Hello fellow hackers!
I've run into an unfortunate situation where a bad customer, probably using a stolen credit card, has triggered dozens of chargeback requests in one day. We had no way of knowing beforehand but that will still cost us $350+ in refunds and penalties. We price a fairly low amount/month ($9), so this stings even more.
I guess we don't have many options but to accept the chargebacks and move on... But that made me think. What if someone wanted to leverage this mechanism to hurt your company? It feels pretty easy:
Do you think this is a legitimate threat? It definitely applies to products and services retailing for a small price even more, but I could see it being applied anywhere. We have pretty aggressive competitors in our market, and I wouldn't be surprised if anyone had this idea.
Are you guys doing anything to tackle this? 🙇♂️
Really sorry. I unfortunately have no insight or advice.
But what happened to you is why I don't share the Gamestop euphoria. Today this happened to Wall Street, which doesn't have many friends. But tomorrow indies may be the targets of coordinated, possibly malicious action.
Interesting perspective. I think it depends a bit on your business model and how its received. I dont think most products can be viewed the same way as taking massive shorts to undermine another company.
Beyond the specifics of what happened with Gamestop, my concern is coordinated action led by the kind of bad actors with the disinformation tactics we saw on social. Such action might target any business.
You pay chargeback... twice the amount of the charge?! $15 on top the original $9? sounds like a bad deal.
Yup, crazy right? But that's industry standard... https://stripe.com/docs/disputes
if that is the case... then yes. anyone could completely obliterate small-medium businesses, especially ones with really cheap products.
you wouldn't even have to go as far as you described. you could use your own card and claim it was stolen. either way what we mention is illegal, but as uncommon as it seems it is disturbing. perhaps some insurance covers something like this?
Sorry for you, that happens to me also years ago.
Now, I activate stripe protection and paypal protection , with the rules : credit card owner should have the same country than the IP.
It's working good, but it's not perfect.
is paypal protection a thing that can be activated? hate paypal interface, how do I enable that too?
Both needs to be activate because not free :
-Paypal : payflow gateway fraud protection
-Stripe : stripe radar
This happened at my previous job.
I checked the dashboard one morning and there was about 100 times more new customers than usual. All with fishy email addresses that looked alike. Most of the credit cards failed.
It ended up costing nothing because we offered a 7 day free trial, meaning no one was charged and no refund was needed.
Then it happened again, so we added a re-captcha in the checkout flow and it solved the problem.
However, a re-captcha in the checkout means more friction in the checkout and there are services to do re-captcha nowadays. Sometimes they'll use humans in third world countries to do the clicking (imagine the dread of going to work to solve captchas all day...).
Yeah, I'd definitely not want to have a captcha at checkout... Some other people in the thread suggested upgrading to Stripe Radar, which could do the trick.
You need to add IP based restrictions. If someone try multiple cards from same location then it gets blocked.
Yep, that's a good idea. I'll add that!
I've read an article about similar fraud where a charity company that relies on online donations was swamped with $50,000 in overnight donations with small amounts like $5.
What they had to do is to manually refund as many transactions as they humanly could. There is no bulk option on Stripe to do it all at once (over 3,000 transactions). However, they could get a hold of someone on Stripe (level two support) and were able to refund everyone.
The good part, not every user would notice a small charge on their credit card. The chances are they will go unnoticed and won't file for chargeback. So you potentially will keep the money to offset your $15 Stripe penalty fees. But this is a cruel example.
Just try to refund everything as fast as you noticed it.
Interesting story! Thanks for sharing, Alex.
I'm still unsure about how to manually catch those cases ; Maybe I should review every paying customer manually, but for high volume + small amounts, that feels like a pretty big lift. Also, I don't really want to invest in stricter payment rules (enforcing the IP location matching with CC, document verification, etc..) because I already see how this will fuck up the UX for legit customers... Any ideas?
Just look for large increases in short amount of time.
When criminals test stolen credit cards, they do it quickly in a short amount of time. They pick a prey a website like yours and bulk upload payments.
If you see these patterns, analyze them by yourself and make a decision. There is no replacement for human. Even darn PayPal and Stripe employ tons of monkeys to review all suspicious transactions. Peter Thiel talked about it in his book that no automated tools are good enough.
Yes, that makes a lot of sense! Thanks a lot, I'll add something like this!
Anyone know how Paddle handles this (vs. Stripe)?
Hey, what protections do you have on your site. I think you might want to put use something like recaptcha on your checkout page to make sure your not being spammed.
I would have thought payment services like stripe would do spam protection as well though.
What payment provider are you using.
