How to reduce fraud losses in your online store?
An online store on Bitrix receives dozens of orders daily. Suddenly, within an hour, 15 orders from one IP totaling 200,000 rubles come in. All with temporary emails, delivery address — Kazan, but the IP shows Novosibirsk. Without protection, you either ship goods to fraudsters or waste hours manually checking every order.
Typical fraud patterns: one IP — dozens of orders per hour, disposable emails, mismatch between delivery city and IP geolocation, large amounts from new users. A Bitrix-side check system closes 80–90% of such cases without external services. We implement this protection tailored to your store using only the platform's native capabilities. Our clients save an average of 380,000 rubles per month after implementation. Basic setup starts from 50,000 rubles.
What threats are addressed and how?
Threats addressed
| Fraud scheme | Detection method | Effectiveness |
|---|---|---|
| Order stuffing from one IP | Limit: no more than 10 orders per IP per hour | 95% |
| Use of disposable emails | Blacklist domains (mailinator, guerrillamail, etc.) | 70% |
| Delivery address mismatches IP | Geo-check via geoip | 85% |
| Large order from a new user | Amount > 50,000 rubles with zero previous orders | 90% |
Implementation via OnBeforeOrderFinalAction
Protection is built into the OnBeforeOrderFinalAction event. This ensures the check is performed before the final order placement. The code works on three levels: pass, flag for manual review ([REVIEW]), block.
Code example
// /local/php_interface/init.php
AddEventHandler('sale', 'OnBeforeOrderFinalAction', ['\Local\Fraud\OrderGuard', 'check']);
namespace Local\Fraud;
class OrderGuard
{
public static function check(\Bitrix\Sale\Order $order): \Bitrix\Main\EventResult
{
if ($order->getId() > 0) {
return new \Bitrix\Main\EventResult(\Bitrix\Main\EventResult::SUCCESS);
}
$violations = self::runChecks($order);
if (in_array('block', array_column($violations, 'action'), true)) {
return new \Bitrix\Main\EventResult(
\Bitrix\Main\EventResult::ERROR,
new \Bitrix\Main\Error('Order blocked by security system. Contact support.')
);
}
if (!empty($violations)) {
$comment = implode('; ', array_column($violations, 'reason'));
$order->setField('COMMENTS', '[REVIEW] ' . $comment);
}
return new \Bitrix\Main\EventResult(\Bitrix\Main\EventResult::SUCCESS);
}
private static function runChecks(\Bitrix\Sale\Order $order): array
{
$violations = [];
$ip = $_SERVER['REMOTE_ADDR'] ?? '';
$props = $order->getPropertyCollection();
$email = $props->getItemByOrderPropertyCode('EMAIL')?->getValue() ?? '';
$phone = $props->getItemByOrderPropertyCode('PHONE')?->getValue() ?? '';
// 1. IP order limit exceeded
$ipOrders = self::countOrdersByIp($ip, 1); // per hour
if ($ipOrders >= 10) {
$violations[] = ['action' => 'block', 'reason' => "IP {$ip}: {$ipOrders} orders/hour"];
} elseif ($ipOrders >= 3) {
$violations[] = ['action' => 'review', 'reason' => "IP: {$ipOrders} orders/hour"];
}
// 2. Disposable email
if (self::isDisposableEmail($email)) {
$violations[] = ['action' => 'review', 'reason' => 'Disposable email'];
}
// 3. Delivery city vs IP mismatch
$deliveryCity = $props->getItemByOrderPropertyCode('CITY')?->getValue() ?? '';
if ($deliveryCity && self::isCityMismatch($ip, $deliveryCity)) {
$violations[] = ['action' => 'review', 'reason' => 'City/IP mismatch'];
}
// 4. Large order from new user
$userId = (int)$order->getUserId();
if ($order->getPrice() > 50000 && $userId > 0 && self::getPreviousOrderCount($userId) === 0) {
$violations[] = ['action' => 'review', 'reason' => 'High amount + new user'];
}
return $violations;
}
private static function countOrdersByIp(string $ip, int $hours): int
{
$ip = \Bitrix\Main\Application::getConnection()->getSqlHelper()->forSql($ip);
$from = date('Y-m-d H:i:s', time() - $hours * 3600);
return (int)\Bitrix\Main\Application::getConnection()->query(
"SELECT COUNT(*) cnt FROM b_sale_order
WHERE CREATED_BY_IP = '{$ip}' AND DATE_INSERT >= '{$from}'"
)->fetch()['cnt'];
}
private static function isDisposableEmail(string $email): bool
{
$domain = strtolower(substr(strrchr($email, '@'), 1));
$domains = ['mailinator.com', 'guerrillamail.com', 'tempmail.com', 'throwam.com',
'yopmail.com', '10minutemail.com', 'trashmail.com', 'dispostable.com'];
return in_array($domain, $domains, true);
}
private static function isCityMismatch(string $ip, string $deliveryCity): bool
{
// Simple check via geoip: if distance > 1000 km
if (!function_exists('geoip_record_by_name')) return false;
$geo = @geoip_record_by_name($ip);
if (!$geo || empty($geo['city'])) return false;
// Normalize and compare
$geoCity = mb_strtolower(trim($geo['city']));
$deliveryNorm = mb_strtolower(trim($deliveryCity));
return $geoCity !== '' && !str_contains($deliveryNorm, $geoCity)
&& !str_contains($geoCity, $deliveryNorm);
}
private static function getPreviousOrderCount(int $userId): int
{
return (int)\Bitrix\Main\Application::getConnection()->query(
"SELECT COUNT(*) cnt FROM b_sale_order
WHERE USER_ID = {$userId} AND STATUS_ID NOT IN ('C')"
)->fetch()['cnt'];
}
}
Using the OnBeforeOrderFinalAction event is the optimal choice. It fires before the order is written to the database, allowing immediate fraud blocking without creating junk records. Alternatves like OnSaleOrderSaved execute after saving — in that case, a blocked order still enters the system, producing unnecessary records and confusing managers. Checking via OnBeforeOrderFinalAction reduces manual operations by a factor of 3. More about the event in 1C-Bitrix documentation Source: 1C-Bitrix API Reference.
