728_header.jpg (23748 bytes)
 Home   EB Blog   AB Blog   Letters   Podcasts   ABTV   Forums   EPIS   PR Service   Classifieds   Ecommerce EKG   Service Ratings   
  Subscribe    RSS Feeds    Twitter        Contact Us  Web Site  
Service Ratings 
   Auction Sites
   FP Marketplaces
   Inventory Management
   Payment Services
   Storefronts & Carts
   Sniping Services
   Wholesale/Dropshipping
   Email List Hosting
   Consignment Services
   Ecommerce EKG 
   Auction Calendar
   Collectors' Links
   eBay Promo History
   Bookshelf
   Fraud Resources
   Drop-Off Store Laws
   ABTV
   Ecommerce Resources
   Photo Tips
   Marketing Inserts
   Yellow Pages
   Advertising

EcommerceBytes-NewsFlash, Number 2016 - April 10, 2009 - ISSN 1539-5065     | Next
Merchant Attack Exposes Vulnerability in eBay's PayPal Service - Part 2
By Ina Steiner
EcommerceBytes.com
April 10, 2009




What happens when a fraudster barrages a merchant with bogus PayPal-funded transactions? In Part One, we saw that in one real-life example, the merchant's account was restricted for 2 weeks. Understandably, he told us that he was frustrated that his account was restricted through no fault of his own. Although he was proactive in reporting the fraudulent payments to his account, and spent many hours working with PayPal's customer support team, his online business came to a standstill because he was not able to accept payments via PayPal.

In this case, PayPal's public relations team was able to give us some information, but it's unlikely merchants typically receive much follow-up after they have been involved in an attack, which can add to a merchant's sense of helplessness.

PayPal spokesperson Sara Gorman said the company's fraud models caught the fraud, but said it was a new case they hadn't dealt with before. They were doing things behind the scenes, which might also explain why it took time to resolve it. "We're sorry the customer was frustrated," she said.

Gorman said that she could not provide all the details about the case because PayPal does not want people to try it. However, she said that while their system ask shoppers for CVV numbers, the fraudsters were able to get around that. PayPal has since closed that workaround, she said.

The problem of fraud is a classic arms race, Gorman said. "We do a good job of staying on top of it, but there is no system that has zero fraud risk. There are people all over the world trying to do this." Gorman said there are very sophisticated fraudsters hitting payment systems all the time.

Fraud Filters
In our previous article, we explained how merchants could control account setting that gives them the option of accepting transactions from consumers who do not have a PayPal account but are using a guest pass. Merchants who use PayPal Website Payments Pro and Virtual Terminal have the option to upgrade to Advanced Risk Filters for an additional monthly fee. This allows them to tighten or loosen the fraud filters on their accounts. PayPal's Gorman said some merchants actually tell them that they think PayPal's fraud filters are too strict and like the ability to control their own settings.

We spoke to an expert in online fraud who previously worked at PayPal and now works for another firm to get some context. Cory Siddens is Senior Product Manager of Risk at CyberSource, which provides payment solutions to large and small businesses and operates the Authorize.Net payment gateway.

Siddens said it is typical that merchants are allowed to tighten or loosen fraud controls, and agreed that merchants prefer to choose their own level of fraud risk. For instance, a merchant can put controls on the volume coming through in a certain time period. However, "Any time you put an impediment, you have the possibility of lost customers," he said. "That customer may never come back again."

He also said that gateways are limited in the amount of data they have to work with - there is matching against billing address, for example, but not the cardholder name.

What Was in It for the Fraudster?
What baffled both merchants and payment processors was why this flood of fraudulent funds was being sent to this merchant's account. The only time this type of activity is seen is for "card testing" after fraudsters have purchased stolen credit card information on the black market and need to test the cards to see if they are still active. However, usually scammers test cards on low-priced items.

CyberSource's Siddens said that he hadn't heard of a case exactly like the one outlined, though he'd seen cases where honest buyers make purchases from scammers who then used stolen credit cards to fulfill the order. The victim is unaware he's handed over his money to a fraudster and is happy to receive his order - until the retailer identifies the fraudulent payment and reports the victim to law enforcement agencies.

The only inkling of why the fraudsters may have processed the payments in this case was PayPal's admission that this was a new type of fraud, so it may have been a test of PayPal's fraud detection.

How Can Sellers Protect Themselves
Sellers should understand the options they have available to them in setting their level of fraud risk. PayPal merchants can learn more about fraud management filters here. For standard accounts, merchants can filter for maximum transaction amounts and country of origin. And this page explains the account settings available to PayPal merchants, including the option of whether to accept transactions from consumers who do not have a PayPal account but are using a guest pass.

Merchants who use PayPal Website Payments Pro and Virtual Terminal have the option to upgrade to Advanced Risk Filters for an additional monthly fee that allows them to screen for 17 additional criteria.

As the merchant in this story found out, it's good to have a backup plan and accept multiple types of electronic payment. He quickly put Google Checkout on his website to replace PayPal. While he didn't know how long he would be without PayPal, he knew every day without any payment method on his site was costing him money.

Finally, higher-volume sellers or those in high-risk categories should consider advanced features and shop around for solutions. John Stevens of Litle & Co., a company whose expertise is in card-not-present transactions, said merchants often don't understand where fraud breakdowns can occur, and it can get more complicated as they integrate payment services with third-party shopping carts. Cory Siddens said merchant training and education is a big issue when it comes to fraud prevention. Merchants must weigh the costs of investing in more expensive services and training because, ultimately, it appears all sellers are vulnerable to online fraud.

