How to Protect Your eCommerce Store from Bot Attacks and Card Testing

What are the signs of bot activity in a SuiteCommerce store?
Most businesses notice the symptoms long before they know the cause. The evidence sits in NetSuite and in the payment gateway, and it usually looks like ordinary admin noise:
- - Customer or guest shopper records in NetSuite that belong to nobody.
- - Sign-ups from random or bouncing email addresses.
- - Repeated failed payment attempts, on one card or across many.
- - Small test charges on cards, often for low-value items.
Each item looks minor on its own. Together they point to automated activity, and the scale is large. Akamai's 2026 report Securing the Agentic Storefront: Attacks on Commerce found that more than 17 trillion bots hit commerce globally in 2025, and that bot counts across APAC grew 63%, more than any other region. This guide, from the SuiteCommerce team at Jobin & Jismi, explains why eCommerce bot attacks happen, what they cost, and how to stop them without slowing down real buyers.
Why do bot attacks on eCommerce stores target sign-up and checkout?
Bot attacks on eCommerce stores focus on sign-up and checkout because those forms are public and open around the clock. They have to be, or customers could not buy. Automated scripts scan the web for exactly these forms and use them to create accounts in bulk, start checkouts they never finish, or test stolen card numbers with small transactions.
Bot traffic is not a sign that anyone did anything wrong. It does not mean the store is misconfigured or the team missed something. Any store with an open sign-up page and a payment form will attract it. The question is not whether bots arrive, but how much damage they do once they do.
What do bot attacks cost your business?
Bot attacks cost a SuiteCommerce business in four places: the quality of NetSuite data, the time of the sales team, standing with payment providers, and the experience of genuine customers.
Dirty ERP data in NetSuite
This is the cost most specific to SuiteCommerce. The web store and the ERP share one database, so there is no separate commerce platform holding bot sign-ups at arm's length. A registration, or a guest checkout, writes a customer or guest shopper record straight into NetSuite, often before any order exists.
Once those records sit beside real customers, every report built on the customer base inherits the noise. Customer counts and new-account trends inflate. Abandoned-cart searches fill with carts nobody will return to. Segmentation and marketing lists pick up addresses that bounce, which drags down campaign performance and sender reputation. Finance and operations teams then make decisions on numbers they cannot fully trust.
The cleanup is manual. Someone has to find the records, confirm they are fake, and exclude or delete them, and the same work returns with the next wave. That is time spent maintaining data instead of using it, and it is why NetSuite eCommerce security is a data quality question as much as a security one.
J&J IMPLEMENTATION OBSERVATION
We see this pattern repeatedly across the SuiteCommerce and SuiteCommerce Advanced stores we support. On one US store, the client reported 53 bot-created guest shopper records in a single day. The bots added items to the cart and walked through guest checkout, which created the record in NetSuite, then abandoned the order. A member of the client's team was deleting the records by hand. On another, bot sign-ups filled the abandoned-cart saved search with junk leads, which is how the client first noticed the problem.
Wasted sales time
A fake account can look like a genuine prospect. Reps review it, send emails, and make calls before discovering it has no commercial value. When lead lists contain enough of these, real opportunities get harder to spot and pipeline reports lose credibility.
Payment processor risk
Card testing turns checkout into a test bench for stolen cards. Each attempt can produce an authorisation, a decline, or a failed transaction, and a sustained pattern draws scrutiny from payment providers. The Merchant Risk Council's 2025 Global eCommerce Payments and Fraud Report, based on a survey of 1,082 merchant professionals in 38 countries, found that 32% of merchants had experienced card testing in the previous 12 months.
The direct loss is only part of the bill. The 2026 LexisNexis True Cost of Fraud Study for Retail and Ecommerce found that every $1 of fraud loss costs US retail and eCommerce businesses approximately $5.13 once the wider operational impact is counted. Not every failed payment is fraud. The risk lies in the repeated pattern and the review work it creates.
Real customers caught in the middle
Every defence against bots adds a check that real buyers may also have to pass. Get the placement wrong and the business pays for its protection in lost or slower orders. That trade-off shapes which kind of protection makes sense, and it is covered after the options below.