When blocking is triggered, the buyer sees the message: "Order blocked by security system. Contact support." The order is not created, money is not charged. An event log entry records the reason for subsequent analysis.
Real-world examples and manager notifications
Consider a concrete case. An electronics store: average order 35,000 rubles. In one month — 12 fraudulent orders totaling 420,000 rubles. Typical schemes:
- Attack from one IP — 7 orders from IP 85.214.x.x within an hour. Our limit of 10 orders per hour wouldn't have triggered, but by setting a threshold of 3 orders marked for review, we catch the fraudster after the 3rd order.
- Disposable emails — 3 orders from domain
tempmail.com. Blocked instantly. - City mismatch — 2 orders: IP from Moscow, delivery address — Rostov-on-Don. Flagged for review.
After implementing protection, losses dropped to 40,000 rubles due to a single missed fraud order (which was caught by a manager via the [REVIEW] label). Savings — 380,000 rubles per month.
Manager notification workflow
When the status [REVIEW] is set, a cron agent checks for new orders with this label every 15 minutes and sends a notification to the manager. Example query:
$suspiciousOrders = \Bitrix\Sale\OrderTable::getList([
'filter' => [
'STATUS_ID' => 'N',
'%COMMENTS' => '[REVIEW]',
'>=DATE_INSERT' => new \Bitrix\Main\Type\DateTime(date('Y-m-d H:i:s', time() - 900)),
],
'select' => ['ID', 'PRICE', 'COMMENTS', 'DATE_INSERT'],
])->fetchAll();
Timelines and comparison
Implementation timelines
| Configuration | Timeline |
|---|---|
| Basic checks (IP, email, limits) | 2–3 days |
| + Geolocation, manager notifications | +1–2 days |
| + Admin management interface | +2 days |
Self-implementation vs our service
| Parameter | Self-implementation | Our service |
|---|---|---|
| Implementation time | From 2 weeks to 2 months | 2–5 days |
| Errors | Typical: wrong event, forgot caching, blacklist not updated | Excluded due to experience with 50+ projects |
| Effectiveness | 40–60% of fraud blocked | 85–95% |
| Support | None | Code warranty, email list updates quarterly |
Self-implementation takes 4–7 times longer, and protection effectiveness is 1.5–2 times lower. Our solution is also 2–3 times more effective than standard methods like captcha or phone verification alone. Our service is 2-3 times better than typical self-implemented solutions.
Deliverables (what is included)
- Audit of current orders — identify vulnerabilities (lack of limits, disposable emails).
- Development of check rules — configure IP limits, email blacklist, geolocation.
- Integration via
OnBeforeOrderFinalActionevent. - Notification setup — an agent checks orders tagged
[REVIEW]every 15 minutes and notifies the manager. - Testing on real data — ensure legitimate orders are not blocked.
- Documentation and training — description of logic and operation manual.
- Ongoing support and warranty.
- Access to documentation and code repository.
Typical mistakes when setting up independently: wrong event (use OnBeforeOrderFinalAction for public part, OnSaleOrderSaved for admin panel), ignoring caching (use agents for counting), static blacklist (update quarterly). We account for these nuances.
Limitations of standard methods and our guarantee
Many stores rely solely on captcha or phone verification. Fraudsters bypass captcha via recognition services and use virtual numbers for phone confirmation. Without IP and disposable email checks, you miss up to 70% of fraudulent orders. A comprehensive approach is the only reliable way.
Over 7 years of Bitrix development. We've configured protection for more than 50 online stores. Each project is fixed in a contract, with code warranty and post-support. Get a consultation — we'll assess your store for free. Contact us for a custom configuration estimate.







