How do you combat fraud on your website?

frankyjo

Registered Member
Joined
Oct 3, 2023
Messages
87
Reaction score
32
Do you have any experience dealing with carders on online store websites?

My payment gateway believes that I am solely responsible for this and must also pay huge fines.

What decisions did you make?
 
Do you have any experience dealing with carders on online store websites?

My payment gateway believes that I am solely responsible for this and must also pay huge fines.

What decisions did you make?
If you have enough evidence, you can win the dispute.

Also create rules
If the card location and the payment location are different, the card will be declined.
 
That is interesting what payment processor do you use to give you huge fines/fee?
 
The law of the country your payment processor operates from will determine a lot here. However, the general principle of common law is that data processor and data controllers are responsible for ensuring the protection and security against cyber attacks on their platforms.

If you don’t mind i can help you look over the terms of service or other relevant legal docs between you both.
 
Do you have any experience dealing with carders on online store websites?

My payment gateway believes that I am solely responsible for this and must also pay huge fines.

What decisions did you make?
Your gateway dumps liability on you cuz they just move risk off their books, classic play. Best move is fraud stack: device fingerprinting, velocity filters, manual review on sketchy orders. Suggestion tag high-risk BIN ranges (prepaid cards, foreign banks) and auto decline, saves chargeback hell.
 
For high-ticket items, I always call or email to verify, most carders won’t bother with a phone call.
 
Do you have any experience dealing with carders on online store websites?

My payment gateway believes that I am solely responsible for this and must also pay huge fines.

What decisions did you make?
Oh brother.

I was for a long time in high risk business niches, you need a multi layered defense approach. This will be complicated.

Nowadays I consult for onboarding, integrations and implementations of gateways and.....the one thing noone wants to hear about until it hits them like in your case, traffic monitoring.

Really, nobody wants to hear about monitoring and the interventions needed everyone wants their gateways just up and running.

Fraud monitoring is not a second thought and "will do later" things. If you get hit with chargebacks from stolen cards the penalties are brutal for everyone involved.

Let me guess your rolling reserve was blocked, funds pending payout withheld , 50k plus fine etcetc.

The payment gateway is most likely right on this, nobody wants to take responsibility, though.

This can't be explained in 5 minutes. Banks and such didn't come up with their various lines of defence in 5 minutes or a forum post.

There's also more data needed.

You must build your gateways being prepared for the worst hoping for the best.
The card fraudsters have business cards with many thousand usd balance at their disposal and they're looking for one single window of opportunity and then they will smash your network. That's how it works, I've managed to find some of them, their real names and addresses and telegrams etc. I kindly told them what I'll do if they don't stop(there's ways to get back at them which they won't appreciate) and then we had casual chats about how they do it and such.
To a degree these are sophisticated networks, not dumb people. Think about it, they can't make many mistakes or it's straight to jail.

If you wanna keep processing, maybe you write about your business model and tx reporting here or via pm if the information is too delicate. And then I'll see what can be done or improved
 
Your gateway dumps liability on you cuz they just move risk off their books, classic play. Best move is fraud stack: device fingerprinting, velocity filters, manual review on sketchy orders. Suggestion tag high-risk BIN ranges (prepaid cards, foreign banks) and auto decline, saves chargeback hell.
This guy has been in the business I can tell. There's more to that but I wouldn't give away all the info myself here unless the op was my merchant
 
Your gateway dumps liability on you cuz they just move risk off their books, classic play. Best move is fraud stack: device fingerprinting, velocity filters, manual review on sketchy orders. Suggestion tag high-risk BIN ranges (prepaid cards, foreign banks) and auto decline, saves chargeback hell.
This guy has been in the business I can tell. There's more to that but I wouldn't give away all the info myself here unless the op was my merchant

If you have enough evidence, you can win the dispute.

Also create rules
If the card location and the payment location are different, the card will be declined.
Okay folks, don't listen to such advise.

All due respect to the guy I've quoted, this is not how it works. If it's a high risk processing env you're not disputing any one thing.

Card location and payment location what does that even mean?

Such transaction would be rejected from upstream, at least they should.

There's way more rules you need. You need to sort by countries and by card issuing countries.

Do you wanna block every revolut payment because the bin points to Lithuania? Hellno
 
If you have enough evidence, you can win the dispute.

Also create rules
If the card location and the payment location are different, the card will be declined.
Okay folks, don't listen to such advise.

All due respect to the guy I've quoted, this is not how it works. If it's a high risk processing env you're not disputing any one thing.

Card location and payment location what does that even mean?

Such transaction would be rejected from upstream, at least they should.

There's way more rules you need. You need to sort by countries and by card issuing countries.

Do you wanna block every revolut payment because the bin points to Lithuania? Hellno
 
Do you have any experience dealing with carders on online store websites?

My payment gateway believes that I am solely responsible for this and must also pay huge fines.

What decisions did you make?
Try using security plugins or programs. Be clear about legal terms on your site. Also, make sure to use trusted payment processors.
 
So any processor will impose penalties on the store? That's strange, of course. After all, they charge commissions for processing transactions and also specify a risk percentage. Which has no effect whatsoever!
 
So any processor will impose penalties on the store? That's strange, of course. After all, they charge commissions for processing transactions and also specify a risk percentage. Which has no effect whatsoever!
Yes, some payment processors can impose fines or hold the merchant liable if fraudulent activity (like carding) occurs, even though they charge commissions and factor in risk. This is because the merchant is legally responsible for verifying transactions and preventing fraud. Commissions cover processing, not losses from chargebacks or fraud. So it’s not unusual that’s why using security tools, fraud filters, and clear legal terms is essential to protect yourself.
 
Yes, some payment processors can impose fines or hold the merchant liable if fraudulent activity (like carding) occurs, even though they charge commissions and factor in risk. This is because the merchant is legally responsible for verifying transactions and preventing fraud. Commissions cover processing, not losses from chargebacks or fraud. So it’s not unusual that’s why using security tools, fraud filters, and clear legal terms is essential to protect yourself.
thank)
 
That's a tough spot, I've seen it. First, max out all the fraud protection features your payment gateway offers – AVS, CVV, 3D Secure. If they're not enough, look into a specialized third-party fraud detection service. Also, build a strict review process for suspicious orders: mismatched addresses, high-value first-time buys, or odd IP locations. It's proactive work, but it saves you big fines down the line.
 
Back
Top