What does bot protection for eCommerce look like on SuiteCommerce?
SuiteCommerce stores have two practical options: Oracle's native SuiteCommerce CAPTCHA, or an extension. Which one fits depends first on the store's version.
Oracle now ships its own SuiteCommerce CAPTCHA, and for stores that can use it, it is a reasonable choice. According to Oracle NetSuite documentation, it works with SuiteCommerce, SuiteCommerce MyAccount, and SuiteCommerce Advanced 2025.2 and later, using hCaptcha or Google reCAPTCHA v2. It covers customer registration, login, place order, and guest checkout, and administrators choose where challenges appear. The same 2025.2 release added SuiteCommerce Email Verification and SuiteCommerce Email Domains Blocklist, which help stop sign-ups from fake or disposable email addresses.
The constraint is the version. Every SuiteCommerce Advanced implementation on a release earlier than 2025.2 cannot use Oracle's CAPTCHA without upgrading first. We meet this regularly in established SCA stores, many of which carry customisations that make an upgrade a project in its own right. One US client on SCA 2022.1.3 came to us after finding the native CAPTCHA was not compatible with its version.
Jobin & Jismi ReCAPTCHA Guard covers the stores Oracle's option leaves out. It is an extension for SuiteCommerce and SuiteCommerce Advanced that protects account sign-up and checkout, and it uses score-based validation instead of challenging every user.
Users with higher scores can proceed without an additional challenge, while lower scores may trigger ReCAPTCHA verification. This approach keeps additional verification focused on activity that requires closer review, rather than applying the same challenge to every customer.
This SuiteCommerce bot protect solution is an alternative to native SuiteCommerce CAPTCHA. The right approach depends on the store’s version, protected flows, customizations, and customer-experience requirements.
How does Oracle SuiteCommerce CAPTCHA compare with Jobin & Jismi ReCAPTCHA Guard?
Area | Oracle SuiteCommerce CAPTCHA | Jobin & Jismi ReCAPTCHA Guard |
Version requirement | SuiteCommerce, SuiteCommerce MyAccount, SuiteCommerce Advanced 2025.2 and later | SuiteCommerce and SuiteCommerce Advanced, all versions |
Method | hCaptcha or Google reCAPTCHA v2 | Score-based behavioural validation |
User experience | Challenge shown at the points the administrator chooses | High-scoring users continue without interruption; challenge only when behaviour looks suspicious |
Protects | Customer registration, login, place order, guest checkout | Account sign-up and checkout |
Setup | Native configuration in NetSuite | 3 to 5 business days |
In both options, bot protection stops automated, as bot-driven activity. It does not stop manual fraud, where a person places an order with stolen details. That needs separate fraud screening, and no CAPTCHA, native or third-party, replaces it.
Why does reCAPTCHA friction matter for B2B buyers?
A challenge shown to a real buyer is friction on an order you have already won. For a distributor whose customers reorder every week, that friction repeats every week, for the same loyal accounts, on the orders that matter most to revenue. The cost is measurable: the 2026 LexisNexis True Cost of Fraud Study found that 56% of US retailers and 54% of US eCommerce merchants reported increased customer churn linked to anti-fraud measures.
This is where reCAPTCHA for eCommerce needs care. Score-based validation takes a different approach. It checks behaviour silently in the background and assigns an authenticity score. On ReCAPTCHA Guard, users with a high score complete payment without interruption, and only lower-scoring sessions are asked to complete a challenge. Genuine customers see nothing extra. Bots meet a check they struggle to pass.
We see buyers weigh this directly. The client with 53 bot records in a day ruled out any challenge at login, where regular buyers sign in, but was open to one at account creation, where the bots actually were. Placement decisions like this matter more than the choice of provider.
Before recommending bot protection for a SuiteCommerce store, we answer three questions in order.
1. Version. Which SuiteCommerce or SuiteCommerce Advanced release is the store on? This decides whether Oracle's native CAPTCHA is available at all.
2. Flow. Where are bots actually getting in: sign-up, guest checkout, or login?
3. Friction. Which customers should never see a challenge? For most B2B stores, the answer is repeat buyers.
J&J PROCESS NOTE
Challenge guests, not loyal customers. For one SuiteCommerce client facing card testing through guest checkout, we scoped a visible challenge for guest shoppers only. Logged-in customers kept their checkout exactly as before.
