Fraudulent sign-ups and card testing

Fraudulent sign-ups and card testing

Membergate Support -

You wake up to dozens of payment failure notifications. Overnight, your checkout has been hit by hundreds of attempts to buy your cheapest plan, each with a different card. Most were declined; a few went through. The names are random, the email addresses are nonsense and the attempts came from all over the world. Your site has been used for card testing.

Criminals who obtain lists of stolen card numbers need to find out which ones still work before they sell them or use them for bigger purchases. They do that by making small purchases on websites that will not look too closely. A membership checkout, especially one with a low-priced plan or a free trial that asks for a card, can be an ideal testing ground. It costs you in fees, disputes and your standing with your payment processor, and the successful charges leave you holding money you will need to give back.

Why membership checkouts attract card testers

  • Low prices. A small charge is less likely to be noticed by the cardholder or flagged by their bank.
  • Card-required free trials. Some trials check a card with a small temporary authorization, which tells the criminal whether the card is live without any real charge.
  • Donation or pay-what-you-want forms that accept very small amounts.
  • Instant, automated sign-up with no verification and no limit on attempts.
  • Detailed error messages that reveal exactly why a card failed.

What it costs you

  • Many processors charge fees per attempt or per successful charge, and these add up over hundreds of attempts.
  • Cardholders who spot the charges file chargebacks, disputes that pull the money back and usually carry a fee. Handling them is covered in chargebacks: preventing and handling payment disputes.
  • A spike in declines and disputes can lead your processor to review, restrict or close your account.
  • Fake accounts clutter your member list, distort your numbers and receive your welcome emails, which bounce and harm your sending reputation.

Recognizing an attack

Watch for these signs, and ask your processor whether it can alert you when they appear:

  1. A sudden burst of failed payments, far above your normal level.
  2. Many attempts on your lowest-priced plan or trial.
  3. Many different cards from the same internet address or device, or one account trying card after card.
  4. Random-looking names, email addresses at unfamiliar domains and billing details that do not match.
  5. Attempts arriving in rapid succession at unusual hours.

A worked example: responding while it is happening

Signe runs a hypothetical printable planner membership with an inexpensive monthly plan. Just after midnight, her phone lights up with payment failure alerts. Here is the response she follows:

  1. Slow the checkout. She switches on the strongest bot challenge her platform offers for the checkout page and asks her host to apply rate limits.
  2. Pause the target if needed. The attempts continue, so she temporarily hides the low-priced plan and shows a short message saying sign-ups will reopen shortly.
  3. Contact the processor. She reports the attack and asks which fraud rules they can switch on for her account.
  4. Find the successful charges. In the morning she filters payments from the attack window and finds a handful that succeeded on stolen cards.
  5. Refund and remove. She refunds those charges and cancels the fake accounts, so she is not keeping money taken from stolen cards. In our experience, refunding quickly reduces the chance of later disputes, but follow your processor’s guidance.
  6. Clean up. She removes the fake addresses from her mailing list before the next newsletter goes out.

By lunchtime the checkout is back to normal, with better defenses than before.

Making your checkout a poor target

Card testers go where it is easy. A few changes make your site much less attractive:

  • Use your processor’s fraud screening, and ask about rules such as declining payments where the security code or postal code does not match.
  • Limit attempts per person, internet address and card within a short period.
  • Add an invisible bot check to checkout, with a visible challenge only when behavior looks automated.
  • Keep decline messages general, such as “Your payment could not be completed. Please check your details or try another card,” rather than revealing the exact reason.
  • Reconsider very low entry points. A tiny paid trial or an open donation amount invites testing; a sensible minimum helps.
  • Verify email before a free trial starts, if the extra step suits your audience.

Balance matters. Every step you add can cost you genuine members, so keep the strongest measures in reserve for when an attack is under way, and relax them afterward.

Other fraudulent sign-ups

Not every fraudulent sign-up is card testing. Sometimes a stolen card is used to buy real access, perhaps to download a whole course library before the charge is disputed. Warning signs include a new member downloading everything within an hour of joining, or several accounts paying with the same card. Where your platform allows, consider releasing downloads gradually to new members and reviewing high-value digital purchases before access is granted. Fraudsters sometimes combine attacks, so keep your payout and payment settings protected too.

Your next steps

  1. Ask your processor what fraud screening and alerts are available, and switch them on.
  2. Set up rate limits and a bot check on your checkout.
  3. Rewrite decline messages so they are helpful but general.
  4. Review your lowest price points and trials for testing risk.
  5. Write your attack response steps, including how to pause a plan quickly.
  6. Decide how you will find and refund successful fraudulent charges.

0 Comments

Comments are reviewed before they appear.