Suspicious orders or customer accounts are appearing
Orders placed with different bank cards within minutes, or dozens of customer accounts created the same night: this is almost never a rush of genuine traffic, but an automated test or abuse.
Two distinct scenarios, two different causes
- A burst of failed orders within minutes, each with a different card number, often for an identical or very low basket amount
- These attempts arrive at any hour, including the middle of the night, at a frequency no human visitor could reach by typing manually
- The billing name and address change with every attempt, unrelated to the visitor's IP address or apparent location
- Dozens or hundreds of customer accounts created in a single night, with email addresses following a very similar pattern (number sequences, disposable domains)
- None of these orders or account creations is ever followed by normal browsing of the catalogue
Carding, and why your store gets used for it
A burst of failed orders with different cards matches a known practice called carding: an attacker tests card numbers in bulk to find out which ones are still valid, before reselling or using them elsewhere. I won't detail how those numbers are obtained here, only the observable symptom: your checkout page is being used as a verification tool, not a way to buy. A small merchant is an attractive target for this precisely because their checkout page is often less protected than a large retailer's against repeated automated attempts.
Mass creation of fake customer accounts generally follows a different logic: building up a pool of credentials to later test password combinations reused elsewhere (a technique called credential stuffing), artificially inflating volume for a poorly protected affiliate or referral scheme, or simply bloating a database to slow it down. These two phenomena don't share the same technical cause, but they do share one thing: they exploit the fact that an order or sign-up form accepts automated submissions at a rate no human can reach, with no limit or check.
On PrestaShop, this kind of abuse is sometimes made easier by a flaw in a poorly secured payment or account module, which for instance leaves an entry point reachable without going through the cart's normal checks. I'll stay general on this point, as I don't have a specific vulnerability identifier to cite here: what matters for a merchant is checking whether the module in question has had a recent update, and treating any third-party payment module as a priority area to watch.
What to check and do
-
Isolate the orders involved without deleting them
They serve as evidence for your payment provider and, where relevant, for a report if your merchant account is questioned.
-
Contact your payment provider
A spike in declined transactions in a short time is a signal they're also monitoring; reporting it promptly avoids a unilateral suspension of your merchant account.
-
Set a rate limit on the checkout and sign-up forms
A maximum number of attempts per IP address within a given window blocks most automated scripts without inconveniencing a genuine customer.
-
Add an anti-bot check on exposed forms
A check of this kind, correctly configured not to inconvenience a human visitor, sharply cuts the volume of automated submissions.
-
Purge the identified fake customer accounts
After confirming none of them placed a genuine order, these accounts should be removed so they don't distort your statistics or remain exploitable.
Going further
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.