Fraud and Chargebacks on an Indian Shopify Store in 2026
Ask a Shopify merchant in the United States about fraud and they will talk about stolen cards and chargebacks. Ask an Indian D2C brand and the honest answer is different. Card fraud exists here and is comparatively rare, largely because so much of the market pays cash on delivery. What actually costs Indian brands money is a category Shopify's fraud tools were never designed to catch, because it does not involve a stolen instrument at all.
The two problems are not the same size
Payment fraud means someone using a card they do not own. Your gateway and your bank carry much of the detection, Indian card transactions carry additional authentication that many markets do not, and the volume is low for most D2C categories.
Order fraud and abuse means the order is real, the payment method is legitimate or absent, and the loss comes from behaviour. A COD order placed with no intention of accepting it. A serial returner. Someone claiming non-delivery on a delivered parcel. Bulk orders placed to exploit a launch or a discount.
For most Indian D2C brands the second category costs several times what the first does, and almost nothing in a standard fraud setup addresses it.
What Shopify gives you
Shopify provides fraud analysis on orders, surfacing risk indicators so you can review higher-risk orders before fulfilling, and it recommends using Shopify Flow to automate how you handle them.
That is genuinely useful for the payment fraud category. It is built around signals that make sense for card transactions, such as mismatches between billing and shipping, unusual velocity, and address verification.
Two honest caveats. A COD order has no payment instrument to analyse, so the strongest signals simply are not present. And chargeback protection products have regional eligibility, so check what is actually available to your store in your admin rather than assuming a feature you read about applies to you.
The signals that actually predict a bad COD order
These come from operating in this market rather than from a fraud engine, and they are worth building rules around.
- Address quality. Vague addresses, missing landmarks, a pin code that does not match the stated city. These correlate strongly with failed delivery.
- Phone reachability. An unreachable number at confirmation is the single best predictor of an RTO.
- Order value against your norm. A COD order at several times your average, from a new customer, deserves a confirmation call.
- Velocity from one address or number. Several orders in a short window is either a genuine bulk buyer worth talking to or a problem.
- Pin code history. Your own RTO rate by pin code is data nobody else has, and it is more predictive for your business than any generic score.
That last one is the highest-value thing on this page. Most brands have this data and have never looked at it.
What to do about it, in order of return
Confirm COD orders. A WhatsApp confirmation before dispatch removes a large share of the problem, because an order nobody confirms is an order nobody wanted. This is the same lever as everything in our RTO work.
Put rules on COD rather than banning it. A value cap, a restriction on pin codes with a poor history, or prepayment required for first orders above a threshold. Enforce these as validation rules so they hold on every path including express wallets, which is exactly what server-side validation is for.
Offer partial prepayment. Collecting a small amount upfront changes the psychology of a COD order more than its economics, and it filters out the least committed buyers cheaply.
Automate the review queue. Flag rather than block. A rule that holds high-risk orders for a human glance costs you minutes and catches the obvious cases.
Chargebacks, when they do happen
Lower volume here than in card-first markets, and expensive when they land because they cost the goods, the fee and the time.
What wins a dispute is evidence gathered before you needed it. Delivery confirmation with a timestamp, the address as entered by the customer, any communication about the order, and your published policies as they stood on the day. If your courier provides proof of delivery, make sure your team can retrieve it months later rather than discovering the retention window expired.
The operational point is that dispute responses have deadlines, and a missed deadline is an automatic loss. Someone has to own that inbox.
Where brands overcorrect
Fraud rules are easy to tighten and hard to loosen, because nobody sees the orders a rule rejected.
A blanket COD ban removes a category of loss and a large share of your revenue at the same time. Blocking a pin code because of two bad orders punishes every genuine customer there. An aggressive risk threshold generates a review queue nobody has time for, so it gets ignored, which is worse than not having it.
Measure what your rules cost as well as what they save. The cheapest way is to keep a count of orders held or rejected and sample a few each month to see how many were actually bad.
Build the pin code scorecard, it takes an afternoon
This is the one piece of work on this page that no vendor can sell you, because it depends entirely on your own history.
Export twelve months of orders with pin code, payment method and final status. Group by pin code, count COD orders and count the ones that came back. You now have an RTO rate per pin code for your products, shipped by your couriers, to your customers.
Most brands find the distribution is not smooth. A small number of pin codes carry a disproportionate share of the failures, and a much larger number are entirely clean. That shape is what makes the data useful, because it means you can act on a short list rather than applying a blunt rule everywhere.
What you do with it is a business decision. Prepayment only above a value threshold in the worst pin codes, a confirmation call, or simply accepting the loss where the volume justifies it. What you should not do is keep guessing when the answer is sitting in your order export.
Discount and launch abuse
A category worth naming separately because it spikes rather than trickles.
A generous launch offer or a first-order discount will be found and worked. One person with several email addresses, several phone numbers and one address is the common pattern, and a discount code shared publicly is the other. Neither is fraud in the criminal sense and both cost real margin.
The cheap defences are usage limits per customer, a minimum order value that makes the maths less attractive, and codes that expire quickly enough to limit spread. The expensive defence is discovering it after the campaign, which is why a quick look at redemption counts on day two of any promotion is worth the five minutes.
Does Shopify protect me from chargebacks?
Shopify offers fraud analysis on orders and there are protection products, but eligibility is regional and tied to specific payment setups. Check what your store is actually eligible for in your admin rather than assuming, since availability differs by country and Indian stores use third-party gateways rather than Shopify Payments.
How do I reduce COD fraud without losing sales?
Confirm orders before dispatch, put value and pin code rules on COD rather than removing it, and offer partial prepayment as a middle option. Banning COD outright removes the loss and a large part of your revenue with it.
What is the best fraud signal for an Indian store?
Your own RTO rate by pin code. It is specific to your products, your couriers and your customers, no generic scoring model has it, and most brands are already sitting on enough order history to build it.
Should I block orders automatically?
Flag rather than block for anything ambiguous. Automatic blocking rejects genuine customers silently and you never find out. A held queue that a human clears daily catches the clear cases and lets the borderline ones through with a phone call.
How long should I keep delivery evidence?
Longer than your dispute window, and longer than your courier's default retention. Find out what that retention period actually is, because discovering it after you needed the proof is the common way these disputes are lost.
Get your risk rules reviewed
Free review. Email hello@exactwhy.com with subject "Fraud and RTO" and tell us your COD share, your RTO rate, and what rules you run today. We respond within 4 hours with what to change first. For most brands the answer is confirmation and pin code data, not a fraud app.
Paid work, Rs 25,000 to Rs 1 lakh. Server-side rules that hold on every checkout path, a pin code scorecard built from your own order history, an automated review queue, and reporting that shows what the rules cost as well as what they save.
Ongoing Shopify development, Rs 20,000 to Rs 50,000 a month. Including tuning rules as your mix changes, because a threshold set in March is usually wrong by November.
The brands that handle this well are not the ones with the strictest rules. They are the ones who know their own RTO rate by pin code and act on it.