Click Smith

Shopify “James Anderson” Fraud Tester Attack

A Shopify store's customer list filled with 2,500+ “James Anderson” profiles in days. We traced them to an automated fraud tester hammering a $1.49 product through abandoned checkouts. Here's how we found it and how to check your store.

Author
Ali Haji · Co-Founder, Click Smith
Published
Updated
Updated
Reading time
5 min read
Hooded figure at a laptop with a Shopify admin showing a fake “James Anderson” order flagged as high-risk, stamped “Fraud Tester”

We recently investigated a Shopify store where the customer list suddenly started filling up with accounts named James Anderson.

At first, it looked like customer account spam.

Within a short period of time, the store had more than 2,500 customer profiles using the same name: james anderson.

Each profile had a different email address. The emails came from providers such as Outlook, Hotmail, ProtonMail, Yandex, and others. New profiles were appearing every few minutes.

After tracing the activity through Shopify, we discovered that the fake customer profiles were connected to repeated abandoned checkout attempts.

The pattern was consistent with an automated Shopify fraud tester, checkout bot, or card-testing script.

What the James Anderson Shopify Attack Looked Like

The fake customer profiles followed the same pattern:

  • Customer name was always james anderson
  • Every profile used a different email address
  • $0 spent
  • 0 completed orders
  • No marketing subscription
  • New profiles appeared every few minutes
  • Most profiles had no customer account
  • Shopify spam protection was already enabled

That last point was important.

Shopify's hCaptcha protection was already active, and customer sign-in links were already turned off. This told us the bot probably wasn't simply filling out the normal customer registration form.

We needed to find another source.

We Started by Checking Shopify Apps

The first step was reviewing the installed Shopify apps and their customer permissions. We checked whether any app had permission to create or modify customer records.

One app had permission to view customer information, but it did not have permission to edit customers.

We also checked a custom Shopify API integration. Its permissions were read-only and did not include customer write access.

That allowed us to rule out the custom API as the source of the James Anderson customer profiles.

We Checked Shopify Forms

The store was also using Shopify Forms, so we checked whether the fake customers were coming through a newsletter, popup, or other form.

They weren't.

The store only had a few legitimate form submissions during the same period in which thousands of fake customer profiles had been created. That ruled out Shopify Forms.

The Answer Was in Abandoned Checkouts

The next place we checked was Shopify Admin → Orders → Abandoned Checkouts.

Abandoned checkouts screenshot
james anderson - New abandoned checkouts were appearing every few minutes.

That's where the pattern became obvious.

The abandoned checkout page was filled with entries for james anderson, and new abandoned checkouts were appearing every few minutes.

Almost every attempt was targeting the exact same product: Plant Food, Espoma Holly-Tone — 5 Ounce, priced at only $1.49.

When we opened individual abandoned checkouts, we found the same pattern:

  • Customer name: james anderson
  • Different email address on each attempt
  • No customer account
  • Same inexpensive product
  • Repeated or similar billing information
  • No completed purchase

At that point, we knew the growing customer list wasn't the actual attack. It was a side effect of repeated automated checkout attempts.

Why Cheap Products Can Be a Warning Sign

One thing that stood out in this case was the product price. The bot was repeatedly targeting a $1.49 item.

Very low-cost products can be attractive targets for automated checkout abuse or fraud-testing scripts because the bot can repeatedly test the checkout process with a small transaction amount.

If you're seeing suspicious activity in your Shopify store, check your abandoned checkout totals.

Repeated attempts for amounts like $0.99, $1.00, $1.49, $2.00, or $5.00 can be worth investigating, especially when the customer names, addresses, or email patterns also look unusual.

How to Check if Your Shopify Store Is Affected

If you found this article because you're seeing James Anderson customers in Shopify, start with your customer list.

Step 1: Review the customer list

Go to Shopify Admin → Customers and search for James Anderson. Look for patterns such as:

  • Hundreds or thousands of profiles
  • Different email addresses
  • $0 spent
  • 0 orders
  • Profiles created minutes apart
  • The same first and last name on every account

If you find that pattern, don't stop there.

