Using IP and ASN Checks to Cut Checkout Fraud: A Worked Example
Updated Published by Kishan Prajapat, SEO & Content Lead
Drafted with Citeya, an AI writing tool built by KPThink.
This is an illustrative scenario, not a report of a real incident. The people, companies, IP addresses (from the ranges reserved for documentation) and figures are made up to show how the investigation works.
Chargebacks hurt small shops twice: the money goes back to the cardholder, and the shop usually pays a dispute fee on top. Picture a small clothing store losing several thousand dollars a week to orders placed with stolen card details. The card numbers, names and billing addresses all check out, because the fraudsters bought complete card profiles.
Look at where the orders come from
Exporting the IP addresses behind recent orders and running them through an IP lookup gives locations near the cardholders, which looks reassuring. The ASN lookup tells a different story: the fraudulent orders come mostly from networks owned by hosting and cloud providers, while genuine customers connect from consumer broadband and mobile networks.
That makes sense. The fraudsters route their checkouts through rented servers, datacenter proxies and VPNs so the IP appears to be in the right country. Location can be faked that way; the type of network behind the IP is much harder to hide.
Turn the pattern into a rule
IP Dekho’s tools are good for investigating by hand, but a checkout needs an automated check. Commercial IP intelligence services return the network type (hosting, residential, mobile) for an IP through an API. A small piece of middleware can then hold risky orders instead of blocking them outright:
const info = await ipIntel.lookup(req.ip); // your IP data providerif (info.networkType === "hosting" || info.isKnownProxy) order.status = "PENDING_REVIEW";
Holding rather than blocking matters, because some genuine customers shop through a privacy VPN. A person reviews the held orders, for example by calling the phone number on the order, before anything ships.
What it can and can’t do
A network-type check catches the lazy majority of fraud that runs through hosting providers. It does little against residential proxies, which route traffic through real home connections, and it adds some friction for VPN users. Combine it with other signals: shipping to known freight forwarders, first-time customers choosing the fastest delivery, and orders placed in bursts overnight.
Before relying on any IP data, read our explainer on how accurate IP geolocation really is.
Check an IP’s Network
See which network and ASN an IP address belongs to, and which organization runs that network.
Run an ASN LookupSpotted a mistake? Tell usand we'll correct it.
Related Articles
Tracing a Suspicious IP During a Database Leak: A Walkthrough
An illustrative walkthrough: a replica database starts streaming data to an unknown IP at 2 AM. How to stop it, identify the IP’s owner, and find the misconfiguration that let it in.
Investigating an “Impossible Travel” Login Alert: A Walkthrough
An illustrative walkthrough of triaging an impossible-travel alert with WHOIS, reverse DNS and a port scan, and deciding whether it’s an attack or an employee on a VPN.
Diagnosing a Partial Outage After a DNS Change: A Walkthrough
An illustrative walkthrough: after a server move, some users reach the site and others time out. How cached DNS records cause it, how to confirm it, and how to avoid it next time.
WestJet first told Boeing about 737 MAX software g
Explains how WestJet first reported a 737 MAX flight-computer software glitch, why regulators delayed MAX 10 certification, and what airlines and crews must do now.
