Zen Cart Logo
Forums / Fraud Prevention / Advice...? harassment from competitor.

Advice...? harassment from competitor.

Locked

Views: 197

Results 1 to 9 of 9
This thread is locked. New replies are disabled.
01 Mar 2010, 15:03
#1
bodyjewelrystores avatar

bodyjewelrystores

Zen Follower

Join Date:
Jun 2006
Posts:
123
Plugin Contributions:
0

Advice...? harassment from competitor.

Hi all,

First of all I apologize I am posting this is in the wrong forum... not exactly sure where this should go, even though this is more about harassment than fraud. Anyway,here goes:

One of our competitors has been spamming us with fake orders. They've created multiple customer accounts - sometimes using completely fake names and nonexistent business info, sometimes even using real names that we've been able to trace to their business(!).

What they do is choose COD as a payment method (well, more precisely a clone of that module) so there is no payment being made during checkout. Then they simply disappear and never reply to contact attempts from our sales (in case that email address exists at all).

I can't really see what they're trying to achieve, except maybe:
A - they want to check the order numbers, to get an idea of how well our sales are doing
B - maybe they think that our store deducts stock automatically (it doesn't), so they could be trying to make our best-selling items disappear by "ordering" a lot of them
C - just wasting our time.

Anyway - my questions:

  1. This is the peculiar thing - the IP address on some of their orders actually resolves to our competitor's mail server, as in "mail.their-domain-name.com". As if they were browsing our site from the same computer as their hosted mail server, to submit the order.

At first, I thought maybe they were running a script from their web server, but the http logs show a normal "human" browsing pattern for that ip address + the user agent string is IE7.
Any ideas what's going on here? I found out who their hosting company is - they have Windows-based hosting. Is it possible that they're actually using IE from a dedicated server to submit their fake orders?
.
2. What can we do? Of course, I could deny their IP address all access to our website.... but I'm wondering if we can/should do more.

As I said, we know who their hosting company is - and we have proof that they (our competitors) have been using their hosting company's servers for the purpose of spamming and harassment.

The hosting company is US-based, and I'm sure there are laws against this kind of thing. They wouldn't be pleased if they found out that one of their customers is abusing their services.
Should we contact the hosting company and complain? Would you...?
Thanks in advance.

01 Mar 2010, 15:40
#2
stevesh avatar

stevesh

Black Belt

Join Date:
Feb 2005
Location:
Lansing, Michigan USA
Posts:
19,793
Plugin Contributions:
2

Re: Advice...? harassment from competitor.

As long as you have the documentation, I would block the IP right away, let their host know what's going on, and, if you know where their website is, I would contact someone at that site (as high a person as you can find an address for) and explain the problem. It could be that some minor drone thinks he's doing something clever, and the people who run the company don't know about it.

01 Mar 2010, 16:39
#3
bodyjewelrystores avatar

bodyjewelrystores

Zen Follower

Join Date:
Jun 2006
Posts:
123
Plugin Contributions:
0

Re: Advice...? harassment from competitor.

Thanks for your input, stevesh.

As for contacting someone at their website/company: one of the names they used for a customer account is actually the same person (name and email address) who owns their domain name - at least according to the contact info in their whois record. The particular orders from that account were using a regular, ISP-provided, dynamic IP address, though... all the orders that came from their actual web host's IP address were using different, fake info, as far as we can tell.

I'm not sure what exactly they were thinking, using real names... maybe they're just not that computer/web-literate. But we can do little by contacting them, other than asking them to stop. As for IP blocking, there has been legitimate business coming from the same ISP that they've been using on some of those orders... so the only thing I can safely block is their web host's IP. Therefore, it won't really eliminate the problem, but perhaps contacting their host would scare them off somewhat.

01 Mar 2010, 16:50
#4
kim avatar

kim

Obaa-san

Join Date:
Jun 2003
Posts:
26,590
Plugin Contributions:
0

Re: Advice...? harassment from competitor.

perhaps contacting their host would scare them off somewhat.

That would be the recommended course of action.

