# Ongoing carding / fake checkout attempts from PH & TW — best way to block at Kinsta level?  Body:

**URL:** <https://community.kinsta.com/t/ongoing-carding-fake-checkout-attempts-from-ph-tw-best-way-to-block-at-kinsta-level-body/6153>\
**Category:** Community Guides\
**Created:** [April 24, 2026, 1:57pm UTC](https://community.kinsta.com/t/ongoing-carding-fake-checkout-attempts-from-ph-tw-best-way-to-block-at-kinsta-level-body/6153 "2026-04-24T13:57:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Edouard\_Rozan](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/edouard_rozan/32/5533_2.png) [@Edouard\_Rozan](https://community.kinsta.com/u/Edouard_Rozan)\
**Post date:** [April 24, 2026, 1:57pm UTC](https://community.kinsta.com/t/ongoing-carding-fake-checkout-attempts-from-ph-tw-best-way-to-block-at-kinsta-level-body/6153/1 "2026-04-24T13:57:41Z")

</div>

Hi all,

We’re running a WooCommerce + Stripe store ([lepure.com](http://lepure.com)) on Kinsta and for the past several days we’ve been hit with a continuous wave of failed checkout attempts / manual card testing. Traffic is overwhelmingly from **Philippines** and **Taiwan** IPs — no legitimate customers in those regions, so blanket blocking is fine for us.

What we’ve tried so far:

- Opened a chat with Kinsta support asking to block those ranges — either wasn’t applied or didn’t stick.

- Manually added offending IPs to the **IP Deny** list in MyKinsta — attempts keep coming from fresh IPs in the same countries, so it’s a whack-a-mole.

What I’d like to hear from the community:

1. Has anyone managed to set up **country-level geoblocking (PH / TW)** cleanly on Kinsta? Is the Kinsta firewall the right layer, or is everyone doing this via **Cloudflare in front**?

2. For **carding specifically on** `/checkout` and `/?wc-ajax=checkout`, what’s working best — Cloudflare WAF managed rules, rate limiting, bot fight mode, a WooCommerce plugin, or a combination?

3. Anyone blocking **VPN / datacenter ASNs** as well? Which ASN list / approach has been low-false-positive for you?

Goal is to stop this at the edge so it never hits PHP/Woo/Stripe. Any concrete rules, screenshots, or setups you’re happy with would be hugely appreciated.

Thanks!

---

<div class="post-metadata">

**Author:** ![VladimirM](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/vladimirm/32/2786_2.png) [@VladimirM](https://community.kinsta.com/u/VladimirM)\
**Post date:** [April 24, 2026, 2:00pm UTC](https://community.kinsta.com/t/ongoing-carding-fake-checkout-attempts-from-ph-tw-best-way-to-block-at-kinsta-level-body/6153/2 "2026-04-24T14:00:11Z")

</div>

Hello @Edouard_Rozan 👋

I’m sorry to hear that you’ve had a recurring issue with failed checkout attempts.

Those are usually the fault of a plugin vulnerability (for example like Woocommerce PayPal Payments)

Woocommerce advises Captcha: [Fraud prevention Documentation - WooCommerce](https://woocommerce.com/document/woocommerce-paypal-payments/fraud-and-disputes/)

Also, I advise you to come back to a chat and our engineers will take a look.

Kind regards!
