7 Signs of a High-Risk Ecommerce Order | EverEye

by on July 14, 2026



● FRAUD PREVENTION

7 Warning Signs of High-Risk Ecommerce Orders

Learn the 7 warning signs that flag high-risk ecommerce orders, from AVS mismatches to freight forwarder addresses, and how to review them without losing sales.

9 min readEvereye Team

Every ecommerce order carries some level of risk, but a small number of patterns show up again and again in orders that turn into chargebacks. Knowing these patterns is only half the battle. The harder part is applying them correctly, since almost every one of these signals also has a completely innocent explanation. A traveling customer connecting through hotel Wi-Fi, a shopper sending a gift to a different address, or someone who simply mistyped a security code can all trigger the same flags a fraudster would.

This is why experienced fraud teams do not treat any single signal as an automatic decline. They look for combinations. This guide walks through the seven warning signs worth building into any ecommerce risk review process, along with guidance on when a flag genuinely warrants a closer look versus when it is likely just noise.

1. AVS and CVV Mismatches

The Address Verification Service, or AVS, compares the billing address entered at checkout against the address on file with the card issuer. A CVV mismatch means the security code entered does not match the one associated with the card. Both are among the oldest and most commonly used fraud signals, and both are frequently misapplied.

A mismatch on either can indicate a stolen card being used without full billing details. But it can just as easily indicate a customer who recently moved and has not updated their address with their bank, a data entry typo, or a card connected to a business account with a different registered billing address than the cardholder’s home. Up to 92 percent of transactions declined solely due to an AVS mismatch are estimated to have actually been legitimate. Treat AVS and CVV mismatches as one input into a broader risk score, not a standalone reason to decline.

When it is likely fraud: An AVS or CVV mismatch combined with a first-time customer, a shipping address that differs from billing, and an order value significantly above the customer’s typical range.

When it is likely legitimate: A returning customer with prior successful orders, a small mismatch consistent with a recent move, or a gift order with a different shipping address clearly noted at checkout.

2. Mismatched IP Address and Billing or Shipping Location

A significant distance between a customer’s IP address location and their stated billing or shipping address is a commonly cited red flag, since fraudsters often operate from a different country or region than the cardholder whose information they are using.

However, this signal has become noisier over time. VPN usage is now widespread for privacy reasons unrelated to fraud, and remote work means many legitimate customers connect through corporate networks registered in a different city or even country than where they actually live. Business travel adds another common, entirely innocent source of this mismatch.

When it is likely fraud: A large geographic mismatch combined with a new account, an unusually large order, and a shipping address that also differs from the billing address on file.

When it is likely legitimate: A known VPN or corporate network IP range, or a returning customer whose IP location varies periodically but who otherwise has a normal, established order history.

3. Unusual Order Volume or Value

Orders that are significantly larger than a customer’s typical purchase, or unusually large relative to what is typical for the product category, deserve a closer look, particularly from customers with no prior purchase history. Fraudsters using stolen card details often try to maximize the value extracted before the card is reported and canceled, which tends to produce orders well above average size.

When it is likely fraud: A first-time customer placing an unusually large order for high-value or easily resold items, especially combined with expedited shipping.

When it is likely legitimate: A returning customer making a larger-than-usual purchase around a holiday, gift-giving season, or a known life event like moving or renovating, particularly if their account has an established order history.

4. Multiple Orders for Identical or Easily Resold Items

Fraudsters frequently place several orders for the same item, sometimes across multiple cards or accounts, in quick succession. This pattern often indicates card testing, where a fraudster is verifying which of several stolen card numbers are still active before making a larger purchase, or an effort to acquire easily resold merchandise like electronics, gift cards, or designer goods in bulk.

When it is likely fraud: Several small, rapid transactions for the same low-cost item, often just under a common approval threshold, sometimes using different cards but the same shipping address, device, or IP.

When it is likely legitimate: A business account purchasing bulk quantities for resale or corporate use, particularly with an established account and consistent past ordering behavior.

5. Excessive Expedited Shipping Requests

A customer paying extra for the fastest available shipping option, particularly on a large or first-time order, can indicate urgency to receive goods before a stolen card is detected and canceled. Legitimate customers do choose expedited shipping regularly, of course, so this signal is weak on its own but becomes meaningful when stacked with other flags.

When it is likely fraud: Rush shipping combined with a first-time customer, a high-value order, and a billing or IP mismatch.

When it is likely legitimate: A returning customer, or a first-time customer purchasing a gift or time-sensitive item like an event-specific product, especially close to a relevant date.

