

In Friends, Ross Geller famously lays out his hotel philosophy, “You have to find the line between what’s included and what’s stealing. Soap? Included. Remote control batteries? Stealing.”
Modern e-commerce promo code abuse is Ross Geller with a Wi-Fi connection.

Today’s shoppers rarely see themselves as fraudsters. They see themselves as clever - create a second Gmail address, get another $15 welcome discount, move on with your day. Find a browser extension that uncovers a forgotten coupon? Even better. Discover a Reddit thread explaining how to stack three offers? Suddenly, you’re basically doing anthropological research:
“Been feeling guilty lately, I was wondering if I’m the only one who will always create a new account before shopping where it says “create account and get 20% off on your first purchase” Am I being rude towards the system?”
As the merchant funding that 20%, you should answer with an emphatic YES. The problem is that this behavior has become remarkably easy to duplicate, and with AI- even automate.
Promo abuse is creeping into the same dangerous territory once reserved for more obvious e-commerce threats. Industry data shows 39% of merchants now point to customers learning to “game the system” as the top driver of rising abuse, with policy and promotion abuse reported by nearly 40% of businesses.
Ironically, that $15 welcome code does drive repeat business, except it’s the same bargain hunter using six burner emails to wreck your customer acquisition metrics. Then come refunds, disputes, and post-purchase headaches, with handling costs averaging $82 per dispute. What once looked like the cost of doing business is now a real margin problem.
That shift is changing how brands approach promo abuse. Static coupon blocks can catch yesterday’s tricks. The harder problem is spotting intent as shoppers get better at finding the loopholes.
In this blog, we’ll get to the root of the matter and look at how coupon abuse evolved and how a harmless discount code turned into a very expensive game of “how many times can I get away with this?”
When you picture the person draining your promo budget, you probably imagine a classic cyberthreat - hoodie pulled up, dark room with a burner laptop running through a VPN.
The reality is much gentler, and somehow, much worse. It’s a real customer, sitting in sweatpants on their couch, leaving you five or one -star reviews based on the mood, while actively picking your pocket.
And these aren't isolated cases. In one survey, nearly a third of shoppers aged 18 to 29 admitted to return fraud or policy abuse. But while casual deal-hunting makes the behavior feel socially acceptable, the more severe financial bleeding comes from a hyper-dedicated few. So, you’re fighting two fronts at once - a widespread culture that normalizes the game, and a hardcore cult of Karens doing the heavy damage.

