• Resolved Minnnnn

    (@minnnnn)


    Hey folks, hoping for a bit of help or insight here.

    I manage a number of websites and in the past two days, two completely seperate sites I manage have both had a heap of spam orders placed in their Woocommerce stores. I believe this is the work of scammers testing whether stolen credit card details work or not, and I’ll elaborate:

    Site 1: about 600 fake orders were placed (over the space of about 4 hours);
    – all of the fake orders were for one product (on a site that sells hundreds),
    – all the names used were in lowercase, but differed every time,
    – all physical addresses were the same – and fake:
    street 2321
    asadasda Victoria 312312,
    – all the email addresses used were the format of [fullname][random_numbers]@gmail.com,
    – almost all of the orders failed,
    – 8 of the fake orders were successful, and now we’re going through a seemingly endless process of getting stripe to freeze those payments so they don’t sync to my client’s bank account, and for them to report those credit card details as stolen,
    – our web hosts confirmed that all the fake orders originated from 3 ip addresses (which we have blocked through Wordfence).
    It’s worth nothing this site doesn’t have registrations enabled, and doesn’t allow account creation during purchase.
    The only way I was able to stop the fake orders from coming in (at the time) was to mark the particular product they were targeting as out of stock.

    I’m assuming that these scammers have a heap of stolen credit card details and are running a script through a store with a small $value product to confirm which of the details they have are successfully able to purchase something. But – like I said – I’m just assuming here.

    Site 2: exists on a completely different web server, if that’s even relevant.
    – 10 fake orders just came in, same model (lowercase for first name and last name that changes every time, bodgy physical address that’s the same for every order – place doesn’t exist – gmail accounts that are names and strings of numbers),
    – again, all orders were for one product (on a site that sells thousands) and all tried to process through the Stripe gateway.

    ALL plugins are up to date on both sites – 6.5.1 of the Woocommerce Stripe gateway plugin. Both stores are located in Australia.

    Any ideas or help?

Viewing 8 replies - 1 through 8 (of 8 total)
Viewing 8 replies - 1 through 8 (of 8 total)
  • The topic ‘fraudulent orders created on 2 sites – all stripe gateway’ is closed to new replies.