Zen Cart Logo
Forums / Fraud Prevention / Business attack: I have not seen this trick before ever...

Business attack: I have not seen this trick before ever...

Locked

Views: 1,497

Results 1 to 16 of 16
This thread is locked. New replies are disabled.
29 Jun 2009, 2:48 AM
#1
dreamdaily avatar

dreamdaily

New Zenner

Join Date:
Apr 2005
Posts:
53
Plugin Contributions:
0

Business attack: I have not seen this trick before ever...

Hello everyone,

I want to share my recent experience and seek your opinion about what's going on.

I've been running ZC stores since 2005 and this is a new development I haven't seen before.
One of my store (name is withheld for now) is under a strange "business" attack.

On several occasions, regularly we get order(s) (from 1 up to 4 at a time) that do look absolutely legitimate.
The billing address is even the same as the shipping one.
The order(s) is shipped and a week later we get a call from the addressee inquiring what this is all about: they'd never ordered anything from us.
Did your kids, friends etc. possibly order it?
Double-checked: No.
Was your card stolen, compromised?
No.
All our questions and checks yielded nothing.
The person absolutely and categorically did not order anything from us.
Of course we'd take the merchandise back, credit the amount and make them whole.

This happened several times already.

As you can imagine, we still suspected the customers simply changed their mind.
Until we found the evidence in our logs that the customers were indeed unsuspecting victims of someone's actions.

I will not publish the logs checking procedure even on this respected public board until this incident is over.
It is likely the culprit is familiar with ZC or at least osCommerce and we do not want to educate them about their mistakes here.
Afterwards, I'll publish all the information one might need to identify and prevent similar activity.

So, we found the evidence that someone places orders under names of different people using their actual credit card numbers.
The culprit gives the actual addresses of credit card holders as shipping addresses for those orders.
People call us to complain and return the merchandise and get the money back.
We gladly do that.
At the end, we are out S&H money to ship stuff back and forth.

It seems that the damage done by this activity is small.

Have you seen anything like this in your store?
Have you heard of it?
Who do you think might be doing this: a competitor, an angry customer, a random idiot?
What do you think is the goal of this business attack?

Your insights and ideas would be greatly appreciated.

Thank you,
DD

29 Jun 2009, 3:08 AM
#2
kim avatar

kim

Obaa-san

Join Date:
Jun 2003
Posts:
26,591
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

If you have evidence of someone in particular placing these orders, you need to contact the authorities. You should also contact your Merchant Services company if you suspect that cardholder information has been compromised somewhere.

To protect yourself, start phoning your customers before you ship any order and verify that it is legit. On large orders, make it a policy to get written verification of the order.

BTW- make sure you are using the most recent code and security patches and that your site is secured.

29 Jun 2009, 4:03 AM
#3
dreamdaily avatar

dreamdaily

New Zenner

Join Date:
Apr 2005
Posts:
53
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

Thank you, Obaa San!

Your suggestions are absolutely correct: we are following the same path you've outlined.
As I mentioned, in terms of prevention we are pretty much covered now.

Still, the motivations behind such an attack are unclear.

Hopefully, the readers of this board would be able to offer their experiences or thoughts on the matter.

29 Jun 2009, 4:05 AM
#4
bobdog avatar

bobdog

Totally Zenned

Join Date:
Mar 2006
Location:
Fresno, California
Posts:
590
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

Actually, yes. I have seen this. But not on zen cart.

Some years back, I was working as a bookkeeper in a music store. A man came in, bought a very expensive saxophone, paid with a credit card, and the next day he returns it. Why? we asked.

He just wanted us to refund the money on his credit card, saying he didn't like the instrument.

Come to find out, he was using his dad's credit card, and just loved the thrill of buying stuff, use it, and then return it. And later we found out that this guy was doing this in all the music stores in our town. We suspected that he wanted to play a gig that night, bought a fine instrument, played the gig, and returned the instrument the next day.

29 Jun 2009, 4:17 AM
#5
dreamdaily avatar

dreamdaily

New Zenner

Join Date:
Apr 2005
Posts:
53
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

LOL!

Thank you for the great story!

We also thought that we were dealing with some nutty customers.

However, by examining the logs we 100% completely exonerated them.

We KNOW that they did not order the merchandise themselves.
We do not sell p##n or scam, btw.

We do know that a culprit ordered it on someone's credit cards, shipped it to the person and tried to cover the tracks.
It happened on many occasions already, all different random people.

