I never thought of that before. Maybe there should be a central shared central repository of who are known good customers/address/cc combinations, or maybe that is what stripe etc do already.
I never thought of that before. Maybe there should be a central shared central repository of who are known good customers/address/cc combinations, or maybe that is what stripe etc do already.
In our case we often do something similar to this:
---
No order is rejected outright - but various combinations of criteria cause a manual review of the order. This prevents customers getting error messages and also avoids having fraudsters receive quick feedback.
Shipping addresses known to be forwarding mail centers or mailboxes are flagged.
If the billing address does not match the shipping address, and the IP is flagged as proxy/vpn/datacenter, etc. or is too far from the billing/shipping address, it is flagged. This allows most people to ship to their office even though the credit card is at their home address, etc.
If the billing address is to far from the shipping address it is flagged. Fraudster are limited to using cards that have billing addresses in a close range to where they can receive goods.
The machine learning system gives a score and various thresholds of that score are used to trigger in combination with other factors.
Flagged items are manually reviewed. Sometimes customers are called to do human verification.
---
Some still get through, but I just implemented one a few weeks ago and saw 99% reduction in fraud orders, and a 90% reduction in man-hours for reviewing orders. In most cases, the fraudsters will just see that it is no longer worth their time and move on to easier targets. Obviously this particular store had a serious problem due to a high level of automation and an easily resalable product. The margin of the product and relatively low shipping costs allowed the fraud to get to pretty high levels before they really focused on it.
TLDR: don’t be last, second to last is still OK. I guess.
They have databases of "known addresses" so if your order doesn't match, it can be hard.
(They keep the old addresses too, as an attempt to get UPS automated phone center to hold for pickup one time ended up with them shipping the clothes to an 8 year address of mine in a adjacent state. )
It should he an issue for you. That is because PayPal is stopping a lot of payments with false positives. I live outside US and using PayPal is generally a pain in the ass.
If it's true I'd expect that we'd get alot more complaints from customers that their cards are being rejected.
In particular, credit card setings are multi-step and all done on the paypal site, I wouldn’t imagine going back to some merchant site to complain about that process.
In the absence of any hard data on this, I'm writing it off as nectodal.
The Internet is full of this stories from people with good karma. Just look for it on Internet. Probably you are from one of the few countries where the experience is different.
Obvious freight forwarder + foreign IP + local US credit card with the wrong billing address...doesn't raise any suspicions from them.
There is always a defcon pwn
The banks still advise customers to inform them when travelling, but I've not found that to be necessary when in countries with chip and PIN. (If I'm going outside Europe I will inform the bank of my main card, but in South America, Asia, Africa there will be some point where it isn't accepted, and I use a backup card -- that bank doesn't know I'm travelling.)
The USA used to be the problem -- about once a year, someone in the office would get a robot phone call from the bank saying their card had just been blocked due to suspect activity in the USA. That should be becoming a lot less common.
The ide behind chip is that transaction result is written back to your card, something mag stripe cannot do. I had a family related fraud where my son used my card in store to buy few video games. Over the phone amex told me to go to the bank which was able to show me this card has been swiped physically in the store because confirmation hashes were written on the chip of my card.
I was explained up to 16777264 transaction hashes can be written on one chip before overwrite process starts.
So at this point you wont get your loeny back if you have your card present but claim someone made copy because they will simply pull data off the card.
Side issue Europe switched to touch credit cards some 3 years ago. Its insane fast yoy dont even touch reader you just wand your card transaction approved. You will need another 5-8 years to wait for that in usa tho.
I was visiting Philippines recently, and wasn't able to withdraw cash - the ATMs (I've tried different banks' ones) were rejecting me with a generic error message. So I've contacted my bank to check what's wrong and if they're blocking me for any reason. Turned out that they haven't seen any transaction attempts at all - like something along the path wasn't working (no clue, really). The suggested method of trying an ATM in a different part of the city worked.
I've also had issues with some payments via PoS terminals. Normally, when payment fails I get a push notification about the failure - but none happened at those times. So, I guess, this could be similar.
Back in the day, eBay had ludicrously good fraud rates (and hundreds of engineers working on models, from what I heard). We hired a few people from them and were quite proud to achieve rates in the same ballpark with orders of magnitude less traffic.
Could a Blockchain/DHT solution work for this? Normalize and hash the data and send it to the network to check its karma. If there's no karma then it's a new customer, otherwise the karma tells if it's a good/bad customer. Then after they buy you add or reduce a karma point.
Would there be a way for someone to reverse/bruteforce the hashes to figure out people information?
Use existence in the DB (weighted by number of instances) as a probability of not-fraud.
My guess is Shopify, Stripe, etc are doing something like that when they send "this might be fraud, you should review" alerts.