Shopify Bot Checkouts: What We Saw and What Stops Them
A bot ran 8,468 fake checkouts on a Shopify store we manage and signed 6,695 fake subscribers up to email. What happened, what worked and how to clean up.

If your Shopify store suddenly shows hundreds of abandoned checkouts a day, each for one cheap product, with no address and an email address that looks machine made, you are dealing with bots. The checkouts themselves cost you nothing. The damage is to your email list: bots that tick the marketing box become subscribers, your welcome flow emails them, most of those addresses bounce, and your sender reputation pays for it. So the first job is to stop your own automations emailing them, the second is to stop new bot sign-ups reaching your email platform, and the third is to clean the list before your next campaign. This is what happened on a Shopify store we manage in September 2026, what the store owner and we tried, what worked, and what other merchants and the platforms themselves say.
What happened on a store we manage
The store is an Australian Shopify store on the Basic plan, with Klaviyo for email. We manage its store, its advertising and its email marketing. We are not naming it, or the product the bots targeted, because naming a store tells the next attacker where to aim. Every figure below comes from the store's own Klaviyo event counts and Shopify admin records, counted in Sydney days and pulled on 29 September 2026.
- It started on 9 September. Before that the store logged about two Checkout Started events a day (32 in the 15 days from 25 August). From 9 to 28 September Klaviyo logged 8,468, peaking at 1,190 on 21 September.
- The bots skipped the shop. On 23 September the store's analytics recorded 126 online store sessions and 7 add to carts all day, while 525 abandoned checkouts had piled up by 8:33 pm. Those numbers only add up if the bots went straight to checkout without browsing.
- The fake checkouts we checked all looked the same. One unit of one low priced product, no shipping or billing address, a new checkout every 30 to 60 seconds and sometimes several in the same second, and an email address on a generated pattern (first name, last name and a year or a few digits) at a free mail provider such as Zoho, Yandex, GMX, Proton or AOL. Partway through, the bot switched from one product to another.
- They became subscribers. The customer records the bots created were marked as subscribed to email marketing within seconds of being created. Klaviyo logged 6,695 new email subscriptions between 9 and 23 September, against about three a day before. By 23 September more than 6,500 customer records matched our bot rule.
- The welcome flow did the attacker's work. The store's welcome series starts when someone joins the list, so it emailed every bot. From 8 to 23 September about three in every four welcome emails hard bounced, and the store logged 5,993 bounced emails between 9 and 23 September, against 6 in the 15 days before.
- Real sales were untouched. Genuine orders carried on at zero to three a day before, during and after, and paid normally.
Two details surprised us. First, the abandoned cart flow did not fire on the bots: it starts on Added to Cart, and the bots did not add anything to a cart. Its sends stayed at one to four a day throughout. Only flows that start on joining the list, or on Checkout Started, were exposed. Second, Klaviyo appeared to be removing some bots by itself. It was not detecting them: Klaviyo suppresses an address as soon as it hard bounces once (Klaviyo's help article on bounces, last checked 29 September 2026), so every one of those removals followed a real email that bounced and counted against the store.
What worked for us
Late on 23 September, Sydney time, the store installed CartWatch, a Shopify app that checks abandoned checkouts for bots, tags bot customers in Shopify and suppresses them in Klaviyo. Nothing was changed at checkout: the email sign-up box stayed on and customers were not made to sign in. From the next day:
| Measure (per Sydney day) | Before the attack | During (9 to 23 Sep) | With the app (24 to 28 Sep) |
|---|---|---|---|
| Checkout Started | About 2 a day | 86 to 1,190 a day | 224 to 394 a day: the bots kept coming |
| New email subscribers | About 3 a day | 77 to 1,188 a day | 0 to 2 a day |
| Bounced emails | 6 in 15 days | 76 to 1,099 a day | 24, then 2, then none |
The app did not stop the bots from creating checkouts. It stopped those checkouts from turning into subscribers and emails, which is the part that did harm.
To stop the checkouts themselves, the store owner then set up the firewall in Armex, a Shopify app that blocks bot traffic, on the night of 28 September. There were 22 bot checkouts in the four hours before 4 am Sydney time on 29 September, then two from 4 am to 7 pm, which is the store's normal rate. The timing points to the firewall. We cannot rule out that the attacker stopped at the same moment, and 15 quiet hours are not proof it is over.