Step 2: Review abandoned checkouts

Go to Orders → Abandoned Checkouts and look for repeated checkout attempts using the same name. Then check:

  • Is the same product being used every time?
  • Is the product unusually inexpensive?
  • Are the emails changing on every attempt?
  • Is the billing information similar?
  • Are new abandoned checkouts appearing every few minutes?

Open several of the abandoned checkouts and compare them. The pattern is often much easier to see once you look at the checkout activity instead of only looking at the customer profiles.

Don't Start by Deleting the Fake Customers

It can be tempting to select all of the James Anderson profiles and delete them. That doesn't fix the problem.

If the bot is still creating a new checkout every few minutes, new customer profiles will simply continue appearing.

The first priority should be finding out how the customers are being created. Once the source is identified and the activity is stopped, the fake customer records can be cleaned up.

Temporarily Remove the Product Being Targeted

In our case, the bot repeatedly targeted one specific $1.49 product variant. As part of the investigation, we temporarily removed that product variant from the Online Store sales channel.

This is a useful test.

If the suspicious abandoned checkouts stop after the product is removed, the bot may have been programmed to target that specific product.

If the bot immediately moves to another low-cost item, you're dealing with a broader store-level problem and need to investigate the checkout traffic further.

Don't start disabling random products throughout the store without understanding the pattern first.

This Is Usually a Sign of a Bigger Shopify Problem

When thousands of fake customers or abandoned checkouts start appearing, the customer records themselves are usually not the main problem.

The important question is: what is creating them?

It could be:

  • Automated checkout abuse
  • A Shopify fraud tester
  • Card-testing activity
  • A checkout bot
  • A vulnerable or exposed storefront process
  • An app or API with unexpected access
  • Another automated process targeting the store

Simply deleting the records doesn't answer that question.

In our case, the customer list was only the symptom. The actual activity was happening through repeated abandoned checkouts.

If you're seeing the same pattern, it's worth investigating before the activity increases or the bot starts targeting other products.

Seeing “James Anderson” Customers in Your Shopify Store?

If your Shopify customer list suddenly started filling up with James Anderson, random email addresses, or repeated low-value abandoned checkouts, don't assume they're normal customer signups.

And don't start deleting everything before identifying the source.

We can help review the store and determine where the activity is coming from. We can check:

  • Shopify customer activity
  • Abandoned checkout patterns
  • App permissions
  • Shopify API permissions
  • Customer creation sources
  • Suspicious product targeting
  • Possible fraud-testing or card-testing activity
  • Checkout bot patterns

If you're dealing with James Anderson Shopify spam, a Shopify fraud tester, card-testing attempts, fake customer accounts, or unusual abandoned checkout activity, contact us. We can review your Shopify store, identify the source of the activity, and help you determine the next steps.

Call back · 15 minutes

Let's talk.

Leave a number. We call back within 15 minutes during business hours.

One call. No spam.

Questions this post raises

What is the “James Anderson” Shopify attack?

It's a pattern where a Shopify store's customer list fills with hundreds or thousands of profiles named James Anderson, each with a different email address, $0 spent, and 0 orders. The profiles are a side effect of an automated fraud tester or checkout bot repeatedly starting checkouts, which Shopify records as abandoned checkouts and new customer profiles.

Should I just delete the fake James Anderson customers?

Not first. Deleting the profiles doesn't stop the bot, and new ones will keep appearing every few minutes. Identify the source (abandoned checkouts, app or API permissions, forms) and stop the activity, then clean up the records.

Why does the bot keep targeting a cheap product?

Low-cost items like a $0.99 to $5.00 product let a card-testing or fraud-testing script repeatedly exercise the checkout with small amounts. Repeated abandoned checkouts for tiny totals on the same product are a strong warning sign.

How do I check if my Shopify store is affected?

Search Customers for “James Anderson” and look for many profiles created minutes apart with different emails and no orders. Then open Orders → Abandoned Checkouts and look for repeated attempts with the same name, the same inexpensive product, and changing email addresses.