Merchant + payment behavior

Lord777

Professional
Messages
2,580
Reputation
15
Reaction score
1,332
Points
113
How do you guess what merch is in the store? builtwith? Not relevant!

See the source code? Or maybe you add it to your shopping cart and view its interface?

Hm. As an option. The shopping cart interface seems to be Authorize.net.

One, two, driving, payment... Damn... This is Shopify.. How much time did I spend on this fucking shop?!

Yes, in essence, builtwith can help, if the shop does not use a shopping cart, scoring and merch from different developers.

Otherwise, it will show shopping carts in the desired E-Commerce developer window. What is closer, then it will glow. In fact, there may be a shopify or pp, and a basket of bigkimmers, which it will show.

And so. Let's look at these very ones.. Merchants.

At the moment, I select for myself the most widespread ready-made solutions. Not including self-written ones:

  • Shopify:
This merchant is truly the most advanced and toughest in relation to fraud.

Out of the box, it has a bunch of systems visualized in the admin panel, an org-based database of templates for interface development, several options for free shopping maps + paid ones, Chuev Valley of plug-in scoring and AF plugins named+from third-party developers and third-party merchants.

The store manager or online verification department receives notifications in the admin panel about how many users are currently surfing, what each of them is looking at, what actions they are performing, and all the user data.

Starting from the standard type of IP, OS version, location, services, and so on, ending with clicks, product viewed, time spent on each action, and so on.

In general, absolutely EVERYTHING you do.

In ONLINE mode, verif can analyze your data already at the stage of filling it out.

For example, you can check whether there were orders from this IP address and data such as audio and finger prints, shared webrtc, and so on, which replaces Linken Sphere.

In online mode, scoring tools and AF calculate your rating, giving graphical indicators to the manager about who is on the other side of the monitor. As a rule, he is not mistaken.

If you consider that SHOPIFY is not only a completely ready-made solution for hosting a shop that works out of the box without requiring any additional intervention, but also the most secure supplier, let's look at the points of its detection methods:

1. Checking the e-mail address using its own database and the database of partner merchandise for the number of orders with calculating the probability of a fraudulent transaction based on past data. If there are no orders from this email address in any merch, this is already a minus in scoring

2. Checking the distance between the shipping and billing address


3. Checking the exact AVS match by billing

4. Receipt for finding the inserted card in the black lists


5. Scoring based on the analysis of data transmitted by the browser for a match or discrepancy.

6. Distance between ip geolocation, shipping and billing address + geolocation from the browser

7. The IP address belongs to a fixed-line or mobile Internet provider

8. Checking behavioral activity in the store and comparing data with the massive amount of information provided by partner scoring systems


9. Analysis of traffic, depth, and number of clicks.

  • Authorize.net
Honestly, I don't even know what to write about it.

The easiest merchant gateway in terms of driving in.

It has almost no plug-in solutions from third-party developers.

Everything that it uses to filter out fraudulent transactions:

  1. Checking for an ABC match
  2. Checking the distance between the IP and the holder
  3. Blacks on the IP and a check of past orders if there were any from this IP
  4. Holder's receipt for past charges, payment behavior, and tranzactions based on card data
  5. Public Records phone number receipt in automatic mode
  6. receipt for the bean belonging to the country where the purchase is made.
The rest of what the merchant uses doesn't bother us in any way!

The most important and interesting thing is that the autorayz instantly writes off the money from the card after the approve, which is good for us.

You don't need to worry about whether there is money on the card or whether the limits are worth it. If the order passed, then the cache was debited to the merchant's side.

But, you should not relax. An autorayz can be used as a payment solution, but the shopping cart and scoring can be used by Shopify. So, do not be happy immediately seeing such a plaque.

  • Big Commerce & Woo-Commerce
Digital merchants are essentially almost the same.

They use the same solutions, but they only differ in the interface.

Own funds are absolutely not effective, and at the time of December 2022, you can still find small shops with a template interface that do not use absolutely any scoring and third-party AF solutions, but trust completely the bottom protection of the subject at the checkout stage.

All they can do is:

  1. Checking the AVS
  2. Distance between the IP and the holder
  3. Scoring by humanization parameters
  4. Receipt of the entered information in public records
At first glance - nothing complicated.

But, shops that trust these e-commerce providers can be counted on the fingers of one hand.

Built-in support for third-party plugins gives a huge advantage in working with these algorithms.

Returning to shopify, we can apply all the detection parameters to Big and Voo - commerce.

By clicking on the link, you can view all available solutions for countering fraud.

The same plugins are easily attached to the first merch from our top - SHOPIFY.

I won't duplicate the detection methods, as they are identical to the first option.


And so. Actually, the considered