Online shopping is one of the activities most people do without much thought about security — you search for a product, find a good price, enter your card details, and wait for delivery. But safe online shopping requires more deliberate habits than most people apply. The shopping experience is optimised for conversion, not security, and the risks range from payment card fraud to phishing storefronts, counterfeit goods, and breaches from merchant systems. For a broader walkthrough, our Complete Guide to Online Security and Privacy is a good next read.
Four distinct risk categories need different defences: fraudulent websites designed to steal payment credentials, legitimate websites with poor security that expose data in breaches, legitimate marketplace sellers shipping counterfeits or nothing at all, and post-purchase privacy exposure through purchase history sales. Building automatic habits for all four takes about one careful read of this guide.
Verifying the website before you pay
Three baseline checks before entering any payment information:
- HTTPS confirmed: the padlock is present and the URL begins with https://
- Domain matches the retailer you intended to visit — not a lookalike with transposed letters, an extra word, or an unfamiliar TLD
- Contact information, physical address, and return policy are visible and verifiable — a legitimate retailer has all three
A site missing any of these is not a safe purchase destination regardless of how compelling the prices appear.
For unfamiliar retailers: run the URL through VirusTotal (virustotal.com), check the domain registration date at whois.domaintools.com (a domain registered weeks ago claiming to be an established retailer is a scam), and look for the merchant on Trustpilot or Google Reviews. Our guide on checking website safety covers the full URL inspection and reputation check process.
Counterfeit store scams — fully functional shopping websites that collect payment and ship counterfeits or nothing — are built professionally and are difficult to distinguish without deliberate checking. Prices dramatically below every other retailer for the same product, limited or no review history, and recently registered domains are the combined signals. When a price difference is significant enough to motivate using an unfamiliar retailer, the verification steps become mandatory rather than optional.
Payment methods — which to use and which to avoid
| Payment method | Protection level | Fraud liability | Best for |
| Virtual card number | Excellent | Zero — merchant never sees real card | All online purchases (ideal default) |
| Credit card | Strong | $0 under FCBA; dispute process typically successful | Established merchants, fallback option |
| PayPal / digital wallet | Strong | Shields real card from merchant; buyer protection available | Marketplaces, unknown sellers |
| Debit card | Moderate | Money removed from account during dispute resolution | Avoid for online use |
| Bank transfer / wire | Poor | No reversal once sent; recovery requires law enforcement | Never use for online shopping |
| Gift cards or cryptocurrency | None | Irreversible, untraceable, no consumer protection | Any request to pay these way is a scam |
Virtual card numbers (Privacy.com in the US; some banks offer these natively) generate merchant-specific card numbers. When a retailer’s systems are breached, the exposed number is valid only at that merchant — changing it takes 30 seconds and affects only that one merchant. Compare this to a real card breach, which affects every future transaction you would have made with that card number.
If a virtual card isn’t available: use a credit card rather than a debit card. The key difference is timing — credit card fraud disputes are resolved against the card issuer’s money, not yours, and your account balance is unaffected during the dispute process. Debit card fraud comes from your actual account balance and the resolution can take weeks.
Accounts and credentials
Use guest checkout when available. This is the single most effective habit adjustment for one-time purchases. Guest checkout completes the transaction without creating a stored account with your payment information, email address, and purchase history — no stored credential to be breached, no purchase history to be sold. Most people reflexively create accounts thinking it makes future purchases easier; reviewing how often you actually return to any given retailer reveals that most purchases are from merchants you use once or rarely. Guest checkout is the correct default.
Use unique generated passwords for every shopping account that requires creation. Retailers are breached constantly — a single reused password turns one retailer breach into access to every other site sharing that password. A password manager makes this automatic. Our guide on using a password manager covers the setup.
Use email aliases for retail account creation (SimpleLogin, AnonAddy, Apple’s Hide My Email). If the retailer sells your email address to marketing lists or is breached, only the alias is exposed — disable it and the exposure stops. Your real email address won’t accumulate across dozens of retail breach databases.
Don’t save payment methods in retailer accounts. “Save this card for future purchases” stores your payment data in the retailer’s system, creating ongoing risk from future breaches. Enter payment details fresh each time, or save only a virtual card number if you must store something.
Enable purchase notifications from your bank for any card used for online purchases — a text or email alert for every charge. Fraud discovered within minutes of the transaction is far easier to reverse than fraud discovered on a monthly statement. Review statements monthly regardless, to catch charges alerts may have missed and identify recurring subscriptions you no longer use.
Marketplace and high-value purchases
Marketplace transactions — eBay, Amazon Marketplace, Facebook Marketplace, Etsy — involve individual sellers with varying reputations, and the fraud patterns differ from retailer-site fraud. High-value items (electronics, jewellery, luxury goods) are disproportionately targeted because the potential profit from a successful scam justifies the effort.
Seller reputation is the primary trust signal. Hundreds of positive reviews across years of activity is meaningfully more trustworthy than a newly-created account or limited history. For eBay: check feedback score, percentage, and read negative feedback carefully — a pattern of “item not as described” or “seller stopped responding” is a warning. For Amazon Marketplace: “Fulfilled by Amazon” means the item ships from Amazon’s warehouse regardless of who the seller is, providing more reliable delivery and return handling.
