RankShield
RANKSHIELD NETWORK Get started

Gift Card Fraud on Shopify: Why Fraudsters Target Your Store (and How to Stop It)

Gift cards are the fraud instrument of choice, and on your store that means stolen-card orders, drained balances, and chargebacks. Here is how it works and how to reduce it.

September 9, 2026 · 12 min read · gift card fraud shopify
Share

Gift cards are the fraud instrument of choice, and if you sell them on your store you are holding exactly what fraudsters want. The scale is not subtle: the FTC has repeatedly found gift cards the single most-reported payment method in fraud, with consumers reporting more than 228 million dollars lost through gift cards in 2022 and about one in four people who lose money to fraud saying it happened via a gift card (FTC1). That figure is the consumer side, people tricked into paying a scammer with gift cards, but it tells you why gift cards matter to you as a merchant: they are money that moves instantly, anonymously, and irreversibly, which is precisely why fraudsters also love buying and draining them on stores like yours. On the merchant side the pattern is different from the consumer scam but rooted in the same properties: criminals use stolen credit cards to buy digital gift cards, then resell or redeem them before the real cardholder disputes the charge, and you are left eating both the lost value and the chargeback. I build fraud tooling for Shopify merchants, and heading into the Q4 gift-card season this guide explains, honestly, why your store is a target, exactly how the fraud works, why it hurts more than ordinary card fraud, and what actually reduces it. One thing up front: nothing eliminates gift card fraud, so anyone promising that is overselling; the goal is to screen the high-risk orders before you hand over the value.

Why is gift card fraud such a problem for online stores?

Because a gift card is the closest thing to untraceable cash that your store sells, and fraudsters know it. The properties that make gift cards convenient for real customers, they are anonymous, their value transfers instantly, they need no identity to redeem, and they are trivial to resell, are exactly the properties that make them ideal for laundering stolen money. The FTC has found gift cards reported far more often than any other payment method in fraud, with those 2022 losses exceeding 228 million dollars on the consumer side alone (FTC1). That is the demand signal: there is a large, liquid criminal market for gift card value, and your store is a place to manufacture it.

There is also a displacement effect working against you. As credit card security has improved, with chip cards, tokenization, and better issuer fraud detection, straightforward card fraud has gotten harder, so criminals increasingly convert stolen card value into something more liquid and harder to claw back. A digital gift card is perfect for that conversion: buy it with a stolen card, and you have turned a card number that might get blocked into portable, resellable value. Your store becomes the laundering step, and the gift card is the output.

The timing compounds it. Gift card sales spike heading into the holidays, which is also when order volume is highest and fraud review is most stretched, so fraudulent gift card orders are easiest to hide in the flood of legitimate ones. That seasonal cover is why Q4 is when this problem bites hardest for most stores, and why it is worth understanding the specific mechanics before the peak rather than during it. The diagram below shows why a gift card is such an efficient target compared with a physical product.

DOWNLOADABLE INFOGRAPHIC

Why a digital gift card is the perfect fraud target

RANKSHIELD // WHY GIFT CARDS GET TARGETED PHYSICAL PRODUCT // a trail you can stop stolen-card order picked + shippedhours to days tracking + addresscan intercept / trace chance to catch it DIGITAL GIFT CARD // gone before you react stolen-card order emailed instantlyseconds, no address resold / drainedminutes, anonymous chargeback landsvalue already gone One fraudulent gift card order bills you twice: you lose the card value AND pay the chargeback. Gift cards = the most-reported fraud payment method (FTC). Prevention lives BEFORE fulfillment, because after is too late.
A physical order leaves a trail you can stop. A digital gift card is instant, anonymous, resellable, and irreversible. Free to share with attribution.

How does gift card fraud actually happen on your store?

There are two main patterns, and most stores see both. The first and most common is stolen-card purchase: a fraudster uses a stolen credit card number to buy digital gift cards from your store, receives the codes by email instantly, and then resells them on secondary markets or redeems them for goods before the real cardholder notices the charge and disputes it. From your side it looks like a normal gift card sale right up until the chargeback arrives weeks later. By then the gift card value is long gone, and you are left paying back the disputed amount plus the chargeback fee. This is the pattern that turns a gift card SKU into a fraud magnet, because it converts a risky stolen card number into clean, liquid value in a single transaction.

The second pattern is automated and targets gift cards more directly: carding and cracking. In carding, bots run large volumes of stolen card numbers through your gift card checkout to find which cards still work, using the purchase as a live test, which both defrauds you and validates cards for further crime. In cracking, bots hammer your gift card balance-check or redemption endpoints, guessing or testing card numbers to find ones with a balance they can drain. Both are volume attacks that depend on automation, and automated traffic is now the majority of the web, with bad bots alone around 37 percent of it (Imperva Bad Bot Report 20263), so a store with an unprotected gift card flow is an easy, scriptable target.