If you’re wondering how they keep waltzing past your defenses, it’s simple - standard coupon rules are built to block strangers. These shoppers are the exact opposite. One Shopify merchant captured the tragic loop watching the same charade over and over again:
“I have a customer who has made 15 orders over the past 6 months on my store. Every time, they create a new email address and use the 10% first-order discount code I have set up (Shopify tracks customers based on email address).”
The only good thing coming out of this charade was one thrilled customer. And this fundamentally flips the threat landscape on its head. Promo abuse used to sit in the “outsider” column next to stolen credit cards and account takeovers. Today, it lives comfortably inside your customer list under a corporate-approved label - first-party misuse.
To put it in classic horror movie terms - the call is coming from inside the house.
Our merchant, who was burned 15 times, slipped something useful into parentheses: Shopify tracks customers by email address.
That aside is essentially the entire loophole, sitting in plain sight.
There is a checkbox in your dashboard that promises to limit a code to one use per customer. Since “customer” quietly means “email,” a fresh Gmail resets the count and your welcome gift is fair game all over again. You are also nowhere near alone, and the receipts go back years.
Case in point, this 2021 cry for help:
“Our client has a discount code that allows users to get 50% off a single product from a certain collection. The “Limit to one use per customer” checkbox is checked to ensure a user can only use the code once, however recently there have been 2 incidents that shouldn’t have happened.”
Even in 2026, we’re stuck in the same swamp, with several merchants pleading Shopify for phone-number validation instead:
“We created a discount code for first-time purchases with a limit of one use per customer. However, Shopify validates discount usage mainly by email, which can be easily misused by creating new email addresses. Is there any way to validate discount usage by phone number, or email + phone number, or even phone number only?”
Shopify staff keeps confirming there is no native second check, which is the nudge to go buy an app for a job the platform should have handled itself.
%20(1).jpg)
On the other hand, some merchants see the serial discounter and decide to let it ride, because the money is real. As one merchant put it:
“if he feels he is getting a win, I am still benefitting.”
The instinct is sweet. It’s also an e-commerce spin on the Stockholm syndrome, where you end up thanking a guy for picking your pocket because at least he bought a T-shirt while doing it.
And if you think losing $15 on a coupon is bad...
Those fake emails eventually bounce, trashing your domain reputation and driving your regular marketing emails straight into spam. Your customer acquisition metrics can turn into pure fiction - since five burner accounts look like five “new customers.”
Worst of all, resellers can use these codes to clear out your best inventory on the cheap, leaving real, full-price buyers facing a “Sold Out” screen. And now you’re dealing with promo abuse and reseller fraud.
At this point, your knee-jerk reaction is probably: “Fine. I’ll just tighten the screws and block anyone looking remotely suspicious.” If only it were that simple. Block too little, and you’re actively funding the exploiters. Block too aggressively, and you start slamming the door on real, paying buyers.
If you thought your shoppers were already running wild on the coupon high, AI is now pouring them another round.
Shoppers now ask ChatGPT to hunt down every working code for a store, and it happily scours the web and even guesses likely ones, landing discounts they would have paid full price to miss. The bolder ones go a step further. A 2026 how-to guide walks shoppers through pointing an AI agent at your checkout so it will open a browser and test code after code until one sticks.
Your promo box, brute-forced while the customer makes coffee.
It scales in the other direction too. The same tools that guess one code can spin up hundreds of fake shoppers wrapped in synthetic identities built to slip past static checks. The loophole you once patched one customer at a time now runs at the speed of a server.
Your legacy defenses were built for a much slower opponent. Tactics designed to block browser extensions like Honey - now hemorrhaging over 7 million users after viral exposes revealed alleged affiliate hijacking - may do nothing against ChatGPT.
Anything you post in public, AI will find, test, and hand back to the shopper at checkout. Your promotion is now up against a customer who never gets tired, never forgets a code, and never types their real name twice.

If email tweaks and basic device checks feel like putting up a “Please Don't Steal” sign, it’s because serial deal-hunters know how to step right over them. Moving beyond basic filters requires structural strategies that make abusing your store uncomfortably difficult, without turning your checkout into a TSA checkpoint.
Burner emails are free; acquiring 20 credit cards isn’t. Matching redemptions to payment card hashes or Apple Pay tokens exposes the “new customer” using the same Visa. Some anti-fraud providers have helped major delivery brands such as Deliveroo, JustEat, and KFC cut multi-account promo gaming by over 70%.
Generic codes like WELCOME10 are open invitations for Reddit threads and bots. A child can crack them. Switch to single-use codes bound strictly to a live user session. If it wasn’t issued directly to that active cart, it dies at checkout.
Email verification is easy to fake, but phone numbers carry recurrent friction. Require SMS verification for high-value promos; risk APIs easily flag cheap VoIP lines, forcing abusers to use a real mobile number.
Automatically rejecting orders flagged for minor flags (like VPNs) turns away real money. Instead, strip the suspicious discount and present a quick verification check. Bots abandon; genuine buyers have the patience of a few seconds and check out.
At its root, promo abuse stings worst when it becomes a margin problem. Patching the technical leaks keeps you safe, but the ultimate move is to stop relying solely on discounts to buy customer loyalty. Where a coupon trims your margin to score a single sale, a trust-builder like product protection does the exact opposite. You lift average order value and deepen the customer relationship in a single move- the very metrics promo abuse was quietly draining.
If you're ready to protect your profit margins and build real long-term value, let’s start a conversation.