6. Freight Forwarders, Mail Drops, and Reshipping Addresses

Shipping addresses tied to freight forwarding services or commercial mail-receiving locations are a well-documented fraud pattern, since these services are sometimes used to reroute goods purchased with stolen cards to a location outside the country where the card was issued, obscuring the fraudster’s true location. This does not mean every freight forwarder shipment is fraudulent. Legitimate customers living abroad, expats, and military personnel stationed overseas regularly and legitimately use these services.

When it is likely fraud: A freight forwarder or mail-drop address combined with a first-time customer, a high-value order, and a mismatched billing address or card-issuing country.

When it is likely legitimate: A known, established account with a documented history of shipping to the same freight forwarder or overseas address without prior disputes.

7. Disposable or Suspicious Contact Information

Free email addresses generated moments before checkout, email addresses with random strings of numbers and letters, disposable phone numbers, or contact details that do not match any other information on the order can all indicate an attempt to avoid leaving a traceable identity behind.

When it is likely fraud: A newly created, randomly generated email address combined with a first-time customer, a high-value order, and other mismatched signals like AVS or IP location.

When it is likely legitimate: Many legitimate customers do use free email providers for everyday shopping, so this signal should almost never be used in isolation. It becomes meaningful mainly when the email itself looks auto-generated rather than personally chosen, or when it is paired with other risk indicators.

Building These Signals Into a Review Process, Not a Blocklist

The theme across all seven signals is the same: no individual flag should trigger an automatic decline on its own. Each one, evaluated alone, will catch some fraud and reject a meaningful number of legitimate customers along with it. The goal of a well-built fraud review process is to weigh these signals together, assign more scrutiny to orders where several appear at once, and route genuinely ambiguous cases to manual review rather than an automatic block.

A practical way to operationalize this is a simple tiered system:

  • Low risk: Zero or one weak signal present, such as a returning customer with a minor AVS mismatch. Approve automatically.
  • Medium risk: Two or more signals present, or one strong signal like a freight forwarder address combined with a first-time customer. Route to manual review before shipping.
  • High risk: Three or more signals present simultaneously, particularly involving a first-time customer, a significant order value, and a location or identity mismatch. Consider holding for verification or declining, depending on the specific combination.

This tiered approach avoids the two failure modes merchants most commonly fall into: declining too aggressively and losing legitimate revenue, or ignoring these signals altogether and absorbing preventable fraud losses.

Training Your Team to Apply These Signals Consistently

Even the best-designed tiered system breaks down if the people reviewing flagged orders apply it inconsistently. Two reviewers looking at the same combination of signals should reach the same decision, which requires clear, written criteria rather than relying on individual judgment or gut feeling. Documenting specific examples of each risk tier, drawn from a merchant’s own order history, gives reviewers a concrete reference point rather than an abstract rule. It is also worth periodically auditing manual review outcomes against what actually happened to those orders later, whether they shipped without incident or resulted in a chargeback, since this feedback loop is what allows the tiered system to improve over time rather than staying static.

FAQ: High-Risk Order Warning Signs

Q: Should I automatically decline any order with an AVS or CVV mismatch?

A: No. A large share of AVS and CVV mismatches come from legitimate customers, whether due to a recent move, a data entry error, or a business card with a different registered address. These signals work best as part of a combined risk score rather than a standalone decline trigger.

Q: How many risk signals should trigger a manual review versus an automatic decline?

A: There is no universal number, since the right threshold depends on your product category, average order value, and historical chargeback rate. Most merchants find that two or more moderate signals, or one strong signal like a freight forwarder address paired with a first-time high-value order, warrants manual review before an automatic decline.

Q: Are freight forwarder shipments always a sign of fraud?

A: No. Many legitimate customers living abroad, military personnel, and expats use freight forwarding and mail-receiving services regularly. This signal is only meaningful when combined with other risk indicators like a mismatched billing address or a brand-new account.

Q: What is card testing and how does it show up in order data?

A: Card testing occurs when a fraudster uses stolen card details to place several small transactions, often for the same low-cost item, to verify which cards are still active before making a larger purchase. It typically appears as a burst of similar small orders in a short time window, sometimes from the same device or IP address using different card numbers.

Q: How can EverEye help apply these warning signs without hurting conversion?

A: EverEye combines these and other signals into a weighted risk score rather than a rigid rule set, so orders with a single innocent mismatch are not automatically blocked, while orders with multiple genuine risk indicators are flagged for review before they ship.

Ready to turn these warning signs into a real risk model?

7-minute demo. Unlimited time for questions.

Get Started
View Customer Stories