Is it a competitor trying to discredit us before our credit card processor, or law enforcement?
Kind-a silly...

Am I missing a big picture here?...

29 Jun 2009, 4:27 AM
#6
kim avatar

kim

Obaa-san

Join Date:
Jun 2003
Posts:
26,591
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

We do know that a culprit ordered it on someone's credit cards, shipped it to the person and tried to cover the tracks.
It happened on many occasions already, all different random people.

That is fraud and needs to be reported. Period.

29 Jun 2009, 7:02 AM
#7
fairestcape avatar

fairestcape

Totally Zenned

Join Date:
Mar 2008
Location:
Cape Town & London (depends on the season)
Posts:
2,957
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

This could be an example of an emerging con game.

Con artists know that many online stores will not deliver to different shipping addresses (different from billing address), so they obtain details of people's credit cards and (usually at the same time, details of their physical addresses).

Then they buy items online, using "legitimate" card and address details.

They then wait outside the delivery address for the consignment to arrive. In the UK, where fulfilment is generally very reliable, this wait is generally no more than a few hours.

In many cases, the occupants of the house (delivery address) are at work, so no-one is at home to receive the goods. This is exactly what the conman wants.

When the delivery van arrives, the con artists gives the impression they are the occupants of the address - often by parking their vehicle outside (or close to) the property and pretend they are rummaging around in the car's trunk, and then they approach the delivery man and say... "That package for number 14...? I've been expecting it... where do I sign?"

The delivery driver, believing the conman to be the legitimate occupant of number 14 hands over the package and gets the conman to sign the waybill...

Both then go on their way!

29 Jun 2009, 10:47 AM
#8
iridiumcorpsupport avatar

iridiumcorpsupport

New Zenner

Join Date:
Feb 2008
Posts:
27
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

Hi All,

This is a form of card slamming attack. Basically it will be someone who has bought in a list of cards and card details and they are checking them for use elsewhere.

What you need to do is inform the card holders that you believe their cards to be compromised and get them to cancel the cards ASAP. You also need to contact your acquiring bank as well and inform them that you have caught and detected this fraud and that you have put in place procedures to deal with it. If you are doing a lot of refunds due to this attack you will get flagged as a potential high risk. By speaking with your acquiring you are demonstrating you are proactive about the situation and they will work with you to resolve the situation.

I also recommend that you start pre-authing transactions rather than doing a full collection payment. This means if a transaction turns out to be bad that you do not have to do a refund but a void of the original transaction.

Hope this helps/

29 Jun 2009, 5:04 PM
#9
dreamdaily avatar

dreamdaily

New Zenner

Join Date:
Apr 2005
Posts:
53
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

Thanks to everyone who posted on this thread so far!

First let me reiterate that WE DID CONTACT THE AUTHORITIES, we DID report the credit card fraud, we DID contact the unsuspecting victims and informed them about the compromised credit card information.
This has all been done.

The motivation behind the activities remains a mystery.

a) It was not a delivery intercept by conmen because all packages were delivered to their addressees. By the way they are all in different states, so coordination of order placement, shipment tracking, and dispatching the "interceptor" to the delivery address is not likely to be worth doing... Who knows but, again, all parcels were delivered, no problems.

b) Card slamming is possible but not likely because the culprit knew the exact information of the card holders: Their billing addresses were flawless, the CVV were entered as well.

By the way, the authorities we've spoken to couldn't offer any insight on what that could be, it does not look like anything they know about.

I was also surprised by how little they wanted to be bothered with reports like that.
For example, the merchant service provider simply refused taking any reports about fraud. Period.
They were only interested, and mildly so, to know if a chargeback will occur or not.

So, we did our part reporting it and we implemented new preventive measures.

I'm just curious to find possible motivation behind such bizarre attacking.

So far, no cigars...

29 Jun 2009, 6:54 PM
#10
kim avatar

kim

Obaa-san

Join Date:
Jun 2003
Posts:
26,591
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

I'm just curious to find possible motivation behind such bizarre attacking.

The only way you will ever learn the TRUE motivation is to ask the folks that did it. :blink:

29 Jun 2009, 6:59 PM
#11
dreamdaily avatar

dreamdaily

New Zenner

Join Date:
Apr 2005
Posts:
53
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

LOL!

You are right!

I also hoped that might be someone had already seen this trickery, had a chance to ask the perpetrators :-) or figure it out and now is willing to share the knowledge with the world.

At least this post could be a warning to other merchants out there...