01 Mar 2010, 17:38
#5
shrimp_gumbo_mmmhhh avatar

shrimp_gumbo_mmmhhh

Totally Zenned

Join Date:
Jun 2007
Location:
Texas, USA
Posts:
1,436
Plugin Contributions:
0

Re: Advice...? harassment from competitor.

bodyjewelrystores:

Hi all,

First of all I apologize I am posting this is in the wrong forum... not exactly sure where this should go, even though this is more about harassment than fraud. Anyway,here goes:

One of our competitors has been spamming us with fake orders. They've created multiple customer accounts - sometimes using completely fake names and nonexistent business info, sometimes even using real names that we've been able to trace to their business(!).

What they do is choose COD as a payment method (well, more precisely a clone of that module) so there is no payment being made during checkout. Then they simply disappear and never reply to contact attempts from our sales (in case that email address exists at all).

I can't really see what they're trying to achieve, except maybe:
A - they want to check the order numbers, to get an idea of how well our sales are doing
B - maybe they think that our store deducts stock automatically (it doesn't), so they could be trying to make our best-selling items disappear by "ordering" a lot of them
C - just wasting our time.

Anyway - my questions:

  1. This is the peculiar thing - the IP address on some of their orders actually resolves to our competitor's mail server, as in "mail.their-domain-name.com". As if they were browsing our site from the same computer as their hosted mail server, to submit the order.

At first, I thought maybe they were running a script from their web server, but the http logs show a normal "human" browsing pattern for that ip address + the user agent string is IE7.
Any ideas what's going on here? I found out who their hosting company is - they have Windows-based hosting. Is it possible that they're actually using IE from a dedicated server to submit their fake orders?
.

  1. What can we do? Of course, I could deny their IP address all access to our website.... but I'm wondering if we can/should do more.

As I said, we know who their hosting company is - and we have proof that they (our competitors) have been using their hosting company's servers for the purpose of spamming and harassment.

The hosting company is US-based, and I'm sure there are laws against this kind of thing. They wouldn't be pleased if they found out that one of their customers is abusing their services.
Should we contact the hosting company and complain? Would you...?
Thanks in advance.

May also be trying to lower profits ... you having to pay the COD fees if you ship it?

Some people are just bad. My great great grandfather was an entrepreur.... one business was a cotton seed gin.... the gin was guarded by the family but a competitor was able to set the barn on fire it was in and he went on to something else.

01 Mar 2010, 17:51
#6
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,682
Plugin Contributions:
56

Re: Advice...? harassment from competitor.

bodyjewelrystores:

What they do is choose COD as a payment method (well, more precisely a clone of that module) so there is no payment being made during checkout. Then they simply disappear and never reply to contact attempts from our sales (in case that email address exists at all).

I'm going to add a small mod that you can plug in to payment modules like COD, Invoice, Check/Money Order, etc. that will allow you disable the payment method for new customers (those without, say, one completed order). This may be useful for people in situations like yours.

01 Mar 2010, 18:02
#7
bodyjewelrystores avatar

bodyjewelrystores

Zen Follower

Join Date:
Jun 2006
Posts:
123
Plugin Contributions:
0

Re: Advice...? harassment from competitor.

shrimp-gumbo-mmmhhh:

May also be trying to lower profits ... you having to pay the COD fees if you ship it?

Oh, we never ship an order before contacting the customer and making sure that they (at the very least) exist. If they wanted to try harder, they would probably attempt to pose as legit customers but they don't even bother - they simply place the order and disappear. So far they haven't cost us money... yet (except for the time wasted by our sales reps... and by me in digging through logs and such).

Anyway, thanks everyone for the tips!

01 Mar 2010, 18:07
#8
kiddo avatar

kiddo

Totally Zenned

Join Date:
Jul 2006
Location:
SF Bay Area
Posts:
837
Plugin Contributions:
1

Re: Advice...? harassment from competitor.

People are clever. I've heard of a scam that worked very much like what you describe, but when you call to verify the order, you un-knowingly are billed a huge amount on your phone bill.

01 Mar 2010, 18:34
#9
flipside avatar

flipside

Zen Follower

Join Date:
Oct 2004
Location:
Ontario
Posts:
114
Plugin Contributions:
0

Re: Advice...? harassment from competitor.

If this is not happening too frequently, I would simply ignore their lame attempts at whatever it is they are trying to do. With that kind of attitude about business/competition, they aren't going to last long.

If you do not actually use COD that often, I would disable it completely. I found in my previous shops that COD was not worth the added work, even with real customers.

Just my 2 cents.