Scams that target the merchant, not the card
The previous post covered transaction fraud: stolen cards, chargebacks, card testing. This post is about the other side: scams that target you, the store owner, directly. Phishing emails pretending to be Stripe. Fake "customers" trying to social-engineer refunds. Suppliers that take your money and disappear. Domain-renewal scams in the post.
Most of these are low-tech. They work because running a store is busy and the scam email arrives on a Tuesday afternoon when you're tired. The defences are mostly about knowing what to expect.
The big categories
1. Phishing pretending to be Stripe, PayPal, Shopify, your bank
You get an email: "Your Stripe account has been flagged, click here to verify." The link goes to a login page that looks perfect. You enter your credentials. They're captured.
What to watch for:
- Sender domain: real Stripe emails come from
@stripe.com, not@stripe-support.comor@stripe.verify.co - Urgency language: "account will be suspended in 24 hours" is a scam pattern
- Links: hover before clicking. Real Stripe links go to
dashboard.stripe.com
Defences:
- Enable 2FA on every payment and commerce platform you use (Stripe, PayPal, your bank, your Shoprocket account, your email). A stolen password is useless without the second factor
- Never click login links in emails. Go to the site directly via your bookmark or typed URL
- Use a password manager. They auto-fill only on the real domain, so they silently refuse on phishing pages, which is a great tell
2. The "overpayment" scam
"Customer" places a large order, overpays (by $500 or so), then emails you asking for a refund of the overpayment to a different card or via a different method (PayPal, bank transfer, gift cards). A week later, the original payment is reversed as fraud, and you've refunded money you never really had.
What to watch for:
- Any refund request to a method different from the original payment
- Orders with unusually large amounts from new customers
- Urgent pressure to refund quickly
Defences:
- Only refund to the original payment method. Stripe enforces this by default, so this scam mostly happens when sellers manually process refunds outside the platform
- If a "customer" insists on an alternative refund method, that alone is the signal
3. The "wrong address, please reship" scam
Customer orders, receives the item, then claims "the address was wrong, please reship to X". If you reship, they keep both.
What to watch for:
- Reship requests that reference an address change after tracking shows delivered
- Multiple customers with variations of the same story, sometimes coordinated
Defences:
- Always check courier tracking before actioning an address issue
- If the item was delivered to the address on the order, the order is fulfilled. Any further shipments are the customer's cost
4. The SEO / review blackmail scam
Someone emails you: "I left a one-star review. Pay $200 and I'll remove it." Or: "I can remove negative reviews for a fee." Or: "Your Google Business Profile will be reported unless you pay."
Most of these are bluffs. Real review removal goes through the review platform's process, not a private payment.
Defences:
- Never pay. Paying identifies you as a mark and you get more demands
- Flag the email as spam, block the sender, move on
- If there's a real negative review, address it publicly with a reasonable response. That does more for you than removal would
5. Fake supplier / dropship scam
You source a new supplier, usually via Alibaba or a cold email. They offer prices that are too good. You send a deposit (often via wire transfer because "PayPal isn't available"). The goods never ship, or ship as fakes, or ship short.
What to watch for:
- Payment methods that have no buyer protection (wire, cryptocurrency, Western Union)
- Prices 30%+ below market rate
- No verified business presence (no factory audit, no Alibaba Trade Assurance, no company registration you can verify)
- Communication exclusively via Gmail or WhatsApp rather than business email
Defences:
- Use Alibaba's Trade Assurance for first orders. It holds payment until you confirm delivery
- Sample first. Order a small quantity before committing to a full run
- Verify the business: registration number, Google them, check LinkedIn for employees, reverse-image-search their product photos (stolen photos are common)
6. Fake Google / Meta / "your listing is unverified"
"Your Google Business Profile is about to be removed. Verify now." Or: "Your Meta Business account has unusual activity." The link goes to a fake login page that steals your ad account credentials.
Meta ad account takeover is particularly painful: attackers run their own ads on your credit card before Meta notices and you get the bill.
Defences:
- Log into Google Business and Meta Business Manager directly (not via email links) to check status
- 2FA on both
- Set ad spend limits on your ad accounts. If they're taken over, the damage is capped at your limit
7. The "your domain is expiring" scam
A letter (actual paper) or email arrives from "Domain Registry of America" or similar. They're not your registrar. The letter is a transfer request dressed up as a renewal invoice. If you pay, you transfer your domain to a slow, expensive registrar that charges three times your current fee and makes transferring out painful.
