Fraudulent charges – Site attacked
-
Hi there
I am using latest WP, your plugin and Stripe payment API versions etc.
I’ve been using your plugin for several months now, all good until this morning.
My site was attacked, where hackers tried to use one of the checkout form and tried to mostly unsuccessfully attempted several thousands transactions.
1. is it possible for someone to attempt to transact a different amount than what’s listed on the checkout form? In my case, I saw hackers attempted value of $29-$30, whereas my form has the product listed for $89? How is that even possible??
2. About 3% of the attempts were successful (visa prepaid, debit card, etc.) with a value of $29-$30, however I didn’t see any of those listed on the Stripe plugin Orders page? It is a good thing that my product was not stolen, but I need to know how is that possible?
3. Going forward, how do I block or beef up security on the checkout form? I am also disappointed in Stripe, however to be fair, they were able to block 97% of the transactions. I am working with them to see how to prevent this from happening again in the future.
Thanks again for an awesome plugin. Appreciated it!
- The topic ‘Fraudulent charges – Site attacked’ is closed to new replies.