TL;DR
The clearest signs of a bot attack are traffic from countries you don't serve, sudden spikes from data-center cities like Ashburn, Virginia, add-to-cart events that climb while purchases stay flat, and waves of fake email signups sharing the same patterns. Confirm by checking ISP/ASN data, engagement metrics, and funnel conversion by segment, then block bad bots at the edge before they reach your store, your analytics, and your ad budget.
Table of Contents
- 1. Traffic From Countries You Don't Sell To
- 2. A Surge of Visits From Ashburn, Virginia
- 3. Add-to-Carts Spike, Purchases Don't
- 4. Fake Email Signups Flooding Your ESP
- 5. The Supporting Evidence Most Brands Miss
- 6. How to Confirm the Signs of a Bot Attack
- 7. What to Do Once You've Confirmed It
- FAQ
Bot attacks rarely announce themselves. There's no ransom note, no downtime alert, no flashing red banner in Shopify admin. Instead, the signs of a bot attack show up as small distortions in the numbers you look at every day: a traffic bump you can't explain, a conversion rate that quietly sags, an email list that grows faster than your ad spend justifies. By the time most brands realize what's happening, bots have been skewing their analytics, draining their ad budget, and degrading site performance for weeks.
The good news is that bots leave fingerprints. Automated traffic behaves in ways real shoppers never do, and once you know the four telltale patterns, plus the supporting evidence that confirms them, you can spot an attack in minutes rather than months. Here's exactly what to look for, where to look, and what to do about it.
1. Traffic From Countries You Don't Sell To
You ship to the US and Canada. So why did 4,000 sessions arrive from countries you've never sold a single unit to, this week alone?
Geographic mismatch is one of the most reliable early warnings of automated traffic. Botnets and scraping operations rent compute wherever it's cheap, and cheap compute is global. When a scraper farm spins up against your product catalog, your country report suddenly lights up in markets where you have no shipping zones, no localized site, no marketing, and no history of demand.
Open your analytics and compare your traffic map against your actual shipping zones. The bot pattern looks like this: session counts from unserved countries that rival or exceed your real markets, engagement time near zero, almost no pages per session (or bizarrely many, if it's a crawler walking your entire catalog), and the giveaway: zero revenue. Real international visitors window-shop occasionally. They don't arrive by the thousands overnight with 100% new users and 0% conversion.
One caveat before you reach for the country-block button: VPN users, travelers, and expats buying gifts for family back home are real customers who look geographically "wrong." The signal isn't the existence of foreign traffic; it's the volume, the suddenness, and the total absence of buying behavior. A handful of sessions from anywhere is noise. A vertical spike from a market you don't serve is a pattern.
2. A Surge of Visits From Ashburn, Virginia
Ashburn, Virginia has roughly 45,000 residents and, on any given week, appears in ecommerce analytics dashboards like a city of millions. That's because Ashburn is the heart of "Data Center Alley": the largest concentration of data centers on the planet and home to AWS's us-east-1 region, the default deployment target for a huge share of the world's cloud servers.
Residential shoppers don't cluster in Ashburn. Servers do. When your city report shows Ashburn suddenly outranking New York, Los Angeles, and Chicago, you are not experiencing a Northern Virginia shopping renaissance. You're being hit by bots running on cloud instances that geolocate to the data center hosting them.
Ashburn is the most famous tell, but the same logic applies to other data-center towns: Boardman, Oregon; Council Bluffs, Iowa; The Dalles, Oregon; Columbus, Ohio; and abroad, places like Dublin and Frankfurt. If you check the network dimension on those sessions, they resolve to Amazon, Google Cloud, Microsoft, or bulk hosting providers, not Comcast, Verizon, or Spectrum. Amazon even publishes its full IP ranges, which makes verifying this straightforward in your server or CDN logs.
A small caveat: some legitimate services also live in data centers: uptime monitors, email link scanners, and search engine crawlers among them. That's why data-center geography alone isn't a verdict; it's a flag you corroborate with the behavioral signals below. Legitimate crawlers identify themselves and respect limits. Attack traffic does neither. (For a deeper breakdown of which automated visitors help you and which hurt you, see our guide to good bots vs. bad bots on Shopify.)
