• Latest

How Fraud Analysts Can Review E-commerce Transactions Accurately

September 29, 2021 - Updated On December 7, 2021
Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

February 28, 2025
Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

February 20, 2025
Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

February 18, 2025
Swap and Signifyd Partner to Empower Brands With Secure, Seamless Global Commerce

Swap and Signifyd Partner to Empower Brands With Secure, Seamless Global Commerce

February 13, 2025
Worldpay to Acquire Ravelin, a Leading AI-Native Fraud Prevention Platform

Worldpay to Acquire Ravelin, a Leading AI-Native Fraud Prevention Platform

February 12, 2025
Socure Verifies Over 2.7 Billion Identity Requests in 2024, Achieves Market-Leading Performance Amidst Increasing AI and Fraud Threats

Socure Verifies Over 2.7 Billion Identity Requests in 2024, Achieves Market-Leading Performance Amidst Increasing AI and Fraud Threats

February 10, 2025
NVISIONx Unveils Nx+RexAI: Redefining Data Security Posture Management with GenAI-Powered Contextual Classification

NVISIONx Unveils Nx+RexAI: Redefining Data Security Posture Management with GenAI-Powered Contextual Classification

February 5, 2025
AuthenticID Annual Report Reveals Surge in Identity-Based Fraud Across Businesses

AuthenticID Annual Report Reveals Surge in Identity-Based Fraud Across Businesses

February 3, 2025
N-able Furthers Open Ecoverse Vision with Launch of AI-Powered Developer Portal—Accelerating API Integrations for Faster, Seamless IT and Security Services Delivery

N-able Furthers Open Ecoverse Vision with Launch of AI-Powered Developer Portal—Accelerating API Integrations for Faster, Seamless IT and Security Services Delivery

January 30, 2025
Zest AI to Deliver First Seamless AI Application Fraud Detection for MeridianLink Clients

Zest AI to Deliver First Seamless AI Application Fraud Detection for MeridianLink Clients

January 29, 2025
Hiya Launches First AI Call Assistant That Stops Live and Deepfake Scams in Real-Time

Hiya Launches First AI Call Assistant That Stops Live and Deepfake Scams in Real-Time

January 28, 2025
Deep Instinct Expands DSX for Cloud Protection to Amazon FSx NetApp

Deep Instinct Expands DSX for Cloud Protection to Amazon FSx NetApp

January 24, 2025
  • Contribute
  • Contact Us
  • About
  • Join Us
  • Advertise
Sunday, June 22, 2025
Merchant Fraud Journal
ADVERTISEMENT
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
  • Home
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Resources
    • Recorded Webinars
    • Podcasts
    • Vendor Directory
    • eCommerce Fraud Reports
    • Training and Certifications
    • Jobs Board
    • Associations and Non-Profits
  • News
No Result
View All Result
Merchant Fraud Journal
No Result
View All Result

How Fraud Analysts Can Review E-commerce Transactions Accurately

This article is part 2 in a series by ex-fraudster Alex Hall, centered around the migration to e-commerce that many merchants employed during 2020 and into 2021.

In my last article, I covered a 4-step strategy development process that will serve to provide merchants with a high-level overview of what an effective strategy entails. The four steps (Identify, monitor, automate, and repeat) can assist companies of all shapes and sizes, and If executed correctly, this process will ultimately mitigate and prevent countless losses incurred by fraud.

This article will cover the first aspect of a merchant’s operation that is most heavily affected by a shift to e-commerce, and drill down on some actionable suggestions that you can employ immediately after reading.

It’s the forms, stupid.

Does your website accept cash? Does your website swipe cards with a Point of Sale terminal? The answer is no. When handling physical forms of payment, it is relatively easy to identify counterfeits and refuse the transaction. When accepting payments online, the checkout system is comprised of a series of forms. Forms that anyone can fill out with any information. Authentic, stolen, accurate, inaccurate, and so on. In pursuit of fraud prevention, it is vital that merchants first understand the data being submitted at various touch-points, and second, understand and employ verification processes.

We will dive into verification processes further in the article. For now, let’s focus on credit card payment information, how a system is exploited by fraudsters and what you can do about it.

Credit Card Payment Information:

We are familiar with online checkout forms, but do we know what is going on behind the scenes? Fraudsters do. They know because they experiment with sets of information of varying degrees of accuracy during the checkout process. Payment information is obtained through various tactics and includes things like billing name, account number, CVV, billing zip, expiration date, and billing address.

When attempting a transaction on a website, some of the questions they seek to answer are: Does this form require CVV? Does this form require billing address / billing zip? Does this form allow me to designate a secondary shipping address? In-Store / curbside pickup? Telephone orders? etc. The information that is required on checkout forms is thoroughly analyzed by fraudsters seeking to author new methods. Next, we can cover how this contributes to a fraudster’s operation.

