Home
>
Merchant Communications
>
Security reminder - protect your business from fraud attacks

Security reminder - protect your business from fraud attacks

Aug 19, 2026
Omair Mirza

An estimated 3.2% of total annual ecommerce revenue is lost to payment fraud each year, per the most recent global ecommerce Payments and Fraud Report by the Merchant Risk Council (MRC).

Fortunately, there are many methods available that can help prevent fraud and protect your customers. We’d like to share the latest practices to prevent card testing attacks and other types of fraud.

Top tips

  • Keep up to date with our managing fraud and risk blogs to understand how to balance fraud prevention against acceptance rates and protect your customers while letting good payments through
  • Consider enrolling in the Fraud Essentials Course, offered free to Checkout.com merchants through our partnership with the MRC. This course breaks the topic down into specific elements related to your business processes, showing how fraudsters can exploit parts of the customer journey
  • Have tested incident response plans in place and ready to use to respond to fraud events
  • Contact your providers as soon as possible if you or your customers experience fraud.
  • If you suspect your customers’ card data is compromised, follow the steps in the ‘what to do if compromised’ section of this article. Most importantly, you must notify your acquirer(s) within three working days of any suspected compromise

Fraud prevention tactics

Monitoring and alerts

  • Monitor and review the language and time zone of your customers’ IP addresses and devices. This can help you detect inconsistencies in data such as mismatch of billing address and IP and flag these transactions as higher risk
  • Add IP addresses that have regular failed payment attempts to a block list for review
  • Look for account usage across multiple IP addresses. While these may not always show fraudulent behavior, you may wish to add these IP addresses to a temporary block list to review their activity
  • Set up alerting for high numbers of approved or decline transactions originating from a single BIN range
  • Consider implementing velocity checks on small or large transaction volumes – where card testing occurs this is usually for transactions with a value of below $10 or a local currency equivalent  
  • Use anomaly detection to monitor transactions and sales patterns

Card authentication and validation

  • Use EMV 3D Secure (3DS2) to authenticate cardholders for high-risk purchases
  • Use 3RI authentication to authenticate Merchant Initiated Transactions such as subscription and recurring payments
  • Use AVS (Address Verification Service) and CVV (Card Verification Value) checks
  • Use Account Name Inquiry to validate a cardholder's name against the name held by their issuing bank

Account security

  • Lock a user’s account if they make a high number of incorrect password or username attempts
  • Block users from using common or suspicious passwords, or regularly review logins that use these passwords
  • Review customer sessions for excessive bandwidth consumption, and look out for multiple transactions using different cards from the same email address or device ID
  • Use random pauses (throttling) when checking an account. This can slow down brute force attacks, particularly for BINs associated with high fraud  

Payment page security

  • Use CAPTCHA control to prevent bots or scripts from making automated transactions on your payment pages, and consider investing in botnet detection and device fingerprinting systems

If you would like advice on implementing any of the above strategies, please contact your Checkout.com representative and we’ll be happy to assist you.

What to do if compromised

If you suspect unauthorized access or misuse of cardholder data, you must report this to Checkout.com within three working days.

We’ll ask you to complete an incident report to help the schemes understand the potential scope, data at risk, and the remediation steps you’ve taken. 

In some cases, the schemes may ask you to conduct a forensic investigation or engage a Payment Card Industry (PCI) Forensic Investigator (PFI) to perform an independent investigation.

The schemes strongly recommend that you also notify your internal incident response team, legal department, information security group, and any integrated partners you use within the payment flow, as well as the appropriate local or national law enforcement agencies.

The schemes also recommend that you:

  • Do not access or alter compromised systems (e.g. do not log on to the compromised systems and change passwords or log in using administrative credentials). You should disconnect compromised systems from the internet immediately and not use them to process payments or interface with payment processing systems
  • Do not turn off, restart, or reboot the compromised systems. Instead, isolate the compromised systems from the rest of the network by unplugging network cables or through other means
  • Identify and document all suspected compromised components (e.g., PCs, servers, logs, security events, databases etc.)
  • Document containment and remediation actions taken, including dates/times (preferably in UTC), individuals involved, and detailed actions performed
  • Preserve and retain all evidence (including physical servers or devices) and logs (e.g., original evidence such as forensic image of systems and malware, security events, web logs, database logs, firewall logs, etc.)
  • If using third-party service providers like hosting companies or cloud providers, request logs and system images to be retained and provided to the PFI or external security firm assisting in the investigation
  • Preserving evidence in cloud computing environments carries its own specific challenges related to digital forensics. For more guidance, visit the PCI SSC Cloud Guidelines

Return to Home

Unlock your payments potential today

Contact us