One thing we got wrong: the first campaign we sent after the bot filter went in, on 29 September, still bounced at about 5.8% (57 bounces against 923 delivered), and most of the bounces we could trace to a domain were on yandex.com, one of the bot domains. Those were bot profiles created before the bot filter went in, which were still on the list. Clean the list before the next send, not after it.
How to tell if it is happening to you
- Abandoned checkouts far above your normal rate, while online store sessions and add to carts stay normal.
- Checkouts for one cheap product, one unit at a time, with no address, arriving every minute or so around the clock.
- Email addresses on a pattern: name, name and digits, at free mail domains, often the same handful of domains.
- New customer records with no name, no address and no orders, marked as subscribed at the moment they were created.
- A jump in bounces on your welcome flow, and new subscribers in Klaviyo with no matching sign-up form activity.
Klaviyo lists similar signs for what it calls list bombing: a sudden spike from one entry point in a short window, clusters of the same email domains, unusual names and a common source (Understanding list bombing and how to remove fake profiles, updated 5 August 2025, last checked 29 September 2026).
Why bots do this
Nobody outside the attacker can know for certain, and we did not find a source that proves the motive for this pattern on Shopify. These are the explanations with some evidence behind them:
- Card testing. Bots put stolen card numbers through a checkout to see which ones work. This is the most common explanation in Shopify's forums, and Shopify's June 2026 change (below) targets it. It did not fit our store: the fake checkouts we sampled had no shipping address, so they had not reached the payment step, and genuine orders paid normally throughout.
- List bombing or subscription bombing. Bots push addresses through sign-up forms in bulk. Klaviyo says the aim is to fill a list with invalid contacts and damage the sender's reputation. Spamhaus described the related tactic of flooding a victim's inbox with sign-up confirmations back in 2016, and recommended CAPTCHA plus confirmed opt-in against it (Spamhaus, Subscription bombing, 16 September 2016). About three in four of the welcome emails sent to the bots hard bounced, so most of the addresses did not exist. That fits poisoning the list better than bombing real people's inboxes.
Either way, the defence is the same: stop the bot's sign-up from reaching your list, and make sure your automations cannot email an address nobody confirmed.
What other merchants report
This is not new, and the reported volumes have grown. Threads on the Shopify Community forum describe the same pattern in waves since at least early 2024:
- February 2024: a bot nicknamed "James James" ran repeated checkouts on free and zero dollar products, up to 14 in 12 minutes. Deleting the customers did not help because the bot came back. One merchant said the bot stopped after they set their free items to draft (James James and the world of Automated Abandoned Cart Robots).
- April to May 2025: merchants reported hundreds and then more than 1,000 bot checkouts a day, with generated emails and fake addresses. CAPTCHA and bot protection apps were reported as ineffective. The one merchant who reported the bots stopping entirely had added bot filtering at the network layer, with custom setup (Tons of bots creating and abandoning carts).
- March 2026: hundreds of fake checkouts a day on new, cheap products. reCAPTCHA, Shopify's fraud analysis and Shopify Flow did not stop them. A Shopify product manager replied on 28 April 2026 that Shopify was strengthening its bot protections; a merchant later reported abandoned checkouts up 18.4% over the most recent four weeks (Card Testing Bot Attack Flooding Our Store With Hundreds of Fake Abandoned Checkouts).
- September 2026: a Shopify Plus store went from about 130 abandoned checkouts in August to more than 11,000 from 1 September, about 94% of them bots, all arriving through direct checkout links without loading the storefront. Suggestions included checkout validation, bot protection apps and turning off the preselected marketing box (Card-testing bot flooding abandoned checkouts on Shopify Plus).
These are single merchants' reports, not measured studies, and each thread was last checked on 29 September 2026. The common threads are clear enough: bots go straight to checkout, storefront CAPTCHA does not reach them, deleting records does not stop them, and they rotate products.
What Shopify does and does not do
- June 2026 change: checkouts that bots use to test stolen card numbers, and that never complete payment, no longer create abandoned checkout records. It covers card testing only; it says nothing about bots that create subscribers (Shopify changelog, 16 June 2026).
