Fraudsters love VPNs because a virtual private network hides their real IP address and location behind an anonymous one-letting them spoof a trusted country, rotate through fresh IPs to dodge fraud filters, test stolen cards at scale, and open unlimited fake accounts, all while looking like an ordinary shopper. The anonymity is the entire point.
For Shopify merchants, that anonymity isn’t abstract-it’s expensive. Juniper Research projects merchants will lose more than $362 billion to online payment fraud between 2023 and 2028, with roughly $91 billion in 2028 alone. VPN- and proxy-masked traffic sits at the center of nearly every card-testing, chargeback, and account-abuse scheme driving those losses.
VPN fraud is any abuse of a store-card testing, chargeback fraud, account takeover, scraping, or geo-spoofing-committed through a VPN, proxy, or Tor connection that conceals the attacker’s real IP address and country. Understanding why the anonymity matters to attackers is the first step to shutting it down.
On this page
- What makes VPNs and proxies so useful to fraudsters?
- VPN vs proxy vs residential proxy vs Tor
- How VPN-masked fraud actually hits your Shopify store
- Are all VPN and proxy orders fraudulent?
- How to stop VPN and proxy fraud on Shopify
- Frequently asked questions
What makes VPNs and proxies so useful to fraudsters?
VPNs and proxies give fraudsters the one thing every fraud scheme depends on: deniability. When the true origin of a connection is hidden, the signals your fraud filters rely on-IP reputation, country, device consistency-stop working. A single attacker can look like a thousand different shoppers in a dozen countries.
Here’s what that anonymity actually buys an attacker:
- Location spoofing. A fraudster in a high-risk region can appear to shop from the United States, Germany, or the UK-matching the billing country of a stolen card and slipping past country-based fraud rules.
- IP rotation at scale. Modern proxy services hand out a fresh IP for every request. That structurally defeats rate limits and IP blocklists, because the address that abused you five seconds ago is already retired.
- Filter evasion. Fraud tools flag suspicious geographies and repeat offenders. Rotating anonymized IPs erase both the geography signal and the repeat-offender history.
- Unlimited fake identities. New IP plus new email equals a “new customer.” That powers promo abuse, referral fraud, fake reviews, and mass account creation.
- Card testing cover. Running hundreds of stolen card numbers from one visible IP gets blocked instantly. Spread across anonymized IPs, the same attack blends into normal traffic.
The scale of this infrastructure is growing fast. According to an April 2026 analysis published by FIRST.org drawing on Infoblox data, DNS traffic to proxy-related domains climbed from around 300 billion queries per month in early 2025 to over 500 billion per month by April 2026, with more than 65% of Infoblox cloud customers connecting to residential proxy services.
Want the defensive playbook first? See our companion guide on how VPN and proxy blocking strengthens your Shopify store security, or explore what Kedra Shield blocks out of the box.
VPN vs proxy vs residential proxy vs Tor
Not all anonymized traffic is the same, and the differences matter for how you respond. A VPN encrypts and reroutes a user’s whole connection; a proxy simply relays requests through another IP; a residential proxy borrows the IP of a real home internet connection (often without the homeowner’s knowledge); and Tor bounces traffic through volunteer relays for near-total anonymity.
| Anonymity method | How it works | Why fraudsters use it | Detectability |
|---|---|---|---|
| Commercial VPN | Routes traffic through a provider’s data-center servers | Cheap, fast geo-spoofing and IP masking | Moderate - data-center IP ranges are catalogued |
| Datacenter proxy | Relays requests through cloud/hosting IPs | High-volume bot attacks and card testing | Easier - almost no real shoppers browse from AWS or OVH |
| Residential proxy | Borrows real home IPs, often via malware or “free VPN” SDKs | Looks like a genuine consumer; evades IP reputation | Hard - the IP is a real household |
| Tor | Bounces traffic through layered volunteer relays | Maximum anonymity for reconnaissance and abuse | Moderate - exit nodes are publicly listed |
Residential proxies are the fastest-rising threat because they defeat the oldest defense-IP reputation. The FBI’s Internet Crime Complaint Center warned in a March 12, 2026 public service announcement (Alert I-031226-PSA) that “cyber threat actors use residential proxies to facilitate illicit activities, while obfuscating their true identities and locations by routing internet traffic through home and small business internet networks.” Because those IPs belong to real households and are frequently swapped out after a session or two, static blocklists can’t keep up-which is exactly why fraudsters pay a premium for them.
How VPN-masked fraud actually hits your Shopify store
VPNs and proxies aren’t a threat on their own-they’re the delivery mechanism for concrete attacks that cost you money. On a Shopify store, the same masked traffic typically shows up as one of six patterns.
1. Card testing (carding)
Fraudsters buy stolen card numbers-roughly $5 per credential set on the dark web, per Experian data cited by Chargebacks911-and run small “does this card work?” transactions to validate them before larger fraud elsewhere. It’s rampant: the Merchant Risk Council found 33% of merchants experienced card testing in 2025, and at peak, payment processor Stripe has reported blocking more than 20 million card-testing attempts a day. Anonymized IP rotation is what lets these bots probe your checkout without getting rate-limited.
2. Chargeback and stolen-card fraud
Once a card is validated, the attacker places a real order-using a VPN to match the IP location to the cardholder’s country so the transaction looks legitimate. The genuine cardholder later disputes it, and you eat the chargeback plus a $20–$100 dispute fee regardless of order value. Geographic patterns matter here; our breakdown of which countries generate the most chargebacks shows how origin laundering distorts the map.
3. Account takeover and credential stuffing
Attackers replay stolen username/password pairs against your login. Fraud platform Accertify reported that credential-stuffing operations are shifting from data-center IPs toward residential proxy networks, with individual campaigns reaching up to 12 million attempts and success rates of 1–2%-enough to compromise as many as 200,000 accounts in a single attack.
4. Promo, referral, and fake-account abuse
Every “new IP + new email” combination reads as a fresh customer, so one person can claim a first-order discount hundreds of times, farm referral credit, or flood you with fake accounts and reviews. VPNs make the one-per-customer promise unenforceable.
5. Content and price scraping
Competitors and resellers use rotating proxies to scrape your product descriptions, images, and prices without tripping rate limits-the same anonymized traffic, pointed at your catalog instead of your checkout.
6. Bypassing your country blocks
If you block a high-risk country outright, a fraudster simply connects through a VPN exit node in a country you do allow. This is why country blocking alone is porous-and why Tor traffic to a storefront is almost always a red flag worth blocking by default.
Are all VPN and proxy orders fraudulent?
No. Plenty of legitimate, privacy-conscious shoppers use VPNs-on public Wi-Fi, while traveling, or simply as a default. Blanket-blocking every VPN order will cost you real sales, so the goal is risk-scoring, not a wall. The right response depends on the type of anonymized connection and the behavior attached to it.
That nuance is measurable. The fraud-analytics service Scamalytics assigns VPN traffic a fraud risk score of 64 out of 100-meaning anonymized traffic is heavily over-represented in abuse relative to its share of legitimate visits, but it is not universally malicious. A sensible policy treats different signals differently:
- Data-center proxies and Tor: block or heavily challenge by default-almost no genuine shopper browses from AWS or a Tor exit node.
- Commercial VPNs: apply friction rather than a hard block-require 3D Secure, flag for review, or limit first-order value.
- Residential proxies: the hardest case; lean on behavioral signals (velocity, device mismatch, impossible travel) because the IP itself looks clean.
- Known-good customers: whitelist returning buyers so a VPN doesn’t punish loyal shoppers.
The practical takeaway: you want a tool that identifies the connection type and lets you set a graduated response, not one that only offers on/off.
How to stop VPN and proxy fraud on Shopify
Kedra Shield is a Shopify security app built to catch exactly this kind of masked traffic-at the storefront entry point, before a visitor ever reaches your product pages or checkout. Instead of forcing you to research and paste IP ranges by hand, it ships with continuously updated intelligence on VPNs, proxies, Tor, and data-center networks. Here’s how a typical setup maps to the threats above.
- Install and open the dashboard. From your Shopify admin, add Kedra Shield and open its protection settings. You’ll see live blocked-traffic reporting by network type and country.
- Enable VPN, proxy, and Tor detection. Turn on anonymized-connection detection so masked visitors are identified in real time. Choose your action per category-block outright, or challenge and log.
- Block data-center and bot networks. Switch on data-center (ASN/hosting) blocking so card-testing bots running on cloud infrastructure never load your store. This alone removes a large share of automated abuse.
- Layer in country and city rules. Pair network detection with geographic blocking to close the origin-laundering loophole-so a fraudster can’t VPN into an allowed country to sidestep your country filter.
- Set friction, not just walls. For commercial VPNs where you’d rather not lose legitimate shoppers, use a softer action and reserve hard blocks for data-center and Tor traffic.
- Monitor and tune. Review the blocked-traffic dashboard weekly, watch for false positives in your support inbox, and adjust each category’s action as your data accumulates.
Because enforcement happens at the front door rather than at checkout, blocked traffic never scrapes your catalog, never tests cards, never pollutes your analytics, and never slows your store for real customers. If you want the deeper configuration walkthrough, our VPN and proxy blocking guide covers the settings in detail.
Ready to see how much masked traffic your store is getting? Install Kedra Shield and turn on VPN, proxy, and Tor detection in minutes.
Frequently asked questions
Why do fraudsters use VPNs and proxies?
Fraudsters use VPNs and proxies to hide their real IP address and location, which lets them spoof a trusted country to match a stolen card, rotate IPs to evade rate limits and blocklists, and appear as unlimited “new” customers. The anonymity defeats the location, reputation, and repeat-offender signals that fraud filters depend on.
Can a VPN make a fraudulent order look like it’s from another country?
Yes. A VPN routes a connection through a server in a chosen country, so a fraudster in a high-risk region can appear to shop from the US or EU-matching the billing country of a stolen card and slipping past country-based fraud rules. This is why country blocking alone is porous and needs VPN and proxy detection alongside it.
Are residential proxies worse than regular VPNs for merchants?
Often, yes. Residential proxies borrow the IP addresses of real households, so they defeat IP-reputation defenses that catch data-center VPNs. The FBI warned in March 2026 that criminals route traffic through home networks to obfuscate their identity. Because these IPs look like genuine consumers and rotate quickly, behavioral signals matter more than IP blocklists for catching them.
Should I block all VPN traffic on my Shopify store?
Not necessarily. Many legitimate shoppers use VPNs for privacy, so a blanket block can cost real sales. A better approach is graduated: block data-center proxies and Tor outright, apply friction (like 3D Secure or manual review) to commercial VPNs, and lean on behavioral signals for residential proxies. Tools like Kedra Shield let you set a different action per connection type.
How do I detect VPN and proxy orders on Shopify?
Shopify’s native tools don’t flag anonymized connections, so you need a dedicated security app. Kedra Shield identifies VPN, proxy, Tor, and data-center traffic in real time using continuously updated network intelligence, then blocks or challenges it at the storefront entry point-before the visitor reaches your product pages or checkout.
The bottom line
Fraudsters love VPNs for one reason: anonymity turns off the signals that would otherwise catch them. A masked IP lets a single attacker spoof trusted countries, test stolen cards, rack up chargebacks, take over accounts, and abuse promotions-all while blending into normal traffic. With online payment fraud losses climbing into the hundreds of billions and residential-proxy infrastructure growing every quarter, the anonymity gap is widening, not closing.
You don’t have to choose between security and legitimate shoppers. By identifying the type of anonymized connection and applying a graduated response-hard blocks for data-center and Tor traffic, friction for commercial VPNs, behavioral scrutiny for residential proxies-you shut down the abuse without punishing the privacy-conscious customers who buy from you honestly.
Kedra Shield brings that layered VPN, proxy, Tor, and data-center defense to your Shopify store in minutes, with maintained intelligence and front-door enforcement that keeps your site fast. Start by turning on anonymized-connection detection and watching what your blocked-traffic dashboard reveals-most merchants are surprised how much masked traffic was reaching checkout unchecked.