Return fraud is an increasing problem for Amazon FBA sellers, and eBay and Etsy shops/ here's how it works and how to stop it.
seen from United States
seen from China
seen from Libya
seen from Singapore
seen from Armenia
seen from China

seen from Malaysia
seen from Russia
seen from France

seen from Russia

seen from Nepal
seen from Germany
seen from United States

seen from United States

seen from Germany

seen from Netherlands
seen from Malaysia

seen from Malaysia

seen from United States

seen from United States
Return fraud is an increasing problem for Amazon FBA sellers, and eBay and Etsy shops/ here's how it works and how to stop it.
Online fraud has gained in sophistication in recent years. As consumers have moved to using mobile devices and have come to expect a consistent shopping experience across platforms, so the fraudst…
We share some of the classic fraud patterns & things to keep in mind, in the fashion vertical, and best practices to avoid con activities.
It is no hidden truth that Customer acquisition is quite a tough job. Doesn’t matter if your online store makes just a few thousand or earns millions of dollars monthly, driving traffic to your sit…
Don’t be the weak link in your store’s security
By Phil Grier Yahoo Small Business Merchant Development
There are a handful of customer service emails that can make online retailers’ stomachs drop, and they usually start something like: “where’s my order,” “you made a mistake,” or even “I want a refund.” But the one that chills me to the bone is “I ordered from you and the next day I had multiple fraud charges on my card.”
Risk factors differ, but regardless of your ecommerce platform, if you accept card payment on your store, this can happen to you. It can indicate the beginning of a PR nightmare for your business and an almost certain headache. Here’s what you need to know to prevent it from happening.
No matter how secure your ecommerce platform, there are several innocuous places in the checkout process that scammers can use to steal your customer’s credit card data. The shocking thing is that most of the time this isn’t done with some super-complex hacking software or a sinister genius sitting in front of 40 monitors streaming code like in the movies. In most cases, the merchants themselves place the problem code or install the plugin and unwittingly cause the problem.
Any plug-in, extension or code could open a hole in the security of your cart if you aren’t careful. Many small business owners are not technically savvy enough to review all of the code involved to make sure these additions are secure (and this is nothing to be ashamed of, it’s really hard). Therefore some trust is involved anytime you extend the platform by adding plug-ins, extensions, and code. Nevertheless, if your cart is compromised, it is your responsibility as the retailer.
I recently witnessed a small business on another ecommerce platform catch fire on this issue. She had installed a well-rated extension that came from an apparently reputable developer. All seemed fine, and then her Facebook wall started filling up with complaints from customers who had their credit card data stolen after ordering from her. I could only imagine the email volume was huge as well. Small business owners aren’t prepared for this kind of thing and it’s easy to panic. She had no idea what was happening and tried to deflect. In the end, her brand was damaged because of a platform extension she had no training to code review for security.
In reaction to stories like these, operating systems and internet browsers continue to tighten security, particularly related to encrypted checkout. Red flags include having a lower encryption level than desired, a certificate that expires too far in the future, forms like search boxes that submit to insecure pages, and images that are pulled in over an insecure URL. But there can be many other issues, and these rules constantly change. The companies that run the most popular internet browsers and operating systems now force webmasters such as yourself and hosting companies to not only be secure, but “the desired level of secure” to avoid warnings. The security safe zone is always moving and your conversion hangs in the balance.
The solution for larger companies is a top-down full security appraisal that looks at local passwords, storage, networks, personnel, site code, email, and every place that could be leveraged for malicious intent to get card data. However, small businesses rarely have the resources to invest in such a thorough and expensive solution. So what can you do without breaking the bank?
Here are a few tips:
Review your access list. Remove anyone who does not need access to your site or store backend.
Frequently change your passwords.
Don’t store card numbers, and especially don’t store CVV codes. Depending on how you manage card numbers, card issuers can fine or revoke your ability to take their cards. And manually storing or collecting CVV codes is never permitted.
Work with trusted developers. Members of our developer network, at ysbdevelopers.com, are individually reviewed by us to help maintain high quality.
Get a security review of your checkout.
The last point bears a little more explanation. Most platforms let you place your own code, like javascript, in checkout. HTML can be used to show images. A search box is commonly seen. These are all vectors where malicious (or simply vulnerable) code can be unintentionally placed. Add-ons, plug-ins, and extensions designed to enhance checkout functionality may have access to all on-page data -- including card numbers. Given the strong urgency around customer payment security, online retailers should have someone on-hand who knows what each snippet of non-core code in checkout does. This expert could be you, someone on your staff, or a trusted developer.
Just remember: A browser warning doesn’t always indicate a real problem, just like a green padlock doesn’t always indicate complete security. As the webmaster, you need to take responsibility for the code your site is running and get help or be prepared to learn a lot. Your brand’s trusted status may hang in the balance.
SignatureLink’s research shows traditional fraud screening solutions actually cost eCommerce merchants between 1% and 4% of gross annual sales. If you’d rather turn those losses into profit, you need SecureBuy™, the only comprehensive fraud solution on the market. Call SignatureLink at (800) 511-2050 to get started.