opinion

How to Thwart Attacks, Fraud in Payment Processing

How to Thwart Attacks, Fraud in Payment Processing

If personal fitness was among your New Year’s resolutions, great! Fitness is essential for your overall health and well-being — and the same can be said about ensuring the “fitness” of your business. To keep your business fit in terms of its overall financial health and well-being, it’s critical to have an effective strategy in place for dealing with fraud.

While it is only February now, I can confirm what all the pundits, analysts, doomsayers and I were prophesying at the end of 2021 with regards to ecommerce fraud, as there is no question that there was a record amount of attempted and successful ecommerce fraud this past holiday season. You may have noticed that I included “attempted” fraud; that is because, as expected, merchants who have enrolled in protective services from payment processors were not as dramatically affected. As I mentioned during the billing panel at XBIZ 2022 in Los Angeles, our Order Insight and Rapid Dispute Resolution capabilities have proven invaluable in preventing fraudulent purchases and disputes.

Velocity controls, which are tools designed to limit the number of times a specific card account number, email address, IP address or user account can attempt a sale during a user-specified time frame, can be very useful in thwarting attacks.

Since the COVID pandemic took off in March 2020, card testing has increased in popularity amongst the steal-from-home fraudsters. Card testing is done by cybercriminals to test the validity of credit card information they obtain. While the purchase may not go through, your business is going to be charged a transaction fee, say $0.20 for example. While that may not make or break you, when you have a criminal deploying a bot on your payment page that can test thousands of card numbers in an hour, those $0.20 transaction fees can add up quickly.

The thing about card testing is that virtually every ecommerce merchant that accepts credit cards is a potential victim of card testing; that being said, it is one of the easiest and least expensive means of ecommerce fraud to combat. The act of adding CAPTCHA to your checkout page will significantly reduce card testing attempts as scripts and bots can have a problem getting around it. There is no need to make it a difficult CAPTCHA as you are only trying to thwart robots, not frustrate your buyers. Any decent shopping cart will provide a CAPTCHA option.

A few other free tools are likely already available to you through your gateway provider. Velocity controls, which are tools designed to limit the number of times a specific card account number, email address, IP address or username can attempt a sale during a user-specified time frame, can be very useful in thwarting attacks. For example, suppose you run a membership site and offer a seven-day trial that converts into a 30-day membership. In that case, there’s no reason a single user, or more importantly, a single IP address, would need to attempt multiple transactions, since they would gain access with a single transaction. Allowing for normal declines, you could even up that number to six attempts every 30 days and still spare yourself having to worry about card testing.

Since it is the beginning of the year, how about setting up a best practices schedule for your ecommerce security? For example, set up a regular schedule for changing passwords for your individual employees as well as your ecommerce gateway. If you check out the December 2021 issue of XBIZ World, I go into greater detail on methods of fighting ecommerce fraud.

To those of you that I got to see at the shows last month, it was good to reconnect. Whether you are an existing, new or potential client, I enjoyed the opportunity to have a drink, chat, get reacquainted and get up to speed with the latest developments in our businesses. I hope you find some value in my suggestions, and may 2022 be off to an excellent start for you.

Jonathan Corona has nearly two decades of experience in the electronic payments processing industry. As chief operating officer of MobiusPay, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards mandated by the card associations, including, but not limited to, maintaining a working knowledge of BRAM guidelines and chargeback compliance rules defined in both Visa and Mastercard operating regulations.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

LoyalFans' Anastasia Pierce Bridges Creator Education, Empowerment and Ownership

Anastasia Pierce beams when she talks about her 26 years in the industry. Full of passionate energy, she clearly doesn’t just work in adult; she loves it.

Women In Adult ·
opinion

Growing Site Revenue Under Ever-Changing Compliance Rules

Over the past year, many merchants have reported earnings that were flat or even a bit down. This is due to three main factors: age verification regulations, click-to-cancel rules, and banks backing away from cross-sales due to regulatory requirements and the rollout of the Visa Acquiring Monitoring Program (VAMP).

Cathy Beardsley ·
opinion

AI Safeguards for Platform Compliance and Trust

If your platform hosts user-generated content (UGC), then you already know protecting your brand is not merely a matter of good design or strong community guidelines. It requires systems that can verify who your users are, filter what they upload and ensure your business stays on the right side of regulators, payment processors and public opinion.

Christoph Hermes ·
opinion

How to Eliminate User Redirects and Improve Checkout Retention

Running an adult site, you work hard to create traffic and make sure your funnel is optimal, with the end goal of getting users to make a purchase. Then, right at that critical moment, what do you do? You send them somewhere else. Not good.

Jonathan Corona ·
profile

Stripchat's Jessica on Building Creator Success, One Step at a Time

At most industry events, the spotlight naturally falls on the creators whose personalities light up screens and social feeds. Behind the booths, parties and perfectly timed photo ops, however, there is someone else shaping the experience.

Jackie Backman ·
opinion

Inside the OCC's Debanking Review and Its Impact on the Adult Industry

For years, adult performers, creators, producers and adjacent businesses have routinely had their access to basic financial services curtailed — not because they are inherently higher-risk customers, but because a whole category of lawful work has long been treated as unacceptable.

Corey Silverstein ·
opinion

How to Build Operational Resilience Into Your Payment Ecosystem

Over the past year, we’ve watched adult merchants weather a variety of disruptions and speedbumps. Some even lost entire revenue streams overnight — simply because they relied too heavily on a single cloud provider that suffered an outage, lacked sufficient redundancy and failover, or otherwise fell short when it came to making sure their business was protected in case of unwelcome surprises.

Cathy Beardsley ·
opinion

Building a Stronger Strategy Against Card-Testing Bots

It’s a scenario every high-risk merchant dreads. You wake up one morning, check your dashboard and see a massive spike in transaction volume. For a fleeting moment, you’re excited at the premise that something went viral — but then reality sets in. You find thousands of transactions, all for $0.50 and all declined.

Jonathan Corona ·
opinion

A Creator's Guide to Starting the Year With Strong Financial Habits

Every January brings that familiar rush of new ideas and big goals. Creators feel ready to overhaul their content, commit to new posting schedules and jump on fresh opportunities.

Megan Stokes ·
profile

Pornnhub's Jade Talks Trust and Community

If you’ve ever interacted with Jade at Pornhub, you already know one thing to be true: Whether you’re coordinating an event, confirming deliverables or simply trying to get an answer quickly, things move more smoothly when she’s involved. Emails get answered. Details are confirmed. Deadlines don’t drift. And through it all, her tone remains warm, friendly and grounded.

Women In Adult ·
Show More