Risk analysis
How to Verify a Suspicious Shopify Order Without Asking for Card Photos

Verify a suspicious Shopify order through a neutral conversation about the purchase, using the contact route already associated with it and the information your team legitimately needs. Do not ask for card photographs, full card numbers, or security codes. Those requests create sensitive-data handling problems and do not turn a support conversation into reliable proof of authorization.
The purpose of contact is limited: clarify the intended items, quantities, delivery arrangement, or an inconsistent request. Combine the response with the existing order record and the store's decision policy. A confident answer, a reachable phone, or a plausible story can be useful context without settling every risk question.
Decide what the conversation must resolve
Before contacting the customer, write the unresolved question. Examples include whether a destination change was intended, whether the buyer meant to place two orders, or whether the requested quantity is correct. If staff cannot explain what an answer would change, the proposed contact may simply add friction.
Use the order information available through Shopify's fraud-review guidance. Choose the established order conversation or approved contact route. A new message claiming to be the customer should not automatically become the route used to validate its own requested change.
Give staff a review deadline and an escalation owner. Otherwise they may promise dispatch before review is complete or continue asking increasingly intrusive questions because they do not know when to stop.
Use a complete customer-contact template
Subject: Please confirm the details of order [order reference]
Hello [customer name],
We are reviewing order [reference] before dispatch and need to clarify [specific order detail]. Our record currently shows [brief, necessary description without sensitive payment information].
Please confirm [the intended items, quantity, delivery arrangement, or other specific question]. If a correction is needed, tell us the requested change in this order conversation so we can review it before fulfillment.
Please do not send a card photograph, full card number, card security code, banking password, or identity document in reply. We do not need those details for this conversation.
The order is currently [accurate operational status]. We will update you by [merchant review time]. Confirmation helps us understand the order, and our team will complete the remaining review before confirming dispatch.
Thank you, [store support team].
Adapt the requested detail to the issue. Do not fill the message with facts that effectively supply answers to a verification question. Equally, do not demand that a customer reproduce information irrelevant to the decision. Clear, limited questions are easier for legitimate buyers to answer and easier for reviewers to interpret.
For a call, introduce the store and order reference, explain the narrow question, and follow the same boundaries. If the person is uncomfortable discussing the order by phone, offer the established written support route rather than treating discomfort as proof of fraud.
Keep sensitive payment data out of support
Card security codes are not information a support team should collect for an order conversation. The PCI Security Standards Council's guidance on card verification codes explains restrictions relevant to these data. Route payment entry through the supported checkout or provider process.
If a customer sends sensitive payment information unsolicited, stop copying or forwarding it. Follow the business's approved handling and deletion procedure, limit access, and move the conversation back to a safe channel. Do not retain a card photo as “stronger evidence” in the review note.
The note should contain the question asked, response summary, contact route, time, and interpretation limits. It generally does not need a full transcript copied into a fulfillment channel.
A hypothetical inconclusive response
A hypothetical order requests a destination different from the merchant's previously reviewed details. Support asks the customer to confirm the intended receiving arrangement through the established order conversation. The customer confirms the requested change but supplies no additional explanation relevant to the unresolved payment context.
The reviewer records that the delivery intention is clearer. They do not write “cardholder verified.” The remaining payment-related concern goes to the authorized decision owner. That owner may maintain a time-limited hold, release under policy, or decline the order through the supported workflow.
In another invented variation, the person contacted says they did not place the order. Staff preserve that statement, stop any unapproved release, and escalate promptly. They do not ask the person to send a card image to prove the denial.
End the conversation with an accountable decision
A verification attempt is complete when the relevant question is answered or the contact is recorded as inconclusive. Repeatedly calling without a defined purpose does not create certainty. Apply the store's escalation rule and communicate the resulting order status accurately.
The best reusable script gives staff a narrow question, a safe channel, a clear data boundary, and an honest description of what confirmation means. It helps the merchant understand the purchase while preserving the distinction between customer communication, payment authentication, and the final release decision.
Explore how Lower Chargeback presents Shopify risk signals for merchant review.
Related reading in this collection:
- Shopify Fraud Analysis: Reading the Recommendation and the Individual Signals
- Support Requests That Try to Bypass Fraud Review: A Staff Response Script
- Order Confirmation Emails That Prevent Purchase Confusion