Keep NetSuite's own delivery network in front of the store. Some teams consider putting a third-party firewall such as Cloudflare in front of the web store. NetSuite runs its own CDN and caching, so we advised that client against it: a third-party layer can disrupt checkout, payments, and SSL, and complicates support from NetSuite.
Test sign-in routes before go-live. On another store, a CAPTCHA blocked single sign-on logins until the SSO route was excluded. Every rollout should be tested against SSO and payment flows first, which is why we scope bot protection as part of our NetSuite integration services rather than as a standalone plug-in.
Which SuiteCommerce bot protection solutions fit your store?
Choosing between SuiteCommerce bot protection solutions starts with the version, because eCommerce bot attacks hit every store but not every store can run the same fix. Stores on SuiteCommerce Advanced 2025.2 or later can use Oracle's native SuiteCommerce CAPTCHA. Stores on any version can use Jobin & Jismi ReCAPTCHA Guard, which uses score-based bot protection at sign-up and checkout, keeps genuine buyers moving, and takes 3 to 5 business days to set up.
Jobin & Jismi is an Oracle NetSuite Solution Provider Partner and one of the NetSuite implementation partners in India with a dedicated SuiteCommerce practice. Whether you are planning a SuiteCommerce Advanced implementation reviewing NetSuite E-Commerce security, or evaluating SuiteCommerce bot protection solutions, our team can check your version and the flows bots are hitting before recommending either.
on LinkedIn
Frequently Asked Questions
eCommerce bot attacks are automated scripts that hit a web store's public forms, mainly sign-up, login, and checkout, at a volume no human shopper would produce. They create fake accounts, start checkouts they never finish, and run stolen card numbers through payment forms. Akamai's 2026 report Securing the Agentic Storefront: Attacks on Commerce found that more than 17 trillion bots hit commerce globally in 2025.
Card testing is the practice of running stolen card numbers through small or low-value transactions to find out which cards still work. Guest checkout is a common target because it needs no account before payment. The Merchant Risk Council's 2025 Global eCommerce Payments and Fraud Report found that 32% of merchants surveyed had experienced card testing in the previous 12 months.
reCAPTCHA for eCommerce is a verification layer that separates human shoppers from bots at sign-up, login, and checkout. Challenge-based versions ask every shopper to complete a task, while score-based validation checks behaviour silently and challenges only suspicious sessions. The choice affects conversion: the 2026 LexisNexis True Cost of Fraud Study for Retail and Ecommerce found that 56% of US retailers and 54% of US eCommerce merchants reported increased customer churn linked to anti-fraud measures.
Yes, for stores on supported versions. SuiteCommerce CAPTCHA works with SuiteCommerce, SuiteCommerce MyAccount, and SuiteCommerce Advanced 2025.2 and later, using hCaptcha or Google reCAPTCHA v2. It covers customer registration, login, place order, and guest checkout. It does not currently cover Quotes to Sales Order, Invoice Payment, Skip Checkout Login, or Support Cases.
Yes. Oracle's native SuiteCommerce CAPTCHA requires SuiteCommerce Advanced 2025.2 or later, so an older SuiteCommerce Advanced implementation cannot use it without an upgrade. Jobin & Jismi ReCAPTCHA Guard supports all SuiteCommerce and SuiteCommerce Advanced versions, protects account sign-up and checkout, and takes 3 to 5 business days to set up.
No. ReCAPTCHA Guard addresses automated, bot-driven activity such as fake sign-ups and card testing at checkout. Manual fraud, where a person places an order with stolen details, is a different problem that needs separate fraud screening. Any vendor that claims one tool stops every type of fraud is overstating what bot protection does.
It can be. When checkout connects to payment gateways, single sign-on, or other systems, bot protection has to be tested against each of those connections, so it often sits within a wider NetSuite integration services scope. On one SuiteCommerce store, a CAPTCHA blocked single sign-on logins until the sign-on route was excluded, which is why Jobin & Jismi tests every integrated flow before go-live.


