New Zenner
- Join Date:
- Apr 2005
- Posts:
- 53
- Plugin Contributions:
- 0
Business attack: I have not seen this trick before ever...
Hello everyone,
I want to share my recent experience and seek your opinion about what's going on.
I've been running ZC stores since 2005 and this is a new development I haven't seen before.
One of my store (name is withheld for now) is under a strange "business" attack.
On several occasions, regularly we get order(s) (from 1 up to 4 at a time) that do look absolutely legitimate.
The billing address is even the same as the shipping one.
The order(s) is shipped and a week later we get a call from the addressee inquiring what this is all about: they'd never ordered anything from us.
Did your kids, friends etc. possibly order it?
Double-checked: No.
Was your card stolen, compromised?
No.
All our questions and checks yielded nothing.
The person absolutely and categorically did not order anything from us.
Of course we'd take the merchandise back, credit the amount and make them whole.
This happened several times already.
As you can imagine, we still suspected the customers simply changed their mind.
Until we found the evidence in our logs that the customers were indeed unsuspecting victims of someone's actions.
I will not publish the logs checking procedure even on this respected public board until this incident is over.
It is likely the culprit is familiar with ZC or at least osCommerce and we do not want to educate them about their mistakes here.
Afterwards, I'll publish all the information one might need to identify and prevent similar activity.
So, we found the evidence that someone places orders under names of different people using their actual credit card numbers.
The culprit gives the actual addresses of credit card holders as shipping addresses for those orders.
People call us to complain and return the merchandise and get the money back.
We gladly do that.
At the end, we are out S&H money to ship stuff back and forth.
It seems that the damage done by this activity is small.
Have you seen anything like this in your store?
Have you heard of it?
Who do you think might be doing this: a competitor, an angry customer, a random idiot?
What do you think is the goal of this business attack?
Your insights and ideas would be greatly appreciated.
Thank you,
DD