You can comment on this case on the AuctionBytes Blog

You may quote up to 50 words of any article on the condition that you attribute the article to EcommerceBytes.com and either link to the original article or to www.EcommerceBytes.com.
All other use is prohibited.

Email Newsletter icon, E-mail Newsletter icon, Email List icon, E-mail List icon Sign up for our Email Newsletters

Email this story to a friend.

| Next

 EcommerceBytes Blog 
 AuctionBytes Blog 
 Letters to the Editor 
Related Stories 
Related Stories
  • New Law May Prove Taxing for PayPal and for eBay Sellers - January 18, 2009, Issue #231
  • PayPal Launches Shopping Website - January 19, 2009, Issue #1958
  • eBay Expands Guest Buying Program to 15 Transactions - January 21, 2009, Issue #1960
  • PayPal Merchants with Credit Card Accounts Must Update Certs - February 24, 2009, Issue #1984
  • Etsy Tests PayPal Billing - March 04, 2009, Issue #1990
  • PayPal's Charity Smackdown at SXSW - March 23, 2009, Issue #2003
  • Blackbaud and PayPal Offer New Web Tools for Nonprofits - March 31, 2009, Issue #2008
  • PayPal Continues Testing Student Accounts - April 03, 2009, Issue #2011
  • PayPal Hires Asia Pacific Manager, Wins Prepaid Card Award - April 07, 2009, Issue #2013
  • Merchant Attack Exposes Vulnerability in eBay's PayPal Service - Part 1 - April 09, 2009, Issue #2015
  • Merchant Attack Exposes Vulnerability in eBay's PayPal Service - Part 2 - April 10, 2009, Issue #2016
  • PayPal Buyer Protection Launches on eBay's Dutch Classifieds Site - May 14, 2009, Issue #2041
  • PayPal Rolling Out New Design - May 15, 2009, Issue #2042
  • Yahoo Makes It Easier to Use eBay, PayPal from Anywhere - June 08, 2009, Issue #2053
  • PayPal Holds Affect eBay and Off-eBay Transactions - June 09, 2009, Issue #2054
  • PayPal Launches 'Do Stuff for Money' Facebook App - June 23, 2009, Issue #2064
  • PayPal Announces New Express Checkout API to Reduce Cart-Abandonment - June 25, 2009, Issue #2066
  • Online Shopping Set to Boom According to PayPal UK Survey - June 26, 2009, Issue #2067
  • PayPal Follows eBay in Opening Platform to Third-Party Developers - July 07, 2009, Issue #2074
  • PayPal Holds Seminar for Developers in Australia - July 13, 2009, Issue #2078
  • PayPal Opens Platform, Announces Developers Conference - July 24, 2009, Issue #2087
  • PayPal Publishes Policy Updates - July 27, 2009, Issue #2088
  • Merchants Must Contact PayPal for Outage Compensation - August 12, 2009, Issue #2100
  • PayPal Introduces Student Account - August 12, 2009, Issue #2100
  • eBay Buyers Can Pay with Credit Card without PayPal Account - August 19, 2009, Issue #2100
  • As PayPal Goes Mainstream, So Do Its Blunders - August 20, 2009, Issue #2101
  • PayPal Runs Twitter Quiz Show - August 21, 2009, Issue #2102
  • eBay's PayPal Faces Increasing Competition in Payments Space - August 27, 2009, Issue #2106
  • eBay Reports PayPal Glitch with UPS Accounts - August 27, 2009, Issue #2106
  • PayPal Accepting Nominations for Developer Awards - September 07, 2009, Issue #2113
  • eBay CEO: Skype Deal Will Happen, Open to PayPal Spin-off - September 25, 2009, Issue #2124
  • PayPal Expands Ability to Place Temporary Holds on eBay Transactions - October 06, 2009, Issue #2131
  • PayPal Lets Shoppers Fund Accounts with Cash - October 08, 2009, Issue #2133
  • eBay and PayPal Now Offer Bill Me Later on BIN and Some Auctions - October 20, 2009, Issue #2141
  • Payvment Brings PayPal-Powered Shopping Cart to Facebook - October 21, 2009, Issue #2142
  • PayPal Launches Own Forum as It Moves toward Independence from eBay - October 30, 2009, Issue #2149
  • PayPal Offers Holiday Deals through Retail Partners - October 30, 2009, Issue #2149
  • You Can't Take It with You: PayPal and Estate Planning - November 01, 2009, Issue #250
  • PayPal Opens Platform to Target $30 Trillion Opportunity at DevCon - November 03, 2009, Issue #2151
  • PayPal Opens Its Global Payments Platform - November 04, 2009, Issue #2152
  • PayPal Announces Developer Challenge for Innovative Apps - November 05, 2009, Issue #2153
  • PayPal Galvanizes Users to Help Lobby Government - November 13, 2009, Issue #2159
  • PayPal's 2008 Holiday Promotions Drove Increased Usage at Retail Sites - November 16, 2009, Issue #2160
  • PayPal Survey Asks Online Sellers to Rate the Service - November 27, 2009, Issue #2169
  • PayPal Launches Facebook App, Continues Global Development Efforts - December 14, 2009, Issue #2180
  • Bulgarian Faces Charges Related to Fake Escrow eBay Scam - May 27, 2010, Issue #2296


  • Discussion Forums 
    Have a question about buying or selling online? Want to get marketing or technical advice? AuctionBytes Discussion Forums are the place to come to get answers to your questions and get advice! Great tips - a refreshing change!

    Current Discussions:
     

    About Us      Privacy Policy      Link to Us      Partners      Our Writers      Write for Us      Press        Site Index

    Copyright 1999-. Steiner Associates LLC. All rights reserved.