- The "Bot protection" setting is not for this. It is Shopify Plus only, switched on through Plus Support, runs for up to 60 minutes over up to 500 products, and Shopify says it is meant for auto-checkout bots at product drops, not fraud related bot activity (Bot protection).
- Checkout validation is open to every plan through apps. Stores on any plan can use public App Store apps that contain Shopify Functions, which is how checkout validation apps work. Only a custom app with its own functions needs Shopify Plus (About Shopify Functions).
All three Shopify pages were last checked on 29 September 2026.
The fixes, in the order we would use them
This order suits a store on Shopify Basic with Klaviyo. Menu paths are from Shopify's and Klaviyo's help pages, last checked 29 September 2026.
-
Step 1 · Do it today
Stop your automations emailing them
- Free
- Stops: emails to bots
In Klaviyo, find every flow that starts when someone joins a list or starts a checkout, and pause it or add a filter that excludes the bot pattern until the rest is in place. Check Shopify's own abandoned checkout email too: Apps, Messaging, Automations, "Abandoned checkout emails by Shopify", then Edit settings (Recovering abandoned checkouts).
-
Step 2
Put a bot filter between checkout and your email platform
- Stopped the damage for us
- Free plan, paid from US$9 a month
- Stops: bot sign-ups reaching Klaviyo
CartWatch lists bot detection on a free plan, Klaviyo suppression and customer tagging from US$9 a month, bot checkout blocking from US$19 and an analytics dashboard at US$39. It launched on 26 May 2026 and had 8 reviews when we checked (CartWatch on the Shopify App Store, last checked 29 September 2026). Other apps offer similar features; we have not tested them, and no independent test of any of them exists that we could find.
-
Step 3
Add a firewall app to stop the checkouts themselves
- Brought our store back to normal
- From US$9.99 a month
- Stops: the fake checkouts
Armex lists plans from US$9.99 to US$39.99 a month, priced by the number of requests it checks, each with a 7-day free trial. It launched in November 2023 and had 53 reviews averaging 4.8 when we checked (Armex on the Shopify App Store, last checked 29 September 2026). As with the bot filters, we found no independent test of it or its competitors.
-
Step 4
Remove the reward: the email box at checkout
- Free
- Stops: bots joining your list
- Costs a few real checkout sign-ups
Klaviyo's Shopify sync adds only customers who agreed to email marketing; someone who types an email at checkout without ticking the box is not added (How to sync Shopify email subscribers to a Klaviyo list). The box appears only while email marketing opt-in at checkout is turned on, under Settings, Checkout, Marketing opt-in, Email (Shopify: customer contact information). Turn it off while the attack runs. At the least, choose "Regions you choose" with no regions selected, so the box is never preselected. Your pop-up and footer forms still collect sign-ups.
-
Step 5
Turn on double opt-in for the list Shopify syncs into
- Free
- Stops: unconfirmed subscribers
- Fewer confirmed subscribers
Klaviyo recommends it against list bombing. A bot that cannot click a confirmation link never becomes a subscriber.
-
Step 6 · If it keeps escalating
Require sign-in before checkout, briefly
- Free
- Hides Apple Pay and costs real sales
- Mixed results reported
Settings, Checkout, Customer contact method, "Require customers to sign in to their account before checkout". Shopify hides accelerated checkouts such as Apple Pay when this is on (Checkout form options). Merchants in the threads above report mixed results, so treat it as a short-term brake.
-
Step 7 · Alongside the rest
Open a Shopify Support ticket with your evidence
- Free
- Slow, limited help reported
Shopify can see traffic you cannot. Merchants report slow and limited help, so do it alongside the steps above, not instead of them.
What does not work well
- Storefront CAPTCHA: bots that go straight to checkout never meet it.
- Blocking email domains: the bots rotate domains, and real customers use the same ones.
- Deleting the fake customers: the bot creates new ones.
- Hiding the targeted product: these bots move between products anyway (ours switched once on its own).
Cleaning up the list
- Export all customers from Shopify (Customers, Export) and filter them locally. Shopify's customer search filters did not return reliable counts for us, so we did not trust them for this.
- Write a strict bot rule and test it. Ours: no orders, no name, no address, created on or after the day the attack began, subscribed within five seconds of being created, and an email on one of the generated patterns. It matched more than 6,500 records and left alone 12 that passed every test except the email pattern and looked like real sign-ups.
