Protecting your payout and payment settings

Protecting your payout and payment settings

Membergate Support -

A criminal who breaks into your membership site might steal a member list. A criminal who breaks into your payment settings can steal your income directly, and often quietly. The most common version is simple: they change the bank account your payouts go to, then wait. Members keep paying, your dashboard shows healthy revenue, and the money goes somewhere else until someone notices the business bank balance has stopped growing.

Payout fraud targets the people who can change payment details: you, your bookkeeper, your assistant and anyone else with access to your processor. Protecting those settings takes a handful of habits that are easy to set up, and far easier than trying to recover redirected money.

How payout and payment fraud usually works

  • Payout redirection. An attacker gets into your payment processor account, often through a phished password or a hijacked inbox, and replaces your bank details with their own.
  • Fake verification requests. An email that looks like it comes from your processor asks you to “confirm your payout details” on a lookalike page.
  • Supplier bank change scams. A message that appears to come from a regular supplier, such as your video editor or developer, says their bank details have changed and asks you to pay the next invoice to a new account.
  • Affiliate account takeover. If you pay affiliates, a criminal who takes over an affiliate’s login may change where commissions go, or set up fake affiliates to collect commission on fraudulent sign-ups.
  • Refund abuse. Someone with access issues refunds to cards they control, or creates new connection keys they can use later.
  • Hiding the evidence. Attackers often change the account’s notification email first, so the alert about a bank change goes to them rather than to you.

Limit who can change where money goes

Few people need the power to change payout details, and ideally only one or two should have it. In your payment processor, give each person their own login and a role that matches their work. A support assistant might view payments and issue small refunds; a bookkeeper might see reports. Neither needs to edit bank details or create connection keys. Protect every login with two-factor authentication using an authenticator app or security key.

Because a password reset for your processor goes to your email, securing that inbox is part of protecting your payouts. The steps in securing the email account that runs your business apply directly.

Alerts that reach you, and someone else

Turn on every notification your processor offers for sensitive changes:

  • Changes to bank or payout details.
  • Changes to the account email or notification settings.
  • New team members or changed roles.
  • New connection keys.
  • Refunds above an amount you choose.

Where possible, send these alerts to two places: your main address and a second person or a private address that is not published anywhere. If an attacker changes one, the other still hears about it. Ask your bank to alert you to unusual activity too, and find out whether your processor holds payouts for a short period after bank details change. Some do, which gives you time to react.

Verify every change outside the channel it arrived on

Adopt one firm rule for your whole team:

We never change bank details, for ourselves, a supplier or an affiliate, based on an email, chat message or form alone. Every change is confirmed by calling or messaging the person using contact details we already had before the request arrived. If a request is urgent, that is a reason to check more carefully, not less.

For affiliates, apply a short waiting period after any change to payout details, and notify the affiliate’s previous email address so a genuine affiliate can object. The same caution applies to a phone call claiming to be from your processor: hang up and call the number on its official website.

A worked example: the weekly payout reconciliation

Reconciliation means checking that the money you should have received matches the money that actually arrived. Rafael runs a hypothetical chess coaching membership and spends ten minutes on it every Monday:

  1. He opens the payment processor and notes the payouts sent in the past week.
  2. He opens the business bank account and confirms a matching deposit arrived for each payout, on the expected date.
  3. He checks that the payout bank details in the processor still end in the last digits of his own account.
  4. He glances at the processor’s activity records for setting changes, new users or new connection keys.
  5. He scans refunds for anything he or his assistant did not issue.

One Monday the processor shows a payout sent, but the bank shows nothing, and the payout details end in unfamiliar digits. Because he checks weekly, only one payout has gone astray. He calls his processor and his bank at once, locks the account, reverses the attacker’s changes and follows his incident plan. The activity logs show the change was made after his assistant’s password was phished, so two-factor authentication becomes compulsory for everyone that afternoon.

If a payout is redirected

  1. Contact your payment processor and your bank straight away, using contact details from their official websites.
  2. Restore your bank details, change passwords, sign out all sessions and remove unknown users and connection keys.
  3. Check that the account email and notification settings have not been changed.
  4. Gather evidence: dates, amounts and screenshots of the changes.
  5. Report the fraud as your bank and local authorities advise.

Recovering redirected money is not guaranteed, which is why speed and prevention matter so much.

Your next steps

  1. Reduce the number of people who can change payout details to one or two.
  2. Turn on alerts for bank, email, user and key changes, sent to two places.
  3. Adopt the verification rule and share it with your team, suppliers and affiliates.
  4. Start a weekly reconciliation of payouts against bank deposits.
  5. Require two-factor authentication on every processor login.

0 Comments

Comments are reviewed before they appear.