Malicious Authorize.Net script being run to process transaction

This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.
7 years ago
At a minimum you could turn off checkout as guest.  At least temporarily.  That would at least make it harder to post the transactions unless they create an account and login to it.  You'd have an easier time identifying them in that situation.

The captcha solution requires some programming to get into place.
7 years ago
Got it ! Thank you! but what is that AN fraud protection ? could you please send me the site link ?
7 years ago
I believe they are referring to the Authorize.net fraud protection.  You'll need to go to your Authorize.net account and look at the options for fraud protection.  Some basic things are free of charge.  More advanced features have additional charges.  You can get more info from their help links in your account.
7 years ago
Yes. It was Authorize.Net fraud protection. We enabled features there and it dramatically stopped fraud attempts. For instance we only ship to USA, Canada and USA territories so within AN you can set a filter to only accept credit cards from issued from banks in those areas. Most if not all of the fraud attempts against our Authorize.Net account were from cards issued outside the US and Canada. They also have an acceleration filter which stops processing attempts from cards being used in rapid succession from the same IP Address which is what was happening to us. It was like someone was using a program, external from the website, to submit transactions to our AN account one after the other. The acceleration filter killed those and now it's like whomever was doing it has just given up. If you use Authorize.Net make it a priority to set up the fraud protection. Just the free stuff works great.
6 years ago
Site live for few days and the script bot came last night.  581 attempts to checkout with different card numbers. Which cost 6 cent each.  Definitely need a honeypot or captcha on order page.   Anyone have any luck with this yet?
Came from different IP's, so hard to just block by IP address.
6 years ago
2nd bot run yesterday afternoon.   Didn't trigger IP velocity limit on Fraud Suite.
6 years ago
which payment gateway do you use? Authorize.net? have you tried the fraud protection?
6 years ago
Set up more fraud protection and it has stopped
6 years ago
We are not using Authorize.Net but still getting the same issue.  Is there a spot in Nop where we can stop a process prior to processing the cart?
This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.