Fraud Response Mode
Plan: Plus
Store-wide overrides for an active incident. Use them when you are under attack, not as everyday settings.
Order modes
| Mode | Effect on every new order |
|---|---|
| Heightened Review | Orders that would auto-approve are sent to manual review instead |
| Full Auto-Cancel | Every new order is cancelled in Shopify, no exceptions |
Activate with a reason and optional notes; both are kept in the history. Deactivate returns to normal scoring. The mode does not expire on its own — turn it off when the incident ends.
Bulk Session Response
Terminates every active visitor session and blocks their IPs for this store, including legitimate visitors currently browsing. Two safeguards:
- Verified search-engine crawlers are never blocked.
- All blocks created by Bulk Session Response are lifted automatically when you deactivate Fraud Response Mode. The deactivation message tells you how many were lifted.
What this mode cannot do
It cannot close your storefront, disable checkout, prevent account registration or put the store in maintenance mode. Shopify does not allow apps to do those things; use Shopify's own password page for that.
Step by step: responding to an attack
- Open Fraud Response Mode (Plus plan).
- Choose a level:
- Heightened Review: new orders that would auto-approve go to review instead. Use this first.
- Full Auto-Cancel: every new order is cancelled. Only during an active attack.
- Enter a reason and click Activate.
- If bots are flooding the storefront, click Run Bulk Session Response. It ends every active session and blocks their IPs, verified search-engine and AI crawlers excepted.
- When the attack is over, click Deactivate. Normal scoring resumes and every IP block made by Bulk Session Response is lifted automatically; the message tells you how many.