You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Linked to known fraud. A new order is tied to an order already marked fraud in the last 30 days (Detection Rules > Linked to Known Fraud, look-back configurable, on by default) when the two share the billing email, the ship-to street and postcode, or the customer IP within an hour of each other. Catches the retry with a second card or gateway after a Radar block, and the reshipping pattern where a new name and card ship to the same address, neither of which a gateway verdict ties together.
On a failed order any fraud order can be the link, a Stripe verdict included. On a paid order only the plugin's own detections and manual marks count, never a Stripe verdict, so a real customer Radar blocked who then pays another way keeps the sale.
Customer-facing paths only (classic checkout and Store API). Orders marked by this rule alone are not reported to AbuseIPDB. The order note names the earlier order and what was shared.
WCAF_Order_Status::recent_fraud_anchors(): one query for recent fraud orders and their compared fields, on the posts store or the HPOS tables.