Nothing is certain, except death and taxes .. and chargebacks
blog.balancedpayments.com
blog.balancedpayments.com
Anyways, contacting the customer can usually get things resolved as well, even if they went straight for the chargeback.
Never underestimate human contact. You might be surprised why they went with a chargeback. Some just thing it's the way to get a refund for something that was wrong. Yes, sometimes the person is just being a douche, in which case you can assure the person that you thank them for reporting the case, and that you will be following up by filing a police report. When they realize what information you have available, some are quick to want to work something out, usually that involves calling the bank in a 3 way conference call and canceling the charge back.
It won't always work, but the nature of chargebacks means every little bit helps.
Again, this also depends on the nature of the industry you are in.
3DS, while effective, is not a bullet proof solution. Requiring 3DS transactions will impact sales, and can impact them enough that it's better to not use it. I always recommended a scoring approach (reach a certain threshold, and we require 3DS).
Even still 3DS only affects the initial transaction. Any recurring payment won't benefit from the 3DS transactions. There are ways to encourage 3DS use (discounted membership fees if one performs a 3DS transaction), but outside of games like that, 3DS only affects the transaction it's made with.
Our policy, as much as possible, is to defers to that company with regards to customer contact because we don't want to interfere with that customer relationship/experience. We support their customer support, we don't supplant it.
The best option today if you don't want chargebacks is adopting Bitcoin for payments (like how Reddit did for Reddit Gold with Coinbase).
http://blog.coinbase.com/post/40131065845/hosted-payment-pag...
In theory, a bitcoin exchange should have a near-perfect defense against chargebacks for faulty or missing products or similar, by showing via the public block chain that they delivered the purchased product as requested. However, there's no defense against chargebacks claiming that the cardholder didn't make the purchase (stolen card number, etc).
Bank wire transfers, though, are unable to be reversed. Its a pity that most US banks charge for them.
1) They have to explain to the credit card chargeback authority what a bitcoin is and why the entry in the block chain means they actually sent the coins.
2) Nothing to stop the Bitcoin buyer from just saying "I didn't do it" (Which is 'friendly fraud' in the article).
From my experience, reversing a chargeback is only possible in a minimum of cases when sending physical items, and even harder for digital goods that you can't just send again (Bitcoins vs an Ebook).
My personal views are my own and NOT Balanced on this topic. I agree, I think bitcoin is a great solution -- for some things. More and more I feel that it's the right strategy going forward.
We actually have an open github issue to support it: https://github.com/balanced/balanced-api/issues/204. You should take a look and read the comments there -- they're very interesting.
Something I'm trying to figure out though is something along the lines of this comment: https://github.com/balanced/balanced-api/issues/204#issuecom.... How can we tackle on risk in a reasonable way?
Jon Matonis, CEO of Hushmail, wrote a pretty interesting article on Bitcoin for Forbes, where he mentions Balanced: http://www.forbes.com/sites/jonmatonis/2012/11/26/payments-s... but he just didn't answer or ask the _right_ questions.
Another reason - there just hasn't been enough demand for it.
As this fraction increases, fraud is reduced further and further.
It would be interesting to have a payment platform that evaluates the trustworthiness of a customer right before payment (based on factors such as customer history, shipping address matching the billing address...), and force those deemed "risky" to pay in Bitcoins. It could even handle CC authorization failures: "credit card declined? No problem, pay in Bitcoins instead."
I doubt it. Most fraudsters are trying to convert someone else's credit into cash by buying goods they can sell. If you have a bitcoin, you pretty much already have cash - just use one of the exchanges.
I can't see how.
As a non-fraudster, I would use any available payment method, including bitcoins.
As a fraudster, I would never use bitcoins.
You not going to have a person not defraud you because you provided the option of Bitcoins. If you have transaction that you deem risky, require a bank transfer, that will make it easier for the criminals to go commit fraud somewhere else.
Other than a few big names I have a lot less than absolute trust in online vendors, so I find the chargeback facility very reassuring
We currently have an issue where someone is using stolen credit cards to buy "digital goods".
We in the UK and Scandinavia, so we started out blocking purchases of digital goods from the UK. Fraud goes to zero right away.
The fraudsters moves to using stolen UK credit cards in Denmark, via a large number of Danish IPs, fine... We'll just require that the card is issued in the country where your IP indicates that you're located ( not 100% correct, but close enough ).
At this point fraud has been reduced to zero for a few weeks. The next we really where not expecting. The same pattern of buying starts showing up, seems like fraud and it turns out it is. We now see a stolen Danish credit cards.
