not stop a specific bot attack, your site will remain resilient and less welcoming to nefarious actors.
Bot traffic has increased substantially in the past several years, and all indications suggest that the problem will only get worse. It makes sense to monitor customer activity on your site to see whether you’ve got a bot problem, then use your platform’s security features and additional tools to stop bots in their tracks.
*A pseudonym.

Carol Sulcoski
contributor
Carol J. Sulcoski is an attorney by day and a knitting author, designer and dyer by night. Her latest book is “Yarn Substitution Made Easy” (Lark Crafts 2019). She lives outside Philadelphia with her three nearly grown-up children and a fluffy orange cat.