How a System is Exploited by Fraudsters:

When I was operating a fraudster, I called this method of discovery “Checklist Building”, and those were the types of questions I sought answers to. The process was simple enough as there was a mountain of information to experiment with. The results of my “research” painted a picture that holds true to this day. That Everyone is vulnerable at some level. By filling in the required fields on a checkout and monitoring the fulfillment, it would become clear what information was being verified on the back end and what level of payment information was required in order to have a successful transaction.

What You Can Do About It

When conducting in-house manual transaction analysis, it is crucial to understand what these data points indicate, how they are determined, and how your system handles different events.

When using a bare-bones e-commerce platform (such as Shopify) and  a payment gateway (like Authorize.net), you should be able to identify about 7 data-points to make accurate determinations. Below I have outlined what the data points are and how they are verified.

1. Card Number – Verified

On it’s own, a card number is deemed ‘verified’ if the number fits the MOD10 / Modulus 10 / Luhn’s Alogorythm.  

2. Expiration Date – Verified

Past / Future

3. CVV – Verified

The code indicates whether or not the entered CVV matches what is on file with the issuer.

4. Cardholder Account Name – Not verified

When dealing with an out-of-the-box platform the billing name can be anything, and the order will move forward.

5. Billing Address – Verified

Using the Address Verification Service (AVS), the 3 numerical values (Street number, Zip Code, and zip + 4 ) are verified with the issuing bank. The response code indicates the accuracy of the information submitted as it relates to the information on file with the issuer. The AVS response code can also indicate whether the registered billing address is foreign, unregistered, and more.

6. Shipping Address – Not Verified

There is no mechanism that verifies shipping addresses with the issuing bank.

7. Historical data – Not Verified

Although not verified by an issuer, historical data is very useful for making accurate determinations for accounts that have transactions that appear suspicious at first glance. By escalating suspicious orders to a secondary verification process, you can begin to white-list a number of customers.

After reading this list, you should have a decent idea regarding your current checkout form and the verification process behind it. It is important to note that, among these 7 data points, there are actionable relationships that can assist you with your transaction analysis.

For example, although the shipping address is not verified by the issuer, the billing address is. If the billing address is verified with a code X (Meaning that the 3 numerical values are 100% accurate) and the shipping address matches the billing, you could say that the package is to be sent to the verified billing address. Success! Adversely, if the billing address is verified, but the shipping address doesn’t match, you should understand that the package is to be sent to an unverified address.


This article has been contributed by Alex Hall, a former fraudster who spent ten years successfully operating in the Las Vegas fraud scene. Today, he is the Principal at Dispute Defense Consulting, a Full-Spectrum Fraud Mitigation Consulting agency, with an aim to assist merchants to build a comprehensive defense against fraud throughout many aspects of their system.

Tags: BOPISCVV
TweetShareSend
Previous Post

Signifyd Partners With Capital One to Deliver Leading-Edge Fraud Protection and Drive Ecommerce Revenue to New Heights

Next Post

Merchant Fraud Journal Webinar – How Automating Trust Can Help You Stop Fraud

Next Post

Merchant Fraud Journal Webinar - How Automating Trust Can Help You Stop Fraud

Download our latest report:

Our Latest Reports

2024 Fraud Trends Report

2023 Consumer Payments Survey Report

2023 Fraud Trends Report

2022 Chargeback Consumer Survey Report

Fraud Prevention Tactics that Enable Exceptional Customer Experience

Addressing Payment Fraud and The Customer Experience in 2022

2022 Fraud Trends Report

ATO Fraud In Retail Report

2022 Customer Experience Report

3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue

Digital Trust And Safety Report: Combating the Evolving Complexities of Payment Fraud

On-Demand Webinars

New Trends in The Payments Ecosystem

Balancing Customer Experience and Fraud Prevention: What’s the Secret?

Stopping Fraud Across the Customer Lifecycle

Addressing Payment Fraud and the Customer Experience in 2022

 

Featured Directory Listings

  • Signifyd
  • TransUnion
  • PayRetailers
  • Spotrisk
  • CB-ALERT
  • Chargeflow
  • Corepay
  • AtData

Get the 2024 Fraud Trends Report

Search Our Site

No Result
View All Result

Our Sponsors

Fraud Industry News

Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

Veeam Releases Kasten for Kubernetes v7.5, Elevating its #1 Data Resilience Market Position with Enhanced Security and Modern Virtualization

February 28, 2025
Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

Major Milestone for PDX Beam as Crypto-to-Fiat App Is Now Available in Apple App Store and Google Play

February 20, 2025
Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

Sardine AI Raises $70M to Make Fraud and Compliance Teams More Productive

February 18, 2025

Connect With Us

Quick Navigation

  • Home
  • News
  • Join Us
  • About Us
  • Contact Us
  • Advertise
  • Contribute
  • Privacy Policy

The Payments Media Network

Merchant Fraud Journal
Payments Review

Privacy Policy

Our Privacy Policy
Our Terms of Use

Resources

  • Articles
  • eCommerce Fraud Reports
  • eCommerce Fraud Webinars
  • Training and Certifications
  • Jobs Board
  • Associations and Non-Profits
  • Podcasts
  • Vendor Directory

Popular Posts

  • What Is a Chargeback: A Primer for Merchants

    What Is a Chargeback: A Primer for Merchants

    0 shares
    Share 0 Tweet 0
  • How Does Two-Factor Authentication (2FA) Work?