What ties both patterns together is that gift cards remove the friction fraudsters normally face. There is no shipping address to verify or intercept, no physical item to source and reship, and no delay that gives detection time to work. The fraud is fast, remote, and repeatable, which is why it scales, and it sits inside the broader card-not-present fraud problem the FBI tracks across billions of dollars in annual losses (FBI IC3 20252). The table below breaks the patterns down so you can recognize which one you are seeing.

THE PATTERNS

How gift card fraud shows up on your store

PatternWhat the fraudster doesWhat you see
Stolen-card purchaseBuys digital gift cards with a stolen cardNormal sale, then a chargeback weeks later
Card testing (carding)Runs stolen cards through gift card checkoutBursts of small orders, many declines
Balance crackingBots guess/test codes to drain balancesSpikes on balance-check or redeem endpoints
Reselling / launderingResells or redeems codes fastValue gone before dispute arrives

The first pattern hits your chargeback rate; the automated ones hit your endpoints. Most stores facing gift card fraud see a mix.

Why does gift card fraud hurt more than ordinary card fraud?

Because the value is irrecoverable by the time you find out, and it bills you twice. With a physical product bought on a stolen card, you at least have chances to intervene: an address to risk-score, a shipment you can sometimes hold or recall, and a delay between order and delivery during which fraud signals can surface. A digital gift card collapses all of that. It is delivered in seconds to an email address, redeemed or resold in minutes, and by the time the chargeback arrives, typically weeks later, there is nothing to recover. You do not get the product back because there was never a physical product, and you cannot claw back the gift card value because it has already been spent by someone else.

That is why a single fraudulent gift card order is a double loss. You lose the value of the gift card, which has been drained or resold, and you separately lose the chargeback: the disputed amount is pulled back from you, and you pay the dispute fee on top. As we covered in the breakdown of what a Shopify chargeback really costs, the fully loaded cost of a chargeback runs well above the disputed amount once you count fees and handling, and with gift cards you are absorbing that on top of value that was pure loss to begin with. Ordinary card fraud on a physical good is painful; gift card fraud is that plus the guarantee that there is nothing to recover.

There is a rate risk too. A cluster of gift card chargebacks can push your dispute ratio toward the thresholds card networks monitor, and once you are flagged there, the consequences, higher fees and monitoring programs, apply to your whole business, not just your gift card sales. So gift card fraud does not stay contained to the gift card line; left unchecked, it can raise the cost of accepting cards across your entire store. That is the real reason to treat the gift card flow as a distinct, higher-risk part of your catalog rather than just another product.

How do you reduce gift card fraud on your store?

You move the defense to before fulfillment, because after a digital gift card is delivered there is nothing left to protect. The single most important principle is that gift card orders deserve stricter screening than the rest of your catalog, precisely because the value is instant and irreversible. In practice that means scoring gift card orders for fraud signals before the codes are sent: the combination of a brand-new account, a high-value digital gift card purchase, a shipping-billing mismatch or mismatched geolocation, an unusual velocity of orders from one source, or a card that has just failed elsewhere on your store should hold an order for review rather than auto-fulfilling it. Because the delivery is what you are protecting, even a short delay or a manual review step on high-value gift card orders takes away the speed the fraud depends on.

Around that, a few structural controls help. Rate-limit and monitor your gift card checkout and balance-check endpoints so that carding and cracking bots cannot run high volumes against them unchecked, since those are automated attacks that thrive on being able to try thousands of times. Set velocity limits so one customer or one payment method cannot buy an abnormal number of gift cards in a short window. And cap or add review to very high-value gift card orders, which are disproportionately fraudulent. None of these block legitimate buyers meaningfully, but each one removes a lever the fraudster relies on.

The honest reality is that doing this well by hand, especially during the Q4 rush, is difficult, which is where a dedicated fraud tool earns its place. A fraud protection app screens every order, including gift card orders, against fraud signals automatically and flags the high-risk ones for review before they are fulfilled, which is exactly the moment that matters for a digital gift card. It will not eliminate gift card fraud, and no honest tool claims to, but it moves the decision to before you hand over irreversible value and it scales through the season when manual review cannot. That is what RankShield fraud protection for Shopify is built to do: screen orders for card testing, stolen-card signals, and high-risk patterns so your gift card sales are checked before the codes go out. The self-check below shows how exposed your current setup is.

