Inactive
- Join Date:
- Jan 2012
- Posts:
- 496
- Plugin Contributions:
- 0
Just got burned...
I just processed my first fraudulent transaction...
Here's the story that I have pieced together so far.
Last week an Account was created, user places a high dollar order *(not uncommon).
CC passed FRISK (fraud detection), CCV # entered, billing address is correct.
The ship to address was different, but when I googled it, it actually came back as an office building owned by the account holder, in a city just north of billing address. Called the phone # on the account, answered and verified order. Checked IP address, came from greater LA area, still good.
I shipped the goods, delivery notice left on first attempt, delivered the following day (picked up at PO).
I figured all was good.
Today I was watching users add items to cart, etc. I see a user from Indonesia adding some high ticket items in their cart. Spent over an hour picking out a few choice items. Cart goes away. A few minutes later, the account user logs in (with a greater LA area IP) adds the exact same items to the cart and proceeds to check out. The transaction was declined (I was going to VOID it if it did go through). The user bails.
I begin researching the IP address and it appears to be an LA based proxy that they came through. Checked out phone # on the account, registered mobile in billing city, called it, now disconnected. I start looking up the account users name, etc. The fake phone # was two digits off the 'legit' number (found in white pages), all other information was correct.
I called the 'real' cc account holder tonight, and yes she has had her card compromised. I am now out ~$500...
Not sure what more I could have done to prevent this?
It surprises me the amount of information that people willing put out on the internet for thieves to piece things together.
I am also surprised at the elaborate level these guys went through to get a few hundred dollars.
Lesson learned I guess.