9 Jul 2009, 10:16 PM
#12
blackhalo avatar

blackhalo

Zen Follower

Join Date:
Feb 2008
Posts:
118
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

dreamdaily:

I was also surprised by how little they wanted to be bothered with reports like that.
For example, the merchant service provider simply refused taking any reports about fraud. Period.
They were only interested, and mildly so, to know if a chargeback will occur or not.

We get card slamming on a semi-regular basis...that's what's happening to you.

The thieves are testing the cards...because even if they have all the information, you don't know where they got it from.
They MUST test them to be sure they're good before they sell them (for a much higher price if the card works!).

Personally, we tried contacting all the appropriate authorities in the beginning...
but that only ran us into a brick wall, built on a disgusting level of apathy.

We use Paypal(PRO) for credit card processing, we contacted them first...
they essentially told us they cannot give me the credit card number,
and they will NOT contact the credit card companies on my behalf.

That right there should be illegal...
Paypal is pro-actively stonewalling my ability to report a stolen credit card.

So then we contacted the credit card companies, but we couldn't get in touch with a real person...
their automated phone system requires that you KNOW the credit card number you're reporting!!
We tried clicking 1 through 0 to get an operator, but all those backdoors are blocked.

You would think the card owners name and address would be a good start for tracing the card...
but no, they only want the card number or nothing at all.

And since we don't collect the customers phone number (which would likely be fake anyway), we only have a billing address...
so the only way to contact them is by snail mail...and by the time they get a hand written letter, it's already been caught on their CC statement.

After 50 card slams this year, we honestly can't be bothered with snail mail....
I know that sounds harsh, but we're just passing along the apathy that we get from the companies above us.
We don't have time to "police" for the credit card companies, let them pay the customer back for the stolen money.

My advice, don't get worked up about it...
if the credit card companies make it impossible to report fraud, that's their problem...
they're the ones that insure the customer, not me.

It's a shame really...but I'm not gonna try and change a system that nobody else is interested in changing.
Just make sure you cover your bases, and don't get burned.

Live and let live.

25 Oct 2009, 1:24 AM
#13
ironpig avatar

ironpig

New Zenner

Join Date:
Oct 2009
Posts:
2
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

blackhalo:

We get card slamming on a semi-regular basis...that's what's happening to you.
<snip>
We don't have time to "police" for the credit card companies, let them pay the customer back for the stolen money.

My advice, don't get worked up about it...
if the credit card companies make it impossible to report fraud, that's their problem...
they're the ones that insure the customer, not me.

It's a shame really...but I'm not gonna try and change a system that nobody else is interested in changing.
Just make sure you cover your bases, and don't get burned.

Live and let live.

I couldn't agree more about the aparant apathy exhibited by card issuers. I have first hand experience trying to report fraud only to be 'stonewalled'. Very frustrating.

Unfortunately it is we the merchants who pay the loss, not the card companies. (even when you've obtained address and CVV match)

17 Dec 2009, 5:01 AM
#14
dreamdaily avatar

dreamdaily

New Zenner

Join Date:
Apr 2005
Posts:
53
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

THank you all guys for the excellent insight!

Your war stories are really helpful.

This reminds me of "Logan's Run", the movie, where in the future a pursuit of a fugitive stops when its cost becomes a bit more expensive than the non-pursuit. Guessing that for CC companies it's just a big numbers game with all margins figured out and they can not be bothered with ad hoc fraud reports from merchants. Complacency begets its antagonist...

31 Dec 2009, 2:57 AM
#15
oneworldstudios avatar

oneworldstudios

New Zenner

Join Date:
May 2007
Posts:
47
Plugin Contributions:
0

Re: Business attack: I have not seen this trick before ever...

We just started having this "card slamming" happen to us a few days ago and it's up to 100 transactions per day. We installed "advance fraud detection" from Authorize.net and it has been catching them all and declining them. So far none have gone through but we guessed someone was testing the numbers because they were all fake addresses and for very small purchases anyway.

Anybody know how to get their IP addresses through ZC? Authorize.net allows a blockage of certain IPs or countries/locales.

31 Dec 2009, 3:56 AM
#16
gjh42 avatar

gjh42

Black Belt

Join Date:
Jul 2005
Location:
Upstate NY
Posts:
21,876
Plugin Contributions:
8

Re: Business attack: I have not seen this trick before ever...

They are probably using rotating IP addresses, so it would be pointless to block any one IP. It might be worthwhile blocking countries if you don't do business to them anyway, though they may be spoofing those too.