EXPOSURE CHECK

How exposed is your store to gift card fraud?

  1. Do you sell digital gift cards delivered instantly?
  2. Are gift card orders screened before the codes are sent?
  3. Do you have velocity limits on gift card purchases?
  4. Are your checkout and balance-check endpoints rate-limited?
  5. Have you seen card testing or gift card chargebacks?

What is the real fix for gift card fraud?

Screen before you deliver, because with gift cards there is no after. Gift cards are the most fraud-favored instrument there is, for the same reasons customers like them: instant, anonymous, and irreversible. On your store that translates into fraudsters buying digital gift cards with stolen cards and reselling or draining them before the chargeback lands, plus automated carding and cracking against your endpoints. The reason it hurts more than ordinary card fraud is that a digital gift card leaves no trail to trace and no shipment to stop, so by the time you learn a card was stolen, the value is gone and you pay the chargeback on top, a double loss that can also push your dispute ratio toward the thresholds that raise costs across your whole store.

The fix is not a promise of zero fraud, which no honest tool can make, but a shift of the defense to the only moment that matters for an instant product: before the codes go out. Score gift card orders for fraud signals and hold the high-risk ones for review, set velocity limits, rate-limit your gift card endpoints, and add scrutiny to high-value digital orders. Doing that reliably through the Q4 rush is hard by hand, which is where a fraud tool that screens every order automatically earns its place. To have your gift card sales checked for stolen-card and high-risk signals before the codes are delivered, see RankShield fraud protection for Shopify. Treat gift cards as your highest-risk product, and defend them like it, especially now, going into the season when the fraud peaks.

FREQUENTLY ASKED

Questions, answered.

Jamie Kloncz
Jamie KlonczCEO, RankShield · online

Why do fraudsters target gift cards specifically?

Jamie Kloncz

Because a gift card is the closest thing to untraceable cash that an online store sells. The properties that make gift cards convenient for real customers are exactly what make them ideal for fraud: they are anonymous, requiring no identity to redeem; their value transfers instantly; they need no shipping address; and they are trivially easy to resell on secondary markets. That combination lets a criminal convert a stolen credit card number, which might get blocked at any moment, into portable, liquid value that is very hard to claw back. The FTC has consistently found gift cards the most-reported payment method in fraud, with consumers reporting over 228 million dollars lost via gift cards in 2022, which reflects how large the criminal market for gift card value is. There is also a displacement effect: as credit card security has improved with chip cards, tokenization, and better issuer detection, straightforward card fraud has gotten harder, so criminals increasingly launder stolen card value through gift cards instead. For a merchant, that means your gift card SKU is not just another product, it is a laundering tool that fraudsters actively seek out, and it deserves to be treated as your highest-risk item rather than a routine sale.

How does gift card fraud actually work on a Shopify store?

Jamie Kloncz

There are two main patterns, and many stores see both. The most common is a stolen-card purchase: a fraudster uses a stolen credit card to buy digital gift cards from your store, receives the codes by email within seconds, and then resells or redeems them before the real cardholder notices and disputes the charge. To you it looks like an ordinary gift card sale until a chargeback arrives weeks later, by which point the value is long gone. The second pattern is automated and aimed more directly at your gift card systems. In card testing, or carding, bots run large volumes of stolen card numbers through your gift card checkout to find which ones still work, defrauding you and validating cards for further crime in the process. In balance cracking, bots hammer your gift card balance-check or redemption endpoints, guessing or testing card numbers to find any with a usable balance to drain. Both automated patterns are volume attacks that rely on being able to try many times quickly, and since automated traffic is now the majority of web traffic, an unprotected gift card flow is an easy, scriptable target. What unifies all of it is that gift cards remove the friction fraudsters usually face: no address to verify, no item to reship, and no delay for detection to work, so the fraud is fast, remote, and repeatable.

Why is gift card fraud worse than fraud on physical products?

Jamie Kloncz

Because the value is irrecoverable by the time you find out, and it costs you twice. When someone buys a physical product with a stolen card, you have chances to intervene: there is a shipping address you can risk-score, a shipment you can sometimes hold or recall, and a gap between order and delivery during which fraud signals can surface. A digital gift card removes every one of those safeguards. It is delivered in seconds to an email address, redeemed or resold within minutes, and when the chargeback finally arrives, typically weeks later, there is nothing to recover, because there was never a physical item and the gift card value has already been spent by someone else. That makes a single fraudulent gift card order a double loss: you lose the gift card value, which is gone, and you separately lose the chargeback, since the disputed amount is pulled back and you pay a dispute fee on top of it. On a physical good you might at least recover or intercept the item; with a gift card you recover nothing. There is also a compounding rate risk, because a cluster of gift card chargebacks can push your overall dispute ratio toward the thresholds card networks monitor, and the higher fees and monitoring that follow apply to your entire business, not just your gift card sales. So the damage does not stay contained to the gift card line.