3. Add-to-Carts Spike, Purchases Don't
A healthy funnel moves roughly in proportion: more sessions produce more add-to-carts, which produce more checkouts, which produce more orders. When add-to-cart events surge and completed purchases don't move at all, something inhuman is in your funnel.
Bots add items to carts for reasons that have nothing to do with buying. Price and inventory scrapers trigger the cart because that's where the data they want lives: real-time stock levels, shipping rates, regional pricing, and discount logic often only reveal themselves mid-funnel. Scalper and inventory-hoarding bots rehearse the path to checkout so they can strike the moment a drop goes live, and some deliberately park stock in carts to starve real customers. Card-testing bots walk the funnel to probe your checkout before running stolen card numbers through it.
The damage compounds quietly. Your add-to-cart rate looks fantastic while your cart-to-purchase conversion craters, sending your team hunting for a checkout bug that doesn't exist. If your Meta and Google pixels fire on those fake add-to-cart events, your bidding algorithms learn from poisoned data and start optimizing ad delivery toward audiences that look like bots. Your abandonment email flows fire at addresses that will never buy. Every downstream system that trusts the add-to-cart signal inherits the corruption.
The diagnostic is simple: segment your funnel by the suspicious traffic slices from signs one and two. If US residential traffic converts from cart at your historical rate while the Ashburn-and-unserved-countries segment adds to cart constantly and buys nothing, you've found your culprit.
4. Fake Email Signups Flooding Your ESP
The fourth sign lives outside your analytics entirely: your email service provider. If Klaviyo or your ESP of choice suddenly shows list growth wildly out of proportion to your traffic and ad spend, look closely at the new profiles. Bot signups share a family resemblance, and once you see it, you can't unsee it.
Watch for clusters of addresses with the same structure: gibberish local parts, real names with random digits appended, the same domain repeated in runs, or sequential variations of one another. Check the timestamps: humans sign up in bursts around campaigns and browsing hours; bots sign up at machine-regular intervals around the clock. Check engagement: these profiles never open, never click, never buy. Many will hard-bounce on the first send.
Fake signups aren't just clutter. Most ESPs bill by contact count, so every fake profile is a recurring line item on your invoice. Worse, bounces and spam-trap hits degrade your sender reputation, which means mailbox providers start filtering your campaigns away from real customers. And in "list bombing" attacks, your signup form is weaponized to flood a victim's inbox with confirmation emails, making your brand the unwitting instrument of someone else's harassment campaign. Enabling double opt-in blunts the list-quality damage, but it treats the symptom: the bots are still hammering your forms, your site, and your analytics.
5. The Supporting Evidence Most Brands Miss
The four headline signs rarely travel alone. When an attack is underway, you'll usually find several of these secondary tells corroborating the story.
Engagement metrics collapse. Average engagement time drops toward zero, bounce rate jumps, and the share of "new users" approaches 100% because every bot session arrives cookieless. If your bounce rate moved sharply without a site or campaign change, ask who's doing the bouncing.
Direct and unattributed traffic spikes. Bots don't click your ads or your Instagram bio. A surge in direct/(none) traffic with no matching brand-awareness activity is automation, not sudden fame.
Your infrastructure feels it. Origin server load climbs, bandwidth bills grow, and uncached endpoints like search and cart slow down, which means real shoppers wait longer on the pages that matter most. Bot load doesn't just skew your data; it taxes the site speed that drives your conversions. Run your store through a free speed test during a suspected attack window and compare it against your baseline.
Your experiments stop making sense. A/B tests that swing wildly, retargeting audiences that balloon overnight, and paid campaigns whose click-through rises while conversion falls are all downstream symptoms of non-human participants contaminating the sample.
6. How to Confirm the Signs of a Bot Attack
Suspicion becomes confirmation with about thirty minutes of segmentation work.
First, build a comparison segment in your analytics: suspicious geographies (unserved countries plus data-center cities) versus your core markets. Compare engagement time, pages per session, add-to-cart rate, and purchase conversion between the two. Bots fail the human test on every metric at once.
