Refusing suspicious orders

And what do you do when they don't pass all security? We still have plenty of customers that place orders without 3D-secure authentification so would you just reject them (even though the vast majority are genuine customers)? Or do you just accept them anyway without performing any other checks?

If you have 3D security on your site, why would a customer not use it (this is a genuine question by the way)?

I'm afraid you don't know what you're talking about - no such thing as a 'credit card that passes all security' exists and you have to have systems to deal with failed cards payments which are genuine.

With the greatest of respect, you know nothing about me, so to make assumptions like this is unkind and inappropriate.

In 2003, I was project manager of the implementation of a new website for a major electrical retailer, that introduced new technology (for then) such as VBV and securecode. This was for a £100m turnover business.

A credit card that passes all your security I am defining as an auth, confirmation of AVS and CVV2/CVC2 number, then whatever other security processes you may have.
 
Upvote 0
If you have 3D security on your site, why would a customer not use it (this is a genuine question by the way)?

Because some customers just HATE having to remember another login and password and there are those who are uneducated to what 3D-secure is even if you splash it all over your payment page explaining what it is people still don't read it.

When we first implemented 3D-secure we had no end of problems with people abandoning carts because they thought it was a phishing attempt even to the point where I had one customer screaming down the phone to me accusing me of trying to steal their details (even when I tried to explain to the customer what it was) - in the end we turned it off until it's use was more widespread and the actual card issuers customer services team new what it was as well (muppets were giving wrong advice to customers)
 
Upvote 0
If you have 3D security on your site, why would a customer not use it (this is a genuine question by the way)?
Some aren't registered, most probably don't even know what it is. It hasn't been very well (or at all?) communicated by the card companies to their customers so most people first experience of it is when they're in the checkout and they get asked for their securecode/verifiedforvisa password ("my what???"). Some people will sign up there and then, others seem to find it easier to hit the 'skip authentification' button than the 'join now' button.


A credit card that passes all your security I am defining as an auth, confirmation of AVS and CVV2/CVC2 number, then whatever other security processes you may have.
To be fair that's not really enough. Firstly a LOT of genuine customers order with the incorrect AVS details (delivering to their work address from their personal card), secondly that provides no security whatsoever from chargebacks. That's why many of the people on this thread add extra levels of security, such as banning free email accounts etc.

Obviously different markets have different levels of security based on their own personal experiences with fraud - some markets are more prone to fraud than others.

I recently tried to buy a (not particularly expensive) LCD screen from a major online retailer with next day delivery and they emailed me back to say I had to send them proof of my ID & address (even though I'd ordered from them before, and my card address details were correct).

Needless to say I told them to get stuffed and bought it elsewhere...
 
Upvote 0
You seem to be missing the point that a credit card can pass all security checks and still be fraud.

As I, and others, said much earlier, VbV for once is a system that can protect the merchant but not all cards from all countries are part of the scheme so you're still at risk if you accept them - and many will pass all checks but still result in a chargeback.

Repeat payments are another difficult issue - but not for public discussion.

You also need to be able to deal with false negatives which is a further risk.
 
Upvote 0
I recently tried to buy a (not particularly expensive) LCD screen from a major online retailer with next day delivery and they emailed me back to say I had to send them proof of my ID & address (even though I'd ordered from them before, and my card address details were correct).

Needless to say I told them to get stuffed and bought it elsewhere...

To be fair to the retailer the slightest difference to what you have registered with your card and what you enter can result in a AVS error.

For example my first bit of the address is Delta House, Unit 2, 264 XXXXX Road

If I enter Delta House in the address field of a website the payment will fail the AVS check, if I leave it out it then goes through fine.

If in doubt I'll phone the customer or use a combination of royal mail, 192.com or if abroad various countries own white pages websites to verify the correct address.
 
Upvote 0
As I, and others, said much earlier, VbV for once is a system that can protect the merchant but not all cards from all countries are part of the scheme so you're still at risk if you accept them - and many will pass all checks but still result in a chargeback.

I ran an experiment on VbV to see if the liability shift works. It does, the card issuer takes the hit if a crook beats 3Dsecure. . .:D
 
Upvote 0
Yes, VbV is a genuine step forward for us poor bloody merchants.

But you have to realise that criminals will tend to use non VbV cards now and if you allow non VbV cards through that pass your other tests - you're still at risk, probably more so.

Not allowing those non VbV through results in significant lost revenue. What we need is universal VbV.
 
Upvote 0
But you have to realise that criminals will tend to use non VbV cards now and if you allow non VbV cards through that pass your other tests - you're still at risk, probably more so.
But on the plus side, as more and more people sign up it means we now have more time to apply extra stringent checks to those few that don't...
 
Upvote 0
Here. Here.

Elect that man president :D

Yes a global VBV and Securcode would be great and i've no idea why visa and mastercard aren't making it mandatory for all countries.

Thirded. And I guess I can understand the commercial reasons to not mandate securecode. I just assumed that given I implemented this in 2004 that all sites nowadays would have it, and mandate it, and likewise that all consumers would use it.
 
Upvote 0
I think the law says that you are fully entitled not to go ahead with any clients order for any reason (so long as they have not paid you obviously otherwise you need to refund them) other than that its the ethics of the situation, if you take reasonable care then you should be ok if the police or worse come knocking
 
Upvote 0
i m so sorry to hear that. that sounds so bad, if customer payment by papal.maybe that is not very safe for seller, most people want to get money back but to solve problem.that is bad.
we have to be careful during online payment.
 
Upvote 0
As I, and others, said much earlier, VbV for once is a system that can protect the merchant but not all cards from all countries are part of the scheme so you're still at risk if you accept them - and many will pass all checks but still result in a chargeback.

CJD,

You are correct in this. We had a merchant yesterday who contacted us to tell us that their acquiring bank was tryign to chargeback 2 transactions were 3D secure had been attempted but the card was not enrolled. In this case the liability still shifts but the bank will try it on anyways.

In another case a merchant was doing full 3D secure on all transactions and over a period of a month took 6 figures worth of questionable transactions. We flagged it to him as most likely fraud and his response was that he did not care as liability was not with him. What he failed to realise is that the issuing bank still registers a chargeback notification with the card schemes regardless of whether the merchant ever sees it. When the chargebacks came rolling in the merchant was flagged at scheme level. Card schemes contacted his acquirer and told them to turn off his account or face fines. Merchant accounts gone in 60 seconds. Merchant also blacklisted for possible merchant side fraud.

The point is that the merchant has a duty of care to use all reasonable means to stop fraud going through their account. Turning away business because you suspect it to be fraud should be the standard operating procedure for every merchant.

Our advise is always that the merchant should use all the technological tools he can to detect fraud but at the end of the day good old common sense is your best protection. If you even marginally suspect it don't accept it or get payment another way. If your worried about taking a payment then later declining it and returning the funds the answer is simple. Get a clause in your T&C's to cover you or do a pre-auth if your processor supports it.

Hope this helps.
 
Upvote 0
As someone who is about to start selling on line it is something I never even thought about. I just assumed Google or Penpal would detect any irregularities and stop the transaction
 
Upvote 0
As someone who is about to start selling on line it is something I never even thought about. I just assumed Google or Penpal would detect any irregularities and stop the transaction

That's a very quick way of going out of business - you need to be very cautious in any form of trading; real shops have theft, on-line has credit card fraud and neither the banks nor Pay Pal are interested in protecting you from it.
 
Upvote 0

Latest Articles