Wait, you have to pay money for a chargeback? Is this normal Stripe practice?
EDIT: I saw the other replies, thanks for the info, I never encountered fees for chargebacks with other payment providers.
There is also a scam way to find out what is the PIN to cc:
scammers register at many different merchants
and try brut force PIN.
wouldn't Strong Customer Authentication (SCA) prevent this?
We have SCA turned on! We have no choice anyway because we are processing payments from European customers (and we're based in Europe ourselves..). I guess the fraudster has managed to fill this or has provided enough valid information to fool Stripe into bypassing the SCA step completely.
Just turned on Stripe Radar and tightened the rules around which payments are forced to use SCA. If you don't have it, then it's up to Stripe to decide...
It does seem like a legitimate problem, thanks for bringing it up here. But I have couple of questions as I don't use Stripe.
Doesn't Stripe ask your side of the reason for processing chargeback? Because PayPal document says they do.
How come the original owners of all the supposed stolen cards detect fraud at the same time(transactions in your twitter image)? Only possibility I can think of is that the credit card company itself catching a load of its cards on the dark web and initiating chargeback?
What does the scammer do with buying these many subscription of your service, I saw that you run an email forwarder and that 1000 domains are available for $49 plan/month; Considering even if the scammer does use your service for further scams/spams how many subscriptions would *they need?(Btw, I hope already have the domains associated with the scammers).
Finally just for Occam's razor,
4. Did you check your end for a possible bug which could have caused a double charge for your customers and that these chargebacks are from genuine customers?
Hey Abishek!
You can definitely respond to the claim but to be honest, this is not worth it. Simply investigating the cases properly and documenting them so that we have a tiny chance to get this resolved in our favor is just not worth the money. Also, I'm pretty sure this guy used stolen credit cards, so it's definitely right that the poor legitimate owners of the card get their money back. It's just crazy you have to pay those penalty fees for each chargeback...
I agree with you, I guess the bank just identified a pattern and issued a bulk chargeback request to Stripe. Not sure as I'm not familiar with the mechanics here, but that seems realistic.
I also doubled check, not a bug from our side, no double payments either, but yes, that could also have been a thing, thx for pointing!
All in all, I'm just pissed at the way this is engineered. Banks are getting tons of $ doing nothing at all... I'll subscribe to Stripe's radar chargeback protection from now on (0.4% per transaction) but argh, that's a bad pill to swallow.
Have you identified the domains associated with the scammer? If so why not file a police complaint?
Hmmm, that seems to be a lot of energy lost for an almost zero return. Any experience?
Depends upon how much you've lost, the thing is something doesn't add up; What does the scammer do with so much subscription of an email forwarder? What if it's a targeted attack by a competitor?
Yep, absolutely! It could be a competitor, although I would rather think that the attacker wanted to take advantage of our SMTP server to be able to send spam/phishing/whatever from all of his account. We've added manual flagging and verification of suspicious accounts + Stripe Radar since Saturday. Hope it helps!
I've seen Stripe talk about this before and it's basically not up to them. You can submit all the evidence you want, but it's up to the bank to decide whether a fraud has occured - and they always side with their customer.
Stripe also introduced chargeback protection (which looks like it's been integrated into Radar now) - https://stripe.com/blog/chargeback-protection
Also, Edwin Wee at Stripe is super easy to contact if you want to talk it through.
Have you enabled Stripe "Radar"?
In our experience, Stripe "Radar" is good, but not perfect. We had a similar spate of stolen cards used to sign up last December. We actually picked up a lot of them ourselves and cancelled the subscription, but we still got hit with penalty fees when the original card owner filed a dispute.
Looking at the Stripe dashboard, there was evidence of multiple attempts with different credit cards, correctly rejected by Stripe, before they used one that even foiled "Radar" and got through. It is my opinion that in these cases, when the charge is disputed, Stripe should be the one bearing the costs as their "Radar" product was the one that failed, not us.
However, we will put layers of protection ourselves to try and pick up what "Radar" misses, including email verification via ZeroBounce - it is amazing how many fraud attempts use fake non existent emails. For those that do use a real 'stolen' email, we now also send a "Are you sure it was you who subscribed" email to them to double check.
We had something like 3 chargebacks in 3 years, so didn't think it was a problem that needed to be fixed. I looked into it and it seems to be solving exactly this, although I must admit that I'm a bit disappointed that Stripe is not offering this by default with their core product. Just charge more, and make Radar + chargeback protection work for everyone...
I have enabled it for the future, but definitely hoped to have known earlier... :( If I recall correctly, the fraud detection part used to be free and bundled in.