Second, go one layer deeper than analytics. Pull your server or CDN logs and look at the ASN behind the suspicious IPs; traffic originating from hosting providers rather than consumer ISPs is the single strongest technical confirmation. Cross-reference against published cloud IP ranges. While you're there, scan user-agent strings: fleets of identical, outdated, or headless-browser user agents are another fingerprint.
Third, don't assume your analytics platform has already handled this. GA4 automatically excludes known bots, but "known" means self-declared crawlers on the IAB spiders list. Modern malicious bots run full headless browsers, rotate residential proxies, and mimic human mouse movement. They are engineered specifically to pass these filters, which is why they show up in your reports looking like real sessions in the first place.
Finally, timestamp everything. Note when the anomaly began and check it against your marketing calendar. If nothing you did explains the inflection point, something someone else did probably does.
7. What to Do Once You've Confirmed It
Resist the two most common first reactions. Blanket country blocking sacrifices real customers (VPN users, travelers, diaspora gift-buyers) while sophisticated bots simply hop to residential proxies inside your home market. And CAPTCHAs alone won't save you: solver services defeat them at scale for fractions of a cent, while the friction lands entirely on your legitimate shoppers.
Effective bot defense happens at the edge, before requests ever reach your store. That means evaluating every request's network, fingerprint, and behavior in real time: letting good bots like Googlebot through, blocking scrapers, scalpers, and fake-signup bots outright, and doing it invisibly so real customers never see a challenge screen. That's exactly what Nostra Edge Protect does: it sits at the edge in front of your storefront, filters malicious automation before it can touch your analytics, your ad pixels, your email forms, or your origin servers, and keeps your ad spend pointed at humans.
Layer in hygiene from there: double opt-in and honeypot fields on email forms, rate limiting on cart and search endpoints, and analytics segments that exclude confirmed bot geographies so your historical reporting heals. For a full playbook, read our complete guide to stopping bot traffic on Shopify.
Frequently Asked Questions
How can I tell if traffic from Ashburn, Virginia is bots?
Check the network or ISP dimension in your analytics and the ASN in your server logs. If Ashburn sessions resolve to Amazon, Google Cloud, or other hosting providers rather than residential ISPs like Comcast or Verizon, and show near-zero engagement with no purchases, it's almost certainly automated data-center traffic, not shoppers.
Why are bots adding items to my cart but not buying?
Scrapers trigger the cart to expose data that only appears mid-funnel: live inventory, shipping rates, and discount logic. Scalper and hoarding bots rehearse checkout ahead of product drops, and card-testing bots probe the funnel before running stolen cards. None of them intend to pay, so add-to-carts climb while orders stay flat.
Do fake email signups hurt my sender reputation?
Yes. Fake addresses bounce, never engage, and can include spam traps, signals mailbox providers use to route your campaigns to spam for real subscribers too. They also inflate your ESP bill, since most platforms charge by contact count.
Does Google Analytics filter out bot traffic automatically?
Only partially. GA4 excludes known, self-declared bots on the IAB spiders list. Malicious bots running headless browsers with spoofed user agents and residential proxies don't declare themselves, so they pass straight through and appear as normal sessions.
Can a bot attack slow my website down for real customers?
Yes. Bots consume origin resources, saturate uncached routes like cart and search, and inflate bandwidth costs. Real shoppers get slower pages, and slower pages directly lower conversion rates.
Should I block all traffic from countries I don't ship to?
It's a blunt instrument. You'll cut off VPN users, travelers, and gift buyers, while serious bots reroute through residential proxies in your home market within hours. Behavior-based detection at the edge is more precise and doesn't cost you real customers.
Find Out What's Really In Your Traffic
If any of these signs look familiar (the mystery countries, the Ashburn spike, the carts that never convert, the email list growing for no reason), don't wait for the next anomaly to compound the damage. Nostra Edge Protect identifies and blocks malicious bots at the edge, before they can distort your analytics, drain your ad budget, or slow your store for the customers who actually buy. Book a demo and see exactly how much of your traffic is human, and how much better your numbers look without the bots.
