Tackling Card Testing Attacks on BigCommerce with Braintree: Unanswered Security Questions

A Merchant's Urgent Call for Security Clarity

The digital storefront, while offering unparalleled reach, also presents new vulnerabilities. A recent forum post from a BigCommerce merchant, Mr Smurfboard, brought to light a critical security concern: a card testing attack. This insidious form of fraud involves bots rapidly cycling through stolen credit card numbers, attempting small, identical transactions through an e-commerce checkout. The goal is to validate the stolen card numbers for future, larger fraudulent purchases, often leaving the merchant to bear the brunt of chargebacks and processing fees.

In response to this attack, the merchant took immediate, commendable steps: enabling AVS (Address Verification Service) and CVV (Card Verification Value) rejection rules within their Braintree control panel, and activating reCAPTCHA in their BigCommerce store settings. However, these initial defenses raised deeper questions about the actual efficacy and scope of BigCommerce's built-in security features when integrated with payment gateways like Braintree.

Unpacking the Critical Questions for BigCommerce & Braintree Users

The core of the merchant's concern, and what makes this thread highly relevant for the BigCommerce community, lies in three pivotal questions that delve into the technical underpinnings of the platform's security architecture:

  • BigCommerce + Braintree Integration: Hosted Fields vs. Direct API Endpoints?

    A primary concern is whether the standard BigCommerce and Braintree integration utilizes secure, hosted fields for payment input, which are designed to protect sensitive card data and often include bot protection. Alternatively, the merchant questioned if there's a direct payment/checkout API endpoint that bots could exploit. Such an endpoint, if accessible without rendering the full storefront checkout page, could potentially bypass any reCAPTCHA or other client-side bot protections, leaving the store vulnerable.

  • reCAPTCHA Scope: Does it Cover the Payment Step?

    The merchant activated reCAPTCHA in their BigCommerce store settings, a common and effective tool against bots. However, the crucial ambiguity is whether this reCAPTCHA toggle applies universally across the entire checkout flow, specifically to the final payment submission step, or if its coverage is limited to other areas like login pages and contact forms. This distinction is vital for understanding the true extent of bot protection at the most critical point of a transaction.

  • Rate Limiting/Velocity Controls: Native BigCommerce or External Solutions?

    Card testing attacks are characterized by a high volume of rapid, repeated transaction attempts. This makes rate limiting or velocity controls – mechanisms that restrict the number of payment attempts per IP address or session within a given timeframe – an essential defense. The merchant inquired whether BigCommerce offers native capabilities for such controls on checkout attempts or if merchants are solely reliant on external solutions like Cloudflare to implement these crucial safeguards.

Even without direct replies in the forum thread, these questions serve as a critical alert and a call for clarity for all BigCommerce merchants utilizing Braintree or similar payment gateways. They highlight the necessity for a deep understanding of how BigCommerce's security features integrate with third-party services and where the responsibility for layered fraud prevention ultimately lies. Proactive steps like AVS/CVV and reCAPTCHA are good starting points, but true peace of mind, especially in the face of sophisticated bot attacks, comes from knowing the full scope of your platform's defenses and identifying any potential blind spots.

Start with the tools

Explore migration tools

See options, compare methods, and pick the path that fits your store.

Explore migration tools