As you browse through your news feed, a headline catches your eye: The North Face has fallen victim to a customer account breach.
You continue with your day, but the news stays with you. There were no major website crashes or ransom requests. The attackers simply used stolen login credentials to get into customer accounts.
If a similar incident occurred at your store, how would you know? Would your security tools alert you? Would you spot any unusual activity? Or would a customer be the first to inform you?
Support keeps an eye on tickets, ops monitors orders, and your agency watches over uptime. A card-testing operation might blend in with the regular flow—some strange tickets, a spike in failed payments, nothing abnormal on the uptime chart—and only stand out as an attack when all three aspects are observed together. Most teams lack someone in a position to oversee all three simultaneously.
The crucial initial step is to grasp what is typical for your store so that you can recognize when something is amiss. Sit down with your team this week and record your average daily order volume, standard refund rate, failed orders, and average order value. Take note of the plugins and admin-level user accounts already present on your site.
Even for larger stores, the WordPress dashboard offers hints of potential issues. You just need to know where to look.
Most of these indicators do not point to a security problem on their own. It is essential to assess them in the context of everything else happening on your site.
WooCommerce Analytics
WooCommerce Analytics sets a benchmark for what regular store activity looks like. Navigate to Analytics → Orders in your WordPress dashboard and be on the lookout for:
- Unexplained spikes in orders or clusters of small orders within a short timeframe, which could indicate card testing fraud.
- Sudden drops in completed orders, signaling potential malicious code, a DDoS attack, or unauthorized alterations to the checkout process.
- Unusual refund patterns, which might indicate compromised accounts.
Order history
Your order history often serves as the initial red flag that something is off. Watch out for:
- Unpaid orders marked as completed, possibly due to a compromised account or malicious code manipulating orders.
- A sudden rise in failed or low-value orders, often linked to card testing or automated attacks.
- Surprising spikes in refunds, potentially indicating unauthorized activity.
Tip: Payment gateways like WooPayments and Stripe come equipped with built-in fraud protection. If you are using a different provider, investigate how they handle fraud protection and assess whether your development team should enhance the account rules.
User accounts
Within the Users section of your WordPress dashboard, review who has access to your store and their permissions. Be wary of:
- Unexpected Administrator accounts not authorized by your team.
- Rapid spikes in user registrations, potentially indicating automated spam activity.
- Accounts with similar names or email addresses, common patterns used by bots for automated account creation.
There are a few other areas in your WordPress dashboard where irregular activity might surface:
- Plugins and themes: Keep an eye out for anything out of place, such as an unexpected tool or one with a suspicious name.
- Pages and posts: Check for any modifications or new content not created by your team.
- Comments: Comment spam often accompanies automated account registration.
The WordPress dashboard offers valuable insights but does not directly pinpoint a hacking attempt or security breach.
To gain a comprehensive understanding, integrate tools that connect the dots and help discern whether anomalies like order spikes result from a hack or other causes. Swift alerts to malware, vulnerabilities, and downtime are also crucial so that your team can react promptly to prevent minor issues from escalating.
Begin with Jetpack Security, which delivers real-time security alerts and includes an activity log providing actionable insights into all activities on your site.
Prioritize Anti-fraud Shield for WooCommerce next. This tool flags high-risk orders and notifies your team based on predefined risk factors, going beyond the fraud protection built into your payment gateway.
Datadog serves as an excellent option for multichannel stores, monitoring security across all selling channels and consolidating data into a centralized dashboard. This expands your team’s visibility beyond just WooCommerce.
Many hosting providers also alert you to malware and other security threats. Some monitor site vulnerabilities and security issues directly within the hosting dashboard, sending alerts regarding any concerning issues.
When these systems are interconnected, you can detect unusual patterns sooner, comprehend their origin, and address issues before they escalate.
While the aforementioned strategies aid in devising a security plan for the future, this may require some time to plan out. In the interim, here are a few ways to mitigate unnecessary risks immediately:
- Review your users. Go through your user list and eliminate any unauthorized users, such as former employees or contractors. Review existing roles and ensure each has the minimum necessary permissions. Enhance security by implementing two-factor authentication for Administrators.
- Assess REST API Keys linked to WooCommerce. In your WordPress dashboard, head to WooCommerce → Settings → Advanced → REST API keys. Remove any unused keys and review those with read/write access.
- Examine your WooCommerce logs. The data found under WooCommerce → Status → Logs examines sources extracting data from your site. Look for services you no longer use or any other irregularities. These logs can be technical, so it’s advisable to have your developer review them.
- Review site traffic logs. Ask your developer to investigate unwanted traffic through hosting logs or your analytics tool. Consider blocking unwanted traffic at the hosting level to prevent draining site resources.
While security alerts are crucial, they may not always be the first indicators. Early signs often manifest as subtle shifts in orders, accounts, or site activity. The key is to detect these changes and respond promptly.
Christopher is a Solutions Architect at Woo, teaming up with expanding merchants to tackle the complex technical hurdles hindering their next growth phase. When not at work, he can be found somewhere along the Carolina coast with his family and their golden doodle, or with a dessert he has no intention of setting down.