Increase of fraud orders
-
Hi, I am experiencing an extremely high rate of fraud order attempts on several websites that I manage. It looks like it always involves the Advanced Card Processing, but due to business requirements, I can’t simply disable this. I tried so many things, such as rotating the API keys, disabling Legacy API, etc, but no joy.
99% of email address used for the fraud orders follow the pattern randomname.6numbers[at]gmail.com
And also, I think this is important — it looks like all fraud orders are first created as Draft and then from Draft to Pending Payment and then to Failed (when the payment fails).
Normal orders submitted through the normal checkout flow do not go through status “Draft”, so I wonder how these are submitted to the website. May be through the REST API somehow?
I’ve checked for malware, reset passwords, but no joy.
At one point I thought rotating the API keys solved the issue, but that doesn’t seem to be the case.
- You must be logged in to reply to this topic.