65% of One Store's Traffic Was a Single Scraper
A Shopify store took 33,700 visits in 22 hours. 21,840 came from one datacenter network. Here is how to find the same pattern in your own logs.
On this page
TL;DR: A jewelry store on Shopify took 33,700 visits in its first 22 hours with Cordon installed. 21,840 of them, about 65%, came from a single datacenter network running at a flat 1,200 to 1,500 requests an hour, day and night. The merchant had no way to see this, because Shopify Analytics reports country and not network. The bandwidth was the least of the damage: every number she was making decisions on was contaminated. Here is the full breakdown and how to check your own store.
Most articles about bot traffic argue from principle. This one is a single store's logs over 22 hours, with the numbers as they were recorded. The store is a jewelry brand on Shopify and is not named here at their request. Everything else is exactly as it happened.
The numbers
Cordon was installed on a Saturday evening. This is what the first 22 hours looked like.
| Measure | Value |
|---|---|
| Total visits, first 22 hours | 33,700 |
| From AS45102 (Alibaba Cloud, geolocating to Singapore) | 21,840 |
| Share of all traffic from that one network | ~65% |
| Request rate from that network | 1,200 to 1,500 per hour |
| Pattern | Flat across all 24 hours, no overnight drop |
| Blocked by Cordon | ~22,300 |
Behind the leader there was a tail from HostRoyale, M247, Vultr and EGIHosting. Every one of those is a hosting provider. Nobody shops for jewelry from a rented server.
The pattern is the proof
A single large number is not evidence of automation on its own. A viral post or a press mention can produce a traffic spike from one region. What makes this unambiguous is the shape.
Human traffic breathes. It rises when your main markets wake up, peaks in the evening, and falls to a trickle overnight. Even a global audience produces a visible rhythm, because the world does not shop uniformly around the clock.
This traffic did not breathe. It ran at 1,200 to 1,500 requests an hour at 04:00 and at 14:00, through the night, without gaps. That is not an audience. That is a scheduled job, and once you have seen the flat line you never mistake it for anything else.
This is the single most useful thing to check in your own logs. Before you look at countries, user agents, or anything else, look at the hourly distribution. If it is flat, you are looking at automation, and the only remaining question is which network it comes from.
Why the merchant could not see any of this
Here is the part that matters most, and it is not really about scraping.
Shopify Analytics reports sessions and countries. It does not report the network a request came from. So those 21,840 requests appeared in her dashboard as ordinary traffic from Singapore, mixed in with real people. There was no anomaly to notice, no warning, nothing out of place. The traffic looked like growth.
The country column is the trap. A request from an Alibaba Cloud server in Singapore and a request from a person in Singapore both report as Singapore. A request from an AWS instance in Ohio and a request from a shopper in Ohio both report as the United States. Country tells you where a packet claims to come from. It tells you nothing about whether a human is attached to it.
What separates them is the ASN, the autonomous system number, which identifies the network operator. AS45102 is a cloud hosting network. AS7922 is Comcast. The first carries servers, the second carries people. That distinction is available on every single request, and it is not surfaced anywhere in the Shopify admin.
If you want one takeaway from this post: country is a weak signal and network is a strong one.
What it actually cost her
The bandwidth is the boring part. Shopify absorbs the hosting and the store did not go down.
The real cost was that every number she was working from was wrong.
Her conversion rate was understated by roughly a factor of three. Conversion is orders divided by sessions. With 65% of sessions belonging to a bot that never buys anything, the denominator was inflated and the rate she saw was a fraction of her true rate. A merchant looking at that number could reasonably conclude her product pages were failing and start redesigning something that was working fine.
Her channel reporting was contaminated. Traffic attributed to a region she does not sell into much, at volume, distorts any read on which markets are worth investing in.
Her growth signal was fake. Traffic went up. Nothing about the business had changed.
This is why bot traffic is worth caring about even when your store stays up. It is not a performance problem. It is a measurement problem, and measurement problems cause bad decisions quietly for months.
Why ASN blocking and not IP blocking
The instinct when you find a bad IP is to block that IP. Against this kind of source, that is a losing game.
A scraper running on rented infrastructure can change IP address whenever it wants. Blocking addresses one at a time is a list you maintain forever and never finish, and every hour you spend on it the scraper spends nothing. You are the only one paying.
The ASN is the network it rents from. One rule at that level ends the entire source at once, and it keeps working when the individual addresses rotate. It is the difference between swatting individual wasps and closing the window.
The caveat that matters: a datacenter list has to be curated, not automatic. Hosting networks carry servers. But CDN networks like Cloudflare, Fastly and Akamai carry iCloud Private Relay traffic, which means real iPhone shoppers exit through them. A naive "block all non-residential networks" rule turns away genuine customers, which is the most expensive mistake available in this category. Cordon's datacenter list deliberately excludes CDN networks for exactly this reason.
How to check your own store
You do not need to buy anything to do the first two steps.
- Look at the hourly shape of your traffic. Any analytics tool will show you this. If your traffic is as busy at 04:00 as at 14:00, something automated is running.
- Look for round-the-clock consistency. Real audiences have weekends, holidays, and quiet Tuesdays. Automation does not.
- Get the ASN. This is the step Shopify does not give you. You need a tool that resolves each visitor IP to its network operator and shows you the breakdown. Cordon's free plan does this, and seeing your own numbers is the point of it. Most merchants have never looked at their traffic this way.
- Block at the network, not the address, once you know what you are looking at.
The ending, told straight
This part does not flatter us, and leaving it out would make the rest less honest.
While the store was on a paid plan, Cordon blocked around 22,300 of those requests. It worked exactly as intended.
Nineteen hours later she moved to the free plan. The free plan does not include datacenter and proxy detection, so the blocking switched off and the block count went to zero from 15:00 onward. The scraper carried on at the same rate, unchallenged.
That is a failure of communication, not of detection. She had no way to weigh what she was giving up, because the value was invisible by exactly the same mechanism that made the original problem invisible: nothing showed her the ASN breakdown at the moment she was deciding.
It is also worth saying that the plan she left was more than she needed. At her volume, Growth at $19 restores proxy and datacenter detection and its limit covers this traffic comfortably. Recommending the more expensive plan would have been the easier sentence to write and the wrong one.
The lesson we took from it: showing a merchant their own traffic honestly is not a marketing exercise, it is the product. If you cannot see what is hitting your store, you cannot make a good decision about it, and neither the problem nor the fix will ever feel real.