BigCommerce

Stopping Card Testing Fraud on BigCommerce: A Comprehensive Guide for Merchants

The digital storefront offers unparalleled opportunities for growth, but it also brings the persistent challenge of fraudulent activity. Many BigCommerce merchants, like Kim Olsen who recently shared her experience in a forum thread, encounter a particularly frustrating issue: receiving numerous orders with captured funds, but suspicious customer details that lead to undeliverable packages and bounced emails. This scenario, characterized by mismatched names and email addresses (e.g., 'Todd Green' with 'Sophia.Moore@gmail.com'), is a classic indicator of card testing or payment fraud, not a compromise of the BigCommerce store itself.

BigCommerce fraud settings showing AVS/CVV verification and fraud app integration.
BigCommerce fraud settings showing AVS/CVV verification and fraud app integration.

The Anatomy of Card Testing Fraud on BigCommerce

As BigCommerce community experts Sri Vathson and Solomon Lite quickly confirmed, Kim's experience aligns perfectly with typical card-testing fraud. Fraudsters acquire stolen credit card numbers from external breaches and use public checkout pages, like those on your BigCommerce store, to test their validity. They often use throwaway or scraped personal information for the order details, leading to the inconsistencies you observe. The goal isn't to receive goods, but to confirm which stolen cards are active before using them for larger, more damaging purchases elsewhere.

Key indicators that an order might be fraudulent include:

  • Mismatched Customer Details: A common name paired with an unrelated or generic email address.
  • Undeliverable Shipping Addresses: Packages returned as undeliverable or to vacant properties.
  • Bounced Emails: Attempts to contact the customer result in emails bouncing back.
  • Suspicious IP Addresses & Geolocation: The customer's IP address doesn't match their stated billing/shipping location, or it originates from a known high-risk region.
  • Low-Value Orders: Fraudsters often start with small purchases to test card validity before attempting larger transactions.
  • Rapid-Fire Orders: A sudden burst of orders in a short timeframe, often indicating bot-driven activity.

Immediate Response: Handling Existing Fraudulent Orders

When you identify a suspicious order, swift action is crucial to minimize your losses and protect your business. Here’s what BigCommerce merchants should do:

  • Cancel and Refund Promptly: If an order hasn't shipped, cancel and refund it immediately. Waiting to contact the 'customer' is futile as the provided email is almost certainly fake.
  • Understand Processor Fees: Be aware that canceling a captured charge typically incurs a small processor fee. While an inconvenience, this fee is significantly less costly than losing product to a future chargeback, which can also negatively impact your merchant account standing.
  • Confirm Returns Before Refund: If an order has already shipped and is returned as undeliverable, only issue a refund after you've physically confirmed the goods are back in your possession. This prevents fraudsters from claiming a refund while still attempting to intercept the package.
  • Exercise Caution with Shipping: Develop a strict shipping policy for suspicious orders. Avoid shipping anything with:
    • Mismatched billing/shipping information.
    • AVS (Address Verification Service) or CVV (Card Verification Value) failures.
    • A first-time, high-value order to a new or unfamiliar address.

Fortifying Your BigCommerce Store Against Future Attacks

Proactive measures are your best defense. BigCommerce, combined with strategic app integrations and vigilant practices, offers robust tools to combat card testing fraud.

Leveraging BigCommerce & Payment Gateway Features

Your BigCommerce store and integrated payment gateway provide essential fraud prevention tools:

  • AVS and CVV Verification:1 Ensure these are enabled in your BigCommerce settings and payment gateway configuration. Crucially, configure them to decline on mismatch rather than just flag. This automatically rejects transactions where the billing address or security code doesn't match the card issuer's records.
  • IP Blocking: If you notice repeat fraudulent activity from specific IP addresses or ranges, use your BigCommerce control panel to block them. While fraudsters can change IPs, this can deter persistent attackers.
  • Requiring Customer Accounts: As suggested by Tanner Brodhagen, consider requiring customers to create an account before checkout. While this might slightly increase friction for legitimate buyers, it can significantly deter bot-driven card testing which relies on quick, anonymous transactions.
  • CAPTCHA and Rate Limiting: Implement CAPTCHA challenges during checkout or set rate limits on transactions from a single IP address within a short period. This can slow down or stop automated card testing bots.
  • BigCommerce Fraud Protection: Depending on your BigCommerce plan, you may have access to built-in fraud protection features that analyze order data and provide risk scores. Familiarize yourself with these tools and configure them to your risk tolerance.

Integrating Advanced Fraud Protection Apps

For higher order volumes or more sophisticated fraud patterns, consider integrating a dedicated fraud-screening app from the BigCommerce App Marketplace:

  • Signifyd, NoFraud, Kount: These services offer real-time fraud scoring, leveraging advanced AI and machine learning to evaluate orders. They can automatically hold or decline suspicious transactions before funds are captured, saving you time and money. Many even offer chargeback guarantees.
// Example of a conceptual API call for a fraud screening app
// (This is illustrative and not actual BigCommerce API code)
{
  "order_id": "12345",
  "customer_email": "sophia.moore@gmail.com",
  "billing_address": {
    "name": "Todd Green",
    "street1": "123 Main St",
    "city": "Anytown",
    "state": "CA",
    "zip": "90210"
  },
  "shipping_address": {
    "name": "Todd Green",
    "street1": "456 Oak Ave",
    "city": "Nowhere",
    "state": "NY",
    "zip": "10001"
  },
  "ip_address": "192.168.1.100",
  "payment_status": "captured",
  "fraud_score_threshold": 75 // Example threshold
}

Proactive Monitoring and Review

Regular vigilance is key. Monitor your orders for patterns and anomalies. Regularly review your BigCommerce admin panel for any unfamiliar admin users or API keys, just as a general security best practice, even if card testing isn't usually a sign of store compromise.

Advanced Merchant Strategies: Customer Segmentation

While requiring more setup time, some merchants, like Ken Persson from the forum thread, implement advanced customer segmentation. By categorizing customers (e.g., "Wholesale," "Guest," "Spammer"), you can control access and purchasing capabilities. For instance, a "Spammer" group could be prevented from placing orders entirely, effectively banning problematic users or known fraudsters. This level of customization can be achieved through BigCommerce customer groups and potentially custom development or apps.

Conclusion: Stay Vigilant, Stay Secure

Card testing fraud is a persistent threat in the e-commerce landscape, but it doesn't have to compromise your BigCommerce store's integrity or profitability. By understanding the signs, taking immediate action on suspicious orders, and proactively implementing BigCommerce's built-in features and powerful third-party fraud protection apps, you can significantly reduce your exposure. At Big Migration, we understand the importance of a secure and optimized e-commerce platform. Ensuring your BigCommerce store is fortified against fraud is not just about protecting revenue; it's about building trust and maintaining a seamless experience for your legitimate customers.

Share:

Start with the tools

Explore migration tools

See options, compare methods, and pick the path that fits your store.

Explore migration tools