- Suppress them in Klaviyo first. Build a segment or upload the list and suppress it, so no campaign or flow can reach them. Klaviyo's list bombing article describes a segment for this: profiles that can receive marketing, got three or more emails in 180 days, and never opened, clicked or ordered.
- Then unsubscribe them in Shopify. A customer CSV import with "Overwrite existing customers" and Accepts Email Marketing set to "no" is the usual route (Importing and exporting customers). Shopify's page does not say whether "no" unsubscribes someone already subscribed, so try it on a few records first. Keep the records until both systems are clean: they are your list of who to suppress.
- Watch the bounce rate on your next campaign. Ours told us the clean-up was not finished.
Why the email side matters
Gmail requires senders of 5,000 or more messages a day to keep the spam rate reported in Postmaster Tools below 0.3%, authenticate with SPF, DKIM and DMARC, and offer one-click unsubscribe (Google email sender guidelines). Yahoo sets the same 0.3% complaint ceiling and tells senders to remove invalid recipients promptly (Yahoo sender best practices). Both last checked 29 September 2026. A welcome flow bouncing three emails in four is the opposite of that. Our store had no spam complaints through the attack, but the bounces alone are the kind of signal mailbox providers watch, and they land on the domain your real customers' order and marketing emails come from.
Common questions
Are fake abandoned checkouts dangerous?
The checkouts themselves are mostly noise in your reports. The danger is what they trigger: marketing sign-ups, welcome and recovery emails to addresses that bounce, and a list full of profiles that drag your email results down.
Will Shopify stop this automatically?
Only partly. Shopify's June 2026 change stops card testing checkouts from creating abandoned checkout records, and its Bot protection setting is a Plus only tool for product drops. Neither is aimed at bots that sign up to your list.
Is this card testing?
Sometimes. If the fake checkouts reach payment and you see failed or tiny payments, it is card testing and your payment provider needs to know. The ones we sampled never got past the contact step, and every one signed up to email, so in our case the target was the list.
Should I delete the fake customers?
Not first. Suppress them in your email platform and unsubscribe them in Shopify, then delete if you want a tidy customer list. Deleting early does not stop the bot and throws away the record of who to suppress.
Why did my abandoned cart flow not fire on the bots?
In Klaviyo it most likely starts on Added to Cart, and these bots go straight to checkout without adding to a cart. Flows that start on Checkout Started or on joining a list are the ones at risk.
Getting help
Our e-commerce team builds and looks after Shopify stores, including the apps, checkout settings and Klaviyo accounts involved here. If bots are hitting your checkout, tell us what you are seeing and we will quote the clean-up and the fix after a short scoping call.
Sources
Store figures are from the store's Klaviyo event counts and Shopify admin, counted in Sydney days and pulled on 29 September 2026. Every page below was read on 29 September 2026. Platforms change these pages and app prices without notice, so check the linked page before you rely on it.
- Shopify changelog: reduced bot noise in abandoned checkouts (16 June 2026)
- Shopify Help Center: Bot protection
- Shopify developer docs: About Shopify Functions (plan availability)
- Shopify Help Center: customer contact information (email marketing checkbox)
- Shopify Help Center: checkout form options (sign-in before checkout)
- Shopify Help Center: recovering abandoned checkouts
- Shopify Help Center: importing and exporting customers
- Klaviyo: Understanding list bombing and how to remove fake profiles (updated 5 August 2025)
- Klaviyo: How to sync Shopify email subscribers to a Klaviyo list
- Klaviyo: bounces and automatic suppression
- Google: Email sender guidelines
- Yahoo: Sender best practices
- Spamhaus: Subscription bombing, COI, CAPTCHA and the next generation of mail bombs (16 September 2016)
- CartWatch on the Shopify App Store (plans, prices and reviews)
- Armex on the Shopify App Store (plans, prices and reviews)
- Shopify Community threads, as linked above: James James (February 2024), Tons of bots creating and abandoning carts (April 2025), card testing bot flood (March 2026) and bot flood on Shopify Plus (September 2026)
Drafted with AI assistance; researched and reviewed by Saad Ali.
Founder / CEO