HomeBlogThe Shopify Fraud Prevention Glossary
Fundamentals2026-06-148 min read

The Shopify Fraud Prevention Glossary

A skimmable reference to the fraud terms every Shopify merchant runs into — AVS, CVV, chargebacks, representment, friendly fraud, velocity, ATO, BIN, 3DS, MCC, and more.

The Shopify Fraud Prevention Glossary

Fraud prevention has its own dialect, and the jargon gets in the way of good decisions. When a payment provider warns you about your chargeback ratio, or a fraud app flags a BIN mismatch, or your processor mentions 3DS, you need to know what they actually mean.

This is a plain-English reference to the terms you will meet running a Shopify store. Skim it, bookmark it, and come back when a term trips you up.

Card and identity verification

AVS (Address Verification System) — A check that compares the billing address the shopper entered against the address the card issuer has on file. A mismatch is a risk signal, though legitimate customers do sometimes fat-finger their address.

CVV / CVC (Card Verification Value/Code) — The 3- or 4-digit code on a card. Because it is not stored after a transaction, a correct CVV suggests the buyer physically has the card. A fraudster with a stolen card *number* often does not have it.

3DS (3-D Secure) — An extra authentication layer (branded as Visa Secure, Mastercard Identity Check, etc.) that asks the shopper to confirm identity with their bank, often via a one-time code. When 3DS is used, liability for fraud typically shifts from the merchant to the issuer.

BIN (Bank Identification Number) — The first six to eight digits of a card, identifying the issuing bank and country. A BIN mismatch — say, a card issued in Vietnam used with a US billing address and a Brazilian IP — is a classic fraud pattern.

Tokenization — Replacing sensitive card data with a non-sensitive stand-in ("token") so real card numbers are never stored on your systems. Reduces both fraud exposure and PCI scope.

Chargebacks and disputes

Chargeback — When a cardholder disputes a charge with their bank and the funds are forcibly reversed. You typically lose the product, the payment, *and* a chargeback fee. Too many, and your processor may penalize or drop you.

Chargeback ratio — Chargebacks as a share of your transactions (or transaction value). Keep it under 1%; card networks treat higher ratios as a serious problem.

Representment — The process of disputing a chargeback by submitting evidence (proof of delivery, AVS/CVV match, customer communication, IP logs) to argue the charge was valid. Your win rate on representment depends heavily on evidence quality.

Friendly fraud (first-party fraud) — A real customer who received the goods but disputes the charge anyway — claiming they never ordered it, never got it, or forgot the purchase. It looks like legitimate fraud to the bank but originates from your actual buyer.

Chargeback fee — The flat fee (often $15–$40) the processor charges per dispute, win or lose. It stacks on top of the lost revenue.

Fraud types and attacks

Card testing (carding) — Fraudsters run many small transactions to check which stolen card numbers still work, often via bots. Signs include bursts of low-value orders and many failed payments before a success.

ATO (Account Takeover) — An attacker gains access to a legitimate customer's account (via leaked passwords or phishing) and uses saved payment methods or loyalty balances to make fraudulent purchases.

Reshipping fraud — Goods are shipped to a middleman address (often a freight forwarder or a recruited "mule") to obscure the fraudster's real location before the items move on.

Triangulation fraud — A fake storefront takes a real customer's order and payment, then uses stolen card data to buy the item from a legitimate store (like yours) and ship it to the unwitting customer. You get the chargeback later.

Refund/return abuse — Exploiting return policies dishonestly: claiming non-delivery, returning empty boxes, or wardrobing (using an item then returning it).

Promo/coupon abuse — Creating multiple accounts or exploiting stacking loopholes to abuse discounts and first-order offers.

Traffic and network signals

VPN (Virtual Private Network) — Routes a user's traffic through another server, masking their real IP and location. Common among *legitimate* privacy-minded shoppers, so a VPN alone is a weak fraud signal.

Proxy — A server that relays traffic to hide the origin. Anonymizing proxies are strongly associated with fraud and are usually safe to block.

Tor — An anonymity network that routes traffic through multiple relays. Exit nodes are rarely used by genuine shoppers, so blocking Tor exit nodes is low-risk, high-value.

Datacenter IP — An IP belonging to a hosting provider (AWS, cloud servers) rather than a residential ISP. Real customers browse from residential or mobile IPs, so datacenter traffic on a checkout is suspicious.

Geolocation (geo-IP) — Estimating a user's physical location from their IP. A large mismatch between IP location, billing country, and shipping country is a strong risk signal.

Device fingerprinting — Identifying a device from its attributes (browser, OS, screen, fonts) to recognize returning fraudsters even when they change IPs or emails.

Velocity — The rate of activity from a single source — orders per IP, attempts per card, sign-ups per email — in a time window. High velocity is a hallmark of automated fraud, and velocity limits are one of the simplest effective defenses.

Bot traffic — Automated, non-human requests. In a fraud context, bots power card testing and credential stuffing at scale.

Payments and classification

MCC (Merchant Category Code) — A four-digit code classifying your business type. It affects interchange fees, some fraud risk models, and which rules apply to your account.

Interchange fee — The fee paid to the card-issuing bank on each transaction, a core component of your total processing cost.

Payment gateway — The service that securely transmits transaction data between your store, the processor, and the banks.

PCI DSS — The Payment Card Industry Data Security Standard: the security requirements for anyone handling card data. Using a compliant gateway and tokenization keeps most of the burden off your store.

KYC (Know Your Customer) — Identity-verification requirements, more common in regulated or high-value contexts, used to confirm a customer is who they claim to be.

How the terms fit together

These are not isolated definitions — they describe one connected system. A fraudster uses a stolen card (failing CVV or AVS), hides behind a proxy or datacenter IP (a geo mismatch against the BIN country), runs card testing at high velocity, and — if it works — leaves you with a chargeback you may fight through representment. Understanding the vocabulary is the first step to reading those signals and stopping the order before it costs you.

Much of this can be caught before an order is even created. Shieldy — Fraud Filter blocks Tor, proxy, VPN, datacenter, and bot traffic at the checkout level and scores fraud risk on orders — turning the terms above into automated protection. Start free and explore the pricing tiers as your store grows.

Protect your Shopify store today

Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.

Install on Shopify — Free