Defences:
- Know where your domain is registered. If the letter isn't from your actual registrar, ignore it
- Enable registrar lock on your domain (most registrars offer this free)
- Set your domain to auto-renew at your real registrar so you never have a "renewal panic"
8. Fake affiliate / partnership / "brand ambassador" scams
"We love your brand! We'd like to feature you in our $500k marketing campaign. Pay $2,000 for placement." Or: "Become our brand ambassador, send us 50 units of your product for an influencer unboxing." (They're not an influencer; they resell the goods.)
What to watch for:
- Requests for free product from accounts you can't verify
- Marketing offers where you pay them (not the other way around)
- Vague, generic messaging that could be sent to any brand
Defences:
- Any real partnership proposal comes with specifics: audience numbers, past campaigns, a deck
- If they want free product, send one unit and see what they do with it before sending fifty
- If they want money upfront for a "feature" or "placement", assume it's not real
9. The fake legal threat scam
You get a DMCA takedown notice or a trademark infringement letter from a "law firm" you've never heard of. They demand immediate action or payment. The firm isn't real; the claim is fabricated.
Defences:
- Verify the law firm exists (Google, state bar registry)
- Forward the email to your actual lawyer or legal advice service; don't engage directly
- Real legal notices arrive on paper or through your registered agent, not as a PDF attached to a Gmail address
10. The chargeback threat email
"I want a refund. If you don't refund in 24 hours I will chargeback my bank AND leave a one-star review on every site." Sometimes this is a legitimate angry customer. Sometimes it's a scam to extract refunds for goods they received and kept.
Defences:
- Handle each on merit: if they have a real reason (wrong item, damaged goods), refund. If tracking shows delivered and the issue is vague, request specifics before refunding
- If they chargeback anyway, respond to the dispute with shipping proof and customer communication. You win most "item not received" disputes this way
- Remember Stripe's chargeback rate threshold is 1%; if you give in to every threat, your rate climbs and your account gets flagged
The security baseline every store should have
Independent of specific scams, a few defaults make almost all of this harder for the attacker:
- 2FA on every account (email, Stripe, PayPal, Shoprocket, domain registrar, ad accounts). Ideally via an authenticator app, not SMS
- Password manager with unique passwords per service
- Separate admin email (not your personal Gmail) for commerce accounts
- Dedicated business card for advertising with low limits
- Tracking + signature delivery over a threshold amount
- Clear statement descriptor on Stripe (cuts friendly-fraud chargebacks substantially)
- Regular log review in your commerce platforms. Unknown logins should be investigated immediately
<!-- EXAMPLE ONLY. Grab your real snippet from Sales channels → Embeds in your dashboard -->
<script src="https://cdn.shoprocket.io/loader.js" data-pk="pk_yourkey"></script>
<div data-shoprocket="catalog" data-embed-id="emb_xxx"></div>
What Shoprocket handles
- Login monitoring. New-device logins trigger an email to the account owner
- 2FA available for seller accounts (enable under Settings → Security)
- Admin activity log. Every significant action (product edits, refunds, permission changes) is logged and reviewable
- Role-based permissions. Staff only get the permissions they need; a support agent can't change bank details
- Refund protection. Refunds route through the original payment method by default. No surprise "refund to different card" flows
What Shoprocket doesn't solve: scams targeting your email, your ad accounts, your domain, your suppliers. Those are outside our scope, but the 2FA + password manager baseline handles most of them.
Tip: If you get a suspicious email claiming to be from Shoprocket, don't click the link. Log into your dashboard directly. Any real notice will be visible in the in-app alerts as well as email.
TL;DR
- Most scams targeting merchants are social engineering, not technical. The defences are about awareness, not software
- Phishing + ad account takeover are the most financially damaging. 2FA on every platform blocks most of them
- Only refund to the original payment method. The "send my refund a different way" request is almost always a scam
- Suppliers are a major attack vector. Use Trade Assurance, sample first, verify the business exists
- Real legal / platform notices don't come via Gmail attachments. Ignore PDF threats unless they're on paper or through a verified channel
- Security baseline: 2FA everywhere, password manager, admin email separate from personal, tracking/signature on high-value shipments
Start a free trial and 2FA + role-based permissions + admin activity logs are on by default. 14 days, no card.

Building ecommerce tools for independent sellers since 2013.