At this point we're more or less reduced to having to approve every purchase manually. The only real solution currently is 3DSecure for MasterCard or Verified by VISA. These solutions are very American and not at all what European customers expect to see. Enabling 3DSecure scares of legitimate customers, but it's currently the only solution.
The article looks at high velocity, that does nothing in some cases, if people are out to scam you, they will appear as a new customer for a new IP, with a new card.
CSC are useless, these are stolen all the time.
AVS is supported by almost no one.
Looking a transaction amount compared to the mean doesn't really work when you mostly sell one product at a time.
Recently created accounts are actually a good indication of fraud, but mostly you have false positives.
Blocking high risk countries don't work for digital goods.
Large distance between IP and billing address, doesn't work well in smaller countries, but worth considering. Somewhat difficult to implement though.
High number of card from the same person... That never happens. Our legitimate customer are the only ones that might use different cards. In the case of fraud cards and accounts are often used only once.
It's not that the article is a bad write up, but non of the information will protect you against someone that wants to scam you. Physical products are easier to safe guard, because the bad guy will need to pick it up at some point, digital good is a lot harder to secure.
Edit: to mean, who would bother to do payment fraud, when you can just download torrents.
Torrents are useless for games that require constant network access, which is most new games. You can have the "stolen" keys blocked, but you still lose money.
I think some effective techniques for digital goods are: 1) behavioral signals, such as how long the user spent browsing your site before making a purchase, 2) physical device -- have I seen activity from this particular machine before, even if they're going through a proxy to use a fresh IP? 3) e-mail address -- is it a legitimate domain? an obvious throw-away account?, 4) mismatch between IP and billing info (as you noted).
In general, fraudsters switch tactics with surprising frequency, so I'd highly recommend combining multiple types of data into a machine learning system that will adapt. Otherwise you're going to spend a lot of time tuning rules.
And if you're looking for help, feel free to send me an e-mail: brandon@siftscience.com. My company deals with fraud all the time. Even if we can't help, I'd be happy to point you to others who can.
Although generally payment methods are quite diverse across Europe, I'd say in places like here in the UK it is now fairly common to get the secondary confirmation prompts when purchasing on-line, certainly from smaller businesses. They also seem to be fairly smart about when they just let it go through without troubling the user these days, e.g., low value regular payments to the same vendor don't seem to ask me for any confirmation most of the time recently, but payments to new vendors often do.
Is this not your experience as well?
We use minfraud, a service that takes all of those parameters as input, and uses a huge database of previous fraud to return the probability the transaction is fraud. It has worked exceedingly well to prevent almost all fraud on our marketplace.
I wrote in detail about this process about half a year ago - http://www.binpress.com/blog/2012/07/31/fighting-online-frau...
Using Braintree as my processor, I send an authorization request for the card. If the auth is successful, I send the data over to MinFraud for a check. If the fraud value is < 25 then I submit the auth for settlement, otherwise it gets voided and the user gets a message that their purchase didn't pass our fraud check.
I also log all minChecks and I manually check any request that has a value > 10 or so just to make sure it looks legit.
The biggest change I had to make to support this is that I had to add Country, City, and Region (State) boxes to my payment form. So user's have to put in 3 more pieces of information that they didn't have to with a plain (a la Stripe Purchase button) payment form.
However, that information has saved me from numerous frauds. Also, it appears that once the fraudsters determined that they couldn't use my site anymore, they've stopped trying.
I am VERY happy with their service and it's very inexpensive.
We had really bad chargebacks and our underwriting merchant almost pulled our account. It took going back to some manual verification and other tricks to finally get it down. We've only had a dozen or so chargebacks in the last 6 months.
I can't speak for Europe, but basically every site here in Sweden where I buy something with a card uses 3DSecure and VbV. The pick up over the past couple of years has been massive.
Back about 2008-2009 it seemed I got hit with a VbV screen for 90% of purchases. Then, it just seemed to 'go away'
In the past 3 or 4 months, I've started seeing VbV screens again though. So perhaps something else has changed?
Personally I never had any purchase problems with the system.
Most of the time that kind of tech isn't even necessary. The types of criminals most online stores deal with are not sophisticated; they're just people that paid $1/number for a list of phished credit cards on a black market forum who are going to enter them one-by-one on a few websites to see which haven't been reported stolen yet.
It's open source, you're welcome to contribute a fix: https://github.com/balanced/balanced.github.com/blob/master/...
Tell me you're not serious.
We crowdsource feedback for a lot of things we do @ Balanced. For example, we've openly discussed pricing (https://github.com/balanced/balanced-api/issues/48), etc.
Everything's on https://github.com/balanced/balanced-api. We're trying a different approach to payments, for once. Openness and transparency.