How can I prevent gift card fraud on my store?

Jamie Kloncz

Move the defense to before fulfillment, because once a digital gift card is delivered there is nothing left to protect. The core principle is that gift card orders deserve stricter screening than the rest of your catalog, precisely because the value is instant and irreversible. Concretely, score gift card orders for fraud signals before the codes are sent, and hold for review any order that combines high-risk indicators: a brand-new account, a high-value digital gift card, a billing and shipping or geolocation mismatch, an unusual velocity of orders from one source, or a payment method that just failed elsewhere on your store. Because delivery speed is what the fraud depends on, even a short delay or a manual review step on high-value gift card orders removes the fraudster’s main advantage. Around that, add structural controls: rate-limit and monitor your gift card checkout and balance-check endpoints so carding and cracking bots cannot run high volumes against them, set velocity limits so one customer or payment method cannot buy an abnormal number of gift cards quickly, and add review or caps on very high-value gift card orders, which are disproportionately fraudulent. None of these meaningfully inconvenience legitimate buyers, but each removes a lever fraudsters rely on. Doing all of this consistently by hand, especially during the Q4 rush, is hard, which is why many merchants use a fraud protection app that screens every order automatically and flags the risky ones before fulfillment.

Can a fraud protection app stop gift card fraud completely?

Jamie Kloncz

No, and you should be skeptical of any tool that claims it can. Gift card fraud cannot be eliminated, because some fraudulent orders will always look legitimate at the moment of purchase, and screening is about probabilities, not certainties. What a fraud protection app genuinely does is move the decision to the point that matters for an instant, irreversible product: it screens every order, including gift card orders, against fraud signals automatically and flags the high-risk ones for review before the codes are delivered, rather than after. That is a meaningful shift, because the entire problem with gift card fraud is that manual review cannot keep up, especially during the holiday rush, and once delivery has happened there is no recovery. An app scales that screening through the season and catches the patterns, such as stolen-card signals, card testing, new-account plus high-value combinations, and abnormal velocity, that are hard to spot by eye in a flood of orders. The honest framing is that it sharply reduces your losses and your chargeback exposure by stopping the clearest high-risk orders before you hand over value, not that it makes you immune. Combined with velocity limits, endpoint rate-limiting, and review on high-value orders, it is the most practical way to bring gift card fraud down to a manageable level, but the goal is reduction and control, not a guarantee.

Does gift card fraud get worse during the holidays?

Jamie Kloncz

Yes, and that seasonal spike is one of the main reasons to prepare before it rather than during it. Gift card sales rise sharply heading into the holidays, which is exactly when your overall order volume is highest and your fraud review capacity is most stretched. That combination gives fraudulent gift card orders cover: a stolen-card gift card purchase is far easier to hide inside a flood of legitimate holiday orders than it is during a quiet week, and an overwhelmed review process is more likely to auto-fulfill something it should have held. Fraudsters know this pattern and time their activity accordingly, so the season that drives your legitimate gift card revenue is also the season that draws the most fraud toward it. The practical implication is that the controls worth having, screening gift card orders before delivery, velocity limits, endpoint rate-limiting, and review on high-value orders, should be in place before the peak, not scrambled together during it. Setting them up in advance means the season’s volume is handled by automated screening rather than by manual review that cannot scale, which is both less risky and less stressful. If you only address gift card fraud once you are in the middle of the Q4 rush, you are trying to fix the roof in the storm, so the time to treat gift cards as your highest-risk SKU is before the holiday surge begins.

Try one of the suggested questions above.

References

  1. Federal Trade Commission. Scammers prefer gift cards, but not just any card will do (Data Spotlight): gift cards the most-reported fraud payment method; consumers reported more than $228M lost via gift cards in 2022; about 1 in 4 fraud-with-payment reports involved a gift card.
  2. FBI Internet Crime Complaint Center (IC3). 2025 Internet Crime Report (macro card-not-present and fraud loss context in which gift card fraud sits).
  3. Imperva (Thales). Bad Bot Report 2026 (automated traffic exceeded half of all web traffic; bad bots approximately 37 percent, the basis of carding and gift card cracking attacks).
Jamie Kloncz
WRITTEN BY

Jamie Kloncz

Founder & CEO, RankShield

Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.

Make every AI action provable.

RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.