Defending WooCommerce: How we blocked 450,000 card testing attempts in one week

Attack overview

We recently stopped the largest WooCommerce card testing attack we’ve seen. Attackers targeted PayPal, credit, and debit card processors across multiple stores, creating thousands of failed orders marked with Origin = “Unknown.”

Merchants using OOPSpam’s protection settings were already covered. Our systems blocked over 450,000 attack attempts in one week.

This attack was broader than previous campaigns that mainly targeted PayPal through Block-based Checkout. For background, see our earlier posts:

What we saw

WooCommerce order list showing multiple failed transactions.

How attackers bypassed security checks

WooCommerce’s newer Block‑based Checkout uses different code paths than the classic checkout. Many security tools were built for the old system and miss activity on the new one. Attackers took advantage of this gap by using both checkout types and multiple payment gateways, relying on:

Card Testing Attack in Woo with Credit Card

Impact on merchants

How we mitigated at the edge and the application layer

Our mitigations combine attribution‑aware rules with IP/email reputation. All three of the following attribution‑based controls leverage WooCommerce Order Attribution (WooCommerce ≥ 8.5):

WooCommerce setting in the OOPSpam WordPress plugin

Blocked entries appear under Form Spam Entries for review.

Blocked orders with Unknown Origin in WooCommerce

In parallel, our IP and email reputation engines blocked over 450,000 attempts during the heaviest 7‑day window.

Fake order with Unknown origin

Indicators and patterns from this campaign

Fake Orders in WooCommerce with missing Device Type

Recommendations

Country and language filter settings for message restrictions.

For teams already using OOPSpam

Merchants with “Block orders from unknown origin” enabled were already protected during this campaign. We have since:

If you haven’t enabled these yet, see our step‑by‑step guide.

Closing notes

This attack shows how fraudsters adapt to new WooCommerce features like Block-based Checkout. Our attribution-based controls and reputation systems effectively stop these attacks while keeping legitimate orders flowing. We’ll keep updating our detection as attackers try new tactics.

Spam Protection for WordPress, Zapier, Make and more.

Since our launch in 2017 we’ve been perfecting our API to be the trusted option for small businesses to enterprise— and continue to stick to our values of being the accessibility and privacy-friendly option. Give us a shot!

Try OOPSpam for free → Try our WordPress plugin for free →

✓ No credit card required ✓ Cancel anytime

Enjoy Reading This Article?

Here are some more articles you might like to read next: