Bot Traffic And Fake Orders, The Hidden Cost To Your eCommerce Store
Learn how we overcame an issue which an eCommerce client was experiencing with fake orders and account sign-ups.
Oops! We could not locate your form.
Learn how we overcame an issue which an eCommerce client was experiencing with fake orders and account sign-ups.
If you run a WooCommerce store, you’ve probably noticed the odd failed order or a customer sign-up that never quite completes. Most of the time it’s nothing, just that a customer changed their mind, a card was declined, someone got distracted mid-checkout.
But recently, on one of our clients’ sites, this turned out to be something else entirely. The way we identified this and the fix we put in place overnight is one every eCommerce site owner should know about.
While reviewing routine monitoring data on a client’s WooCommerce site this week, after a reported uptick in transactional email bounces, we spotted two related patterns that had been quietly building for some time:
Both were coming from constantly rotating IP addresses, which is exactly why a simple IP block doesn’t solve the problem. You block one address and the next attempt just comes from somewhere else. This is bot traffic, and automated scripts probing checkout and registration forms at scale, and it’s becoming more and more common.
The volume kept climbing, so we deployed our solution overnight and by the time we checked in the morning, over 5,000 attempts had been detected and blocked in a matter of hours.
It’s tempting to write this off as background noise, but it has real, practical costs:
Every one of those bot requests still has to be processed by your server, your database, your CPU. At scale, that’s wasted hosting resources you’re paying for and, in the worst cases, it can slow the site down for genuine customers.
Fake sign-ups generate a high rate of invalid email addresses. Every bounce from those addresses damages your sender reputation with your transactional email provider (the service that sends your order confirmations, shipping updates, and password resets) and your email marketing provider. Push that reputation too far and you risk being blacklisted, meaning real customers stop receiving real order emails, or your marketing communications. This is actually what first flagged the issue to us, as the email provider got in touch about bounce rates.
For stores that handle fulfilment manually, exporting orders to send to a courier or warehouse, a bot-generated fake order slipping through can mean postage and packing time wasted on an address that was never a genuine customer.
A spike in failed payments can look like a checkout problem or a payment gateway issue, when actually it’s bots hammering the payment form. That’s a frustrating rabbit hole to go down if you don’t know what you’re looking for.
Rather than adding a reCAPTCHA that forces every customer to prove they’re human on every visit, we implemented Cloudflare Turnstile across registration, login, and the checkout.
Cloudflare Turnstile is a modern alternative to traditional CAPTCHA. Rather than making customers solve puzzles or select images, Turnstile runs invisible checks in the background to confirm a real person is submitting the form. Genuine shoppers pass through without noticing a thing, while bot traffic gets blocked before it can place a fake order or create a fake account, keeping order data clean and cutting down on wasted time processing orders that were never going to convert.
We also configured it to fail open, meaning if the Turnstile service itself ever goes down, checkout still works rather than blocking every customer.
Within hours of switching it on, the fake registrations and failed orders dropped off a cliff, with Turnstile challenging and blocking over 5,000 by the following morning, and more than 27,000 at the time of writing.

This kind of incident is also a good reminder that bot protection works best as part of a wider, ongoing security routine rather than a one-off fix. Turnstile solved the immediate problem, but it’s worth being honest about what it didn’t do. It didn’t scan for malware already on the site, it didn’t patch the plugin vulnerability a bot might have been probing for next, and it won’t stop an attack that doesn’t come through a form at all.
That’s why, on every site we manage, solutions like Turnstile sit alongside an established security routine rather than replacing it That routine includes:
A week of monitoring will confirm the drop holds, but we’re also looking further upstream at email validation services (similar in concept to how Akismet filters spam blog comments, but for sign-up forms) that sit between your site and your transactional email provider, checking an address is genuinely deliverable before it ever triggers a welcome email or account creation. These typically run from around £40 to £50 a month depending on volume, and are worth it for any store seeing this kind of activity regularly.
Bot traffic and fake orders aren’t rare, they’re a normal part of running an online store today, and we’ve seen more of it this year than in previous years. The warning signs are usually there before it becomes a real problem – a run of failed payments to the same address, a spike in account sign-ups that don’t match your usual traffic, or a sudden bounce-rate warning from
your email provider.
This example was caught early for our client because the monitoring and maintenance routine flagged it, not because anyone was watching for this specific attack. If any of the warning signs above sound familiar on your site, this is the moment to check, not after the bounce rate becomes a blacklisting, and the failed orders spiral.
Experiencing a similar issue? Get in touch and we can take a look at what is happening on your site.

If you’d like to learn more about our WordPress & WooCommerce Support & Maintenance plans, drop us an email or give James a call.
Our plans provide a holistic solution to your website’s performance, reliability and security, and are inclusive of premium tools and services.