Fraud Prevention - Should I be doing more steps to prevent?

junipaire2009

Free Member
May 21, 2010
162
11
Hi

I currently have a woocommerce store using Paypal and Stripe for my store and basically want to limit as much as possible being stung for fraud.

To follow for fraud prevention.
1. Check that both the delivery and billing address match.

2. Treat all orders of high priced items as potential fraud and also someone ordering lots of products.

3. Many smaller transactions made with similar or the same card numbers, especially over a short duration.

4. Many transactions made with the same card but different shipping addresses, or many cards with the same shipping address.

5. Many transactions from the same IP address with different cards - this includes failed transactions (fraudsters will often attempt to use many cards, and keep trying until one succeeds).

6. Use of obviously or likely-fake information in the transaction (such as fake phone numbers or gibberish email addresses)

7. Check the address is legit and not a company that mails on parcels like mail forwarders.

8. Inconsistencies in customer details across multiple purchases, e.g. seeing the same e-mail address but a different name provided for another payment.

9. Many failed attempts by the same customer name/email address! The same customer might have many failed charge attempts, and if each failure is associated with a different credit card, any successful charge carries much greater risk for fraud.

10. Communication that doesn’t sounds quite right. Fraudsters often use a “script” and will send this to multiple sellers using common/generic phrases. If you see a phrase that appears scripted, try an Internet search by putting the short phrase in quotes.


Now I've seen some plugins and there seems to be heaps of these fraud prevention companies like maxmind, cybersource, fraudlabspro, SiftScience, Signifyd or Riskified. I think most of these are US based though.

Anyone use a 3rd party service to further help their store detect fraud before you lose out or at least limit some of the risk.

One of the interesting plugins I discovered was Vantage Point Friendly Fraud Protection For Woocommerce. They claim to take a video or each order and digital fingerprint to prove that an order was made to prevent friendly fraud.

I've also heard people mention a few times on here the 3rd man or something but I couldn't find a website, anyone know more about this service.

Cheers
 
  • Like
Reactions: Nochexman
I currently have a woocommerce store using Paypal and Stripe for my store and basically want to limit as much as possible being stung for fraud.

Hi junipaire2009, have you actually had any or much direct experience of being defrauded? What happened?
 
Upvote 0
Hi

No thankfully not but I was reading about that there's been a massive increase in fraud from ecommerce sites and criminals targeting the smaller businesses. I just wanted to see if I was doing all the checks I could be basically and seeing what other folk were doing in their battle to fight it.
 
Upvote 0
Maxmind works well, very rarely does it flag fraud that isn't. It sometimes flags fraud where IP & location checks fail, usually when someone orders from work and all their office traffic is routed through a corporate data centre abroad but in most cases a genuine client will phone - or you could phone them.

There's also https://www.fraudrecord.com/ which has an API and manual checking, great idea but reliant on data from those impacted by fraudsters.
 
Upvote 0
Cheers guys for the additional posts, really appreciate you taking time to post. I'll checkout the links and signup for a trial with Maxmind and see how it goes.
 
Upvote 0
In addition to the other excellent advice given, consider using a Payment Gateway that supports 3D Secure, that way if you are subject to a fraudulent ttx, the liability is shifted to the Card Issuer from the Merchant automatically, without having to fight a Charge back.
 
Upvote 0
In addition to the other excellent advice given, consider using a Payment Gateway that supports 3D Secure, that way if you are subject to a fraudulent ttx, the liability is shifted to the Card Issuer from the Merchant automatically, without having to fight a Charge back.
 
Upvote 0
We have a high number of fraudulent transactions even though we have our security settings set really high with SagePay. Always make sure the cv2 and address details match the card, however the fraudsters seem to have found a way around this too.

I tend to do some digging around the internet regarding the address too, there are a number of sites that show electoral details where you can link a customer to the address.

You can also ask the customer to obtain the bank authorisation code (Barclays don't seem to offer this though).

Another great way to check that they have control of the account is by refunding a small amount back to them and asking them to confirm the amount.

Fortunately we have only had a handful of chargebacks, but make sure you are always sending a high value order to the cardholders address, the CV2 number has passed and you have evidence that you asked the customer to confirm their details.

Unfortunately fraudsters know every trick in the book but if it seems too good to be true then it probably is!
 
Upvote 0

Latest Articles