Never complete a marketplace transaction outside the platform. A seller who asks to take the transaction to WhatsApp, email, or direct bank transfer is attempting to move the sale outside the platform’s buyer protection and payment systems. Off-platform payment solicitation is the single most reliable indicator of marketplace fraud — no legitimate seller needs to do this. The request itself is the warning. Keeping the transaction on the platform — both communication and payment — is non-negotiable for buyer protection.
For Facebook Marketplace significant purchases: pay through the platform’s checkout rather than Venmo, Zelle, or bank transfer, which offer no buyer protection for fraudulent transactions. Meeting in person for local transactions and cash payment for physical goods inspection before purchase is also a safe alternative for local marketplace buys.
Subscription purchases — the specific pitfall
Subscription services (streaming, software, meal kits, boxes) often make cancellation deliberately difficult: burying the cancel button, requiring phone calls during limited hours, or using dark patterns that make accidental renewal easy. For subscription signups: use a virtual card with a spending limit matching only the initial charge. A subscription billed monthly on a card with a $15 spending limit — matching the first month’s charge — is blocked automatically when the card limit is reached, forcing the service to contact you for a new payment method rather than auto-charging future periods. This provides clear control over which subscriptions continue without requiring active cancellation.
High-pressure sale periods — Black Friday, Prime Day
Scammers concentrate their efforts during major commercial shopping events because urgency lowers guard. Fraudulent deal aggregators, fake retailer sites running “limited time” sales, and phishing emails offering exclusive discounts all peak during these periods. The rule: if a deal seems implausibly good, navigate to the retailer’s official site directly rather than through the deal link. If the same deal doesn’t appear there, the deal link is fraudulent regardless of how compelling the price appears.
Our guide on protecting your online identity covers the complementary practices for limiting the personal data retailers collect and share after signup. For verifying specific deals during sales periods, CamelCamelCamel tracks Amazon price history — confirming whether a “sale” price is actually lower than the item’s historical pricing, or just an artificially inflated “was” price making the current price look like a discount.
Post-purchase monitoring
Safe online shopping doesn’t end when the order is placed. Monitoring catches fraud early:
- Watch for order confirmation emails you didn’t initiate — a confirmation for an order you didn’t place from a retailer where you have an account means the account is compromised. Change the password immediately, remove saved payment methods, and check for in-progress fraudulent orders.
- If a package arrives that you didn’t order: this is sometimes “brushing” — marketplace sellers sending unsolicited packages to generate fake verified reviews. Report it to the platform and the FTC. It indicates your address is in a database being used for this scheme.
- Check for new store credit accounts opened in your name — retailers sometimes open store credit during checkout, and fraudulent account opening at retail chains is a common identity theft form. A credit freeze (if you’re not actively applying for credit) prevents this entirely.
Safe online shopping habits, once automatic, require no more effort per transaction than insecure habits do — but they substantially limit both the probability and the impact of the inevitable retail security incidents that occur throughout the year regardless of which retailers you use.
Return fraud and “safe” merchant practices
Return fraud — where a merchant ships counterfeit goods, requires returns to an address that doesn’t accept them, or simply doesn’t process refunds — is a growing issue on major marketplaces as third-party seller quality control has declined. Protections for handling it:
- Pay with a credit card or PayPal when possible — both provide chargeback rights that apply when a merchant fails to deliver what was described. Bank transfers and debit cards are much harder to recover through chargebacks.
- Document receipt condition immediately for high-value items — photograph the package condition and the item before using it. This documentation supports a claim if the item is damaged or not as described.
- Keep email confirmations and order details until the return window has expired — these are your evidence in a dispute. A retailer that claims no record of your order is more easily challenged with email proof.
- Dispute charges promptly — credit card chargeback rights have time limits (60–120 days for most cards). Waiting months before disputing a fraudulent or unfulfilled order can forfeit the right to recover the charge.
The shopping safety checklist — quick reference
| Before paying | During checkout | After purchase |
| Verify HTTPS and domain match | Use virtual card or credit card | Enable purchase notifications |
| Check reviews on Trustpilot / Google | Use guest checkout if available | Watch for unexpected confirmations |
| Verify domain age for unfamiliar merchants | Use email alias for required accounts | Review statements monthly |
| Check seller reputation on marketplaces | Don’t save payment methods | Dispute charges promptly if fraudulent |
| If price seems too good: verify directly on retailer’s site | Never pay outside the marketplace platform | Cancel unused subscriptions quarterly |
These habits add roughly 30 seconds to a typical online purchase — the time to check the URL, select a virtual card or PayPal rather than the stored real card, and choose guest checkout. Against this minimal time cost is protection against the full range of online shopping fraud that affects millions of consumers each year. The habits that cost the least effort provide the most protection; the ones that cost the most (extensive manual research for every unfamiliar merchant) are reserved for the specific cases where the price or the product makes the additional diligence worthwhile.







