Security reminder - protect your business from fraud attacks
Security reminder - protect your business from fraud attacks
Aug 19, 2026
Omair Mirza
An estimated 3.2% of total annual ecommerce revenue is lost to payment fraud each year, per the most recent global ecommerce Payments and Fraud Report by the Merchant Risk Council (MRC).
Fortunately, there are many methods available that can help prevent fraud and protect your customers. We’d like to share the latest practices to prevent card testing attacks and other types of fraud.
Top tips
Keep up to date with our managing fraud and risk blogs to understand how to balance fraud prevention against acceptance rates and protect your customers while letting good payments through
Consider enrolling in the Fraud Essentials Course, offered free to Checkout.com merchants through our partnership with the MRC. This course breaks the topic down into specific elements related to your business processes, showing how fraudsters can exploit parts of the customer journey
Have tested incident response plans in place and ready to use to respond to fraud events
Contact your providers as soon as possible if you or your customers experience fraud.
If you suspect your customers’ card data is compromised, follow the steps in the ‘what to do if compromised’ section of this article. Most importantly, you must notify your acquirer(s) within three working days of any suspected compromise
Fraud prevention tactics
Monitoring and alerts
Monitor and review the language and time zone of your customers’ IP addresses and devices. This can help you detect inconsistencies in data such as mismatch of billing address and IP and flag these transactions as higher risk
Add IP addresses that have regular failed payment attempts to a block list for review
Look for account usage across multiple IP addresses. While these may not always show fraudulent behavior, you may wish to add these IP addresses to a temporary block list to review their activity
Set up alerting for high numbers of approved or decline transactions originating from a single BIN range
Consider implementing velocity checks on small or large transaction volumes – where card testing occurs this is usually for transactions with a value of below $10 or a local currency equivalent
Use anomaly detection to monitor transactions and sales patterns
Card authentication and validation
Use EMV 3D Secure (3DS2) to authenticate cardholders for high-risk purchases
Use 3RI authentication to authenticate Merchant Initiated Transactions such as subscription and recurring payments
Use AVS (Address Verification Service) and CVV (Card Verification Value) checks
Use Account Name Inquiry to validate a cardholder's name against the name held by their issuing bank
Account security
Lock a user’s account if they make a high number of incorrect password or username attempts
Block users from using common or suspicious passwords, or regularly review logins that use these passwords
Review customer sessions for excessive bandwidth consumption, and look out for multiple transactions using different cards from the same email address or device ID
Use random pauses (throttling) when checking an account. This can slow down brute force attacks, particularly for BINs associated with high fraud
Payment page security
Use CAPTCHA control to prevent bots or scripts from making automated transactions on your payment pages, and consider investing in botnet detection and device fingerprinting systems
If you would like advice on implementing any of the above strategies, please contact your Checkout.com representative and we’ll be happy to assist you.
What to do if compromised
If you suspect unauthorized access or misuse of cardholder data, you must report this to Checkout.com within three working days.
We’ll ask you to complete an incident report to help the schemes understand the potential scope, data at risk, and the remediation steps you’ve taken.
In some cases, the schemes may ask you to conduct a forensic investigation or engage a Payment Card Industry (PCI) Forensic Investigator (PFI) to perform an independent investigation.
The schemes strongly recommend that you also notify your internal incident response team, legal department, information security group, and any integrated partners you use within the payment flow, as well as the appropriate local or national law enforcement agencies.
The schemes also recommend that you:
Do not access or alter compromised systems (e.g. do not log on to the compromised systems and change passwords or log in using administrative credentials). You should disconnect compromised systems from the internet immediately and not use them to process payments or interface with payment processing systems
Do not turn off, restart, or reboot the compromised systems. Instead, isolate the compromised systems from the rest of the network by unplugging network cables or through other means
Identify and document all suspected compromised components (e.g., PCs, servers, logs, security events, databases etc.)
Document containment and remediation actions taken, including dates/times (preferably in UTC), individuals involved, and detailed actions performed
Preserve and retain all evidence (including physical servers or devices) and logs (e.g., original evidence such as forensic image of systems and malware, security events, web logs, database logs, firewall logs, etc.)
If using third-party service providers like hosting companies or cloud providers, request logs and system images to be retained and provided to the PFI or external security firm assisting in the investigation
Preserving evidence in cloud computing environments carries its own specific challenges related to digital forensics. For more guidance, visit the PCI SSC Cloud Guidelines
ABOUT THE AUTHOR
As Director of Scheme Relationships, Omair plays a pivotal role in bridging the gap between Checkout.com and the major card schemes – Visa, Mastercard, American Express, and JCB. With over 11 years of experience in scheme relationships, Omair is an expert at navigating the complexities of scheme requirements, helping you keep up to date on key changes that affect our merchants.