    0 shares
    Share 0 Tweet 0
  • Understanding “Close Case – No Issuer Response” and Its Importance

    0 shares
    Share 0 Tweet 0
  • Twitch Chargebacks for Streamers: Prevention and Recovery Opportunities

    0 shares
    Share 0 Tweet 0

Featured Vendors

  • Signifyd
  • TransUnion
  • PayRetailers
  • Spotrisk
  • CB-ALERT
  • Chargeflow
  • Corepay
  • AtData

Download the 2023 Fraud Trends Report

No Result
View All Result
  • About Merchant Fraud Journal
    • Interested in Contributing or Guest Posting to Merchant Fraud Journal?
    • Merchant Fraud Journal Editorial Guidelines
  • Advertise on Merchant Fraud Journal
  • Articles
    • Chargebacks
    • Fraud Prevention
    • Influencer Insights
  • Contact Us
  • Download Addressing Payment Fraud and Customer Experience Report
  • Download Chargebacks Consumer Survey Report 2022
  • Download Evolving Complexities of Payment Fraud Report
  • Download Fraud Prevention Tactics that Enable Exceptional Customer Experiences Report
  • Download Merchant Fraud Journal 2023 Fraud Trends Report
  • Download Merchant Fraud Journal 2024 Fraud Trends Report
  • Download Merchant Fraud Journal Generative AI Fraud Prevention Checklist for SMBs
  • Download Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
  • Download the 2020 Chargeback and Representment Report
  • Download the 2020 Merchant Fraud Journal Vendor Guide
  • Download the 2021 Fraud Trends Report
  • Download the 2022 Fraud Trends Report
  • Download the 2023 Consumer Payment Trends Report
  • Download the 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue Report
  • Download the MFJ 2022 Customer Experience Report
  • Download the MFJ ATO in Retail Report
  • Home
  • Home Elementor
  • Job Dashboard
  • Join The Merchant Fraud Journal Community
  • Merchant Fraud Journal Advertising Agreement
  • Merchant Fraud Journal Advertising Agreement – Signifyd
  • MFJ Fraud Trends Report Giveaway
  • News
  • Post a Job
  • Privacy Policy
  • Resources
    • #9978 (no title)
    • 2020 Chargeback Representment Guide for Merchants
    • 2020 Vendor Guide
    • 2023 Consumer Payments Survey Report
    • 3 Ways a Unified Chargeback Management and Fraud Platform Increases Revenue
    • Addressing Payment Fraud and the Customer Experience in 2022
    • Associations and Non-Profits
    • ATO Fraud In Retail Report
    • Balancing Customer Experience and Fraud Prevention: What’s the Secret?
    • Chargebacks Consumer Survey Report 2022
    • Digital Trust & Safety: Combating the Evolving Complexities of Payment Fraud
    • eCommerce Fraud Reports
    • eCommerce Fraud Webinars
    • Fraud Prevention Tactics that Enable Exceptional Customer Experiences
    • Fraud Prevention Training and Certifications
    • How to Build a Recession Proof Chargeback Prevention Strategy
    • How to Reduce Customer Friction During Holiday Sales Season
    • How to Stop Fraud During the 2022 Holiday Season
    • Jobs Board
    • Merchant Fraud Journal 2023 Fraud Trends Report
    • Merchant Fraud Journal’s Fraud Trends 2020 Report
    • Merchant Fraud Journal’s Generative AI Fraud Prevention Report: A Checklist for SMB Companies
    • Merchant Fraud Journal’s Fraud Trends 2021 Report
    • Merchant Fraud Journal’s Fraud Trends 2022 Report
    • MFJ’s 2022 Customer Experience Report
    • Podcasts
    • Prevent High-Velocity Fraud Attacks During the 2021 Holiday Season
    • Quantifying the Challenge of Friendly Fraud: Your Post-purchase Strategy for the Future
    • Stopping Fraud Across the Customer Lifecycle
    • The surprisingly easy way to secure your payment data, reduce your risk, and win the war on ecommerce fraud
    • Vendor Directory
    • Webinar – Addressing Payment Fraud and the Customer Experience in 2022
    • Webinar – Mitigating Fraud and Risk on the ACH Network
    • Win January Chargeback Disputes
  • Subscribed
  • Terms and Conditions

© 2021 Payments Media Solutions Canada Inc.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?