You’re scrolling through your news feed when a headline grabs your attention: The North Face has experienced a customer account breach. 

You move on and go about your day, but the story gets stuck in your head. There wasn’t a dramatic website outage or ransom demand. Attackers simply used stolen login credentials to access customer accounts. 

If something similar happened to your store, how would you find out? Would one of your security tools alert you? Would you notice unusual activity? Or would your first warning come from a customer?

Support watches tickets, ops watches orders, your agency watches uptime. A card-testing run looks like background noise in each of those views — a few odd tickets, a bump in failed payments, nothing on the uptime chart — and only looks like an attack when someone sees all three at once. Most teams have no one positioned to see all three at once.

The most important first step is to understand exactly what’s normal for your store so you know when something isn’t right. Sit down with your team this week and document your average daily order volume, typical refund rate, failed orders, and average order value. Take note of the plugins and admin-level user accounts that already exist on your site.

Even for large stores, the WordPress dashboard provides clues to potential problems. You just need to know what to look for.

Most of these signs don’t indicate a security issue on their own. It’s important to consider them in context of everything else happening on your site. 

WooCommerce Analytics

WooCommerce Analytics gives you a baseline for what normal store activity looks like. Go to Analytics → Orders in your WordPress dashboard and watch out for:

  • Unexplained order spikes or clusters of small orders in a short period, which could indicate card testing fraud.
  • Sudden drops in completed orders, which may point to malicious code, a DDoS attack, or unauthorized changes to the checkout process.
  • Unusual refund activity, which could signal compromised accounts.

Order history

Your order history is often the first sign that something is wrong. Watch for:

  • Unpaid orders marked as complete, which could be a compromised account or malicious code manipulating orders.
  • A sudden increase in failed or low-value orders, often associated with card testing or automated attacks.
  • Unexpected refund spikes, a potential sign of unauthorized activity.

Pro tip: Payment gateways like WooPayments and Stripe have built-in fraud protection. If you’re using a different provider, look into how they handle fraud protection and see if your dev team needs to tighten the rules on your account. 

User accounts

In the Users section of your WordPress dashboard, see who can access your store and what actions they can take. Look out for:

  • Unexpected Administrator accounts that weren’t created by your team.
  • Rapid spikes in user registrations, which could indicate automated spam activity.
  • Accounts with similar names or email addresses, which are patterns bots use for automated account creation.

There are a few additional areas in your WordPress dashboard where unusual activity can appear:

  • Plugins and themes: Look for anything that isn’t supposed to be there, like an unexpected tool or one with a suspicious name.
  • Pages and posts: Check for changes or new content your team didn’t create.
  • Comments: Comment spam often appears alongside automated account registration.

The WordPress dashboard provides valuable clues, but it doesn’t directly identify a hacking attempt or security breach.

To get the full picture, add tools that connect the dots and help you determine whether things like order spikes are due to a hack or something else. You also want instant alerts to malware, vulnerabilities, and downtime so your team can respond before small issues snowball.

Start with Jetpack Security, which sends real-time security alerts and includes an activity log with actionable visibility into everything that takes place on your site. 

Anti-fraud Shield for WooCommerce should be your next priority. This tool flags high-risk orders and alerts your team based on the risk factors you set. It goes one step beyond your payment gateway’s built-in fraud protection.

Datadog is a great option for multichannel stores, monitoring security everywhere you sell and compiling the data into one central dashboard. This extends your team’s view beyond just WooCommerce.

Many hosts also alert you to malware and other security issues. For example, some track site vulnerabilities and security issues directly in the hosting dashboard and send alerts about anything concerning. 

When these systems are connected, you can detect unusual patterns earlier, understand their cause, and deal with issues before they escalate. 

While everything above helps you put together a security strategy moving forward, this can take some time to plan. In the meantime, here are a few ways you can reduce unnecessary risk today:

  1. Audit your users. Go through your list of users and remove any who don’t belong, like previous employees or contractors. Review existing roles and confirm that each one has the lowest permission level required to complete their job. Take things one step further by requiring two-factor authentication for Administrators.
  2. Check REST API Keys connected to WooCommerce. In your WordPress dashboard, go to WooCommerce → Settings → Advanced → REST API keys. Remove any unused keys and audit those with read/write access.
  3. Audit your  WooCommerce logs. The information found under WooCommerce → Status → Logs looks at sources pulling data from your site. Check for services you’re no longer using or anything else that seems out of place. These logs can get technical, so it’s always a good idea to have your developer look it over.
  4. Review site traffic logs. Ask your developer to search for unwanted traffic through hosting logs or your analytics tool. Consider blocking unwanted traffic at the hosting level to avoid draining site resources. 

Security alerts matter, but they don’t always show up first. Early signs often appear as small shifts in orders, accounts, or site activity. The key is noticing those changes and responding to them quickly.

Get your business started on WooCommerce
Christopher Jones Avatar

About

Christopher Jones

Christopher is a Solutions Architect at Woo, partnering with growing merchants to solve the tricky technical problems standing in the way of their next stage of growth. When he’s not working, he’s somewhere on the Carolina coast with his family and their golden doodle, or holding a dessert he has no intention of putting down.

Similar Posts