Managing Fraud Across Multiple Shopify Stores
Running several Shopify stores means fraud shows up in more places at once. Learn how to share rule sets, keep policies consistent, and centralize review across a portfolio.

Running one Shopify store is a fraud problem. Running five is a coordination problem. Fraudsters rarely target a single storefront — they test cards, spoof locations, and cycle through proxies across every brand they can find under the same owner. If each of your stores fights fraud in isolation, you end up with five different rule sets, five different review habits, and five different blind spots.
This guide covers how to treat a portfolio of stores as one defensive surface: shared rules, consistent policies, and a single place to review what happened.
The three problems unique to multi-store
Before tooling, understand what actually breaks when you scale from one store to many.
- Rule drift. Store A blocks Tor and high-risk countries. Store B never got the same config because a different VA set it up. Attackers find B.
- Duplicated review effort. The same suspicious customer places orders on three stores. Three people manually review the same signals and reach three different conclusions.
- Inconsistent policy. One store auto-cancels flagged orders; another emails the customer for verification; a third does nothing. Your chargeback outcomes become impossible to compare.
The fix for all three is standardization first, per-store tuning second.
Step 1: Define a baseline rule set
Write one canonical rule set that every store inherits by default. This is your floor — no store should be weaker than this.
A reasonable baseline for most stores:
- Block Tor exit nodes and known anonymizing proxies outright.
- Challenge or block datacenter IPs (hosting-provider ranges rarely belong to real shoppers).
- Block countries you do not ship to, plus any high-risk regions you have no business in.
- Flag orders where billing and shipping countries mismatch on high-value carts.
- Apply velocity limits: e.g. no more than 3 orders from one IP in 15 minutes.
Tools like Shieldy — Fraud Filter let you enforce these at the checkout level using Shopify Functions, so the block happens before the order is created rather than after money moves. When your baseline is enforced pre-checkout, drift is far less costly — a misconfigured store fails safe.
Step 2: Layer store-specific exceptions on top
Not every store is the same. A US-only supplement brand and a global streetwear shop need different geo rules. The trick is to treat differences as explicit exceptions to the baseline, not as separate configs built from scratch.
Document each exception with a reason:
| Store | Exception | Reason |
|---|---|---|
| Store A (US only) | Block all non-US, non-CA | No international shipping |
| Store B (global) | Allow all countries, keep VPN challenge | Ships worldwide, still filters anonymizers |
| Store C (high AOV) | Manual review over $500 | Chargeback exposure on big orders |
When an exception exists but has no documented reason, that is a red flag — someone loosened a rule and forgot why. Review these quarterly.
Step 3: Centralize review, not just rules
Rules stop the obvious cases. The gray-area orders still need human eyes, and this is where portfolios waste the most time.
Set up a single review queue mindset even if the tooling lives per store:
- Designate one owner (or one shift) responsible for reviewing flagged orders across all stores that day. Rotating this per-store guarantees inconsistency.
- Use the same decision criteria everywhere (see the checklist below).
- Log every decision — order ID, store, signals seen, action taken — in one shared sheet or system. This is what lets you spot the customer hitting three stores at once.
Cross-store review checklist:
- Does this email, phone, or card appear in flagged orders on any other store?
- Is the IP or device fingerprint one you have blocked elsewhere?
- Does the shipping address match a known reshipper or freight-forwarder?
- Is the AOV wildly above this store's normal range?
- Are billing details and IP geolocation on different continents?
Two "yes" answers usually justify a hold-and-verify. Three usually justify a cancel.
Step 4: Share a blocklist across the portfolio
The single highest-leverage multi-store move is a shared blocklist. When you confirm fraud on Store A, that email, IP, or country restriction should propagate to every other store the same day.
Practically:
- Keep a master list of confirmed-bad emails, IP ranges, and countries.
- Apply it as part of the baseline so new stores inherit it automatically.
- Re-check it monthly and expire stale entries — IPs get reassigned, and a permanent block on a rotated residential IP can quietly cost you real customers.
Step 5: Standardize your response policy
Decide once, apply everywhere. For each risk tier, define the action:
- Hard block (pre-checkout): Tor, proxies, non-shipping countries. No order ever created.
- Challenge: VPN or datacenter IP on an otherwise normal order — allow checkout but flag for review.
- Manual review: Geo mismatch, high AOV, or velocity trip — hold before fulfillment.
- Auto-approve: Everything clean.
The point is not the exact thresholds — it is that all your stores use the same ladder, so a customer gets the same treatment regardless of which brand they buy from, and your metrics stay comparable.
Measuring the portfolio
Track these per store *and* rolled up:
- Chargeback ratio (keep it well under 1%).
- Block rate (share of checkouts stopped).
- Manual review volume (if this climbs, your rules are too loose).
- False-positive complaints (real customers who got blocked).
If one store's chargeback ratio spikes while the others hold steady, you have found either a targeted attack or a config gap. Either way, the comparison told you where to look — which is the whole point of standardizing.
Bringing it together
Multi-store fraud management is less about clever rules and more about discipline: one baseline, documented exceptions, one review standard, a shared blocklist, and one response ladder. Get those five things aligned and adding a sixth store stops being a new fraud surface — it just inherits your defenses.
If you want checkout-level enforcement that is easy to apply consistently across every store, Shieldy — Fraud Filter is a low-effort way to make your baseline the same everywhere. Start on the free plan and expand as your portfolio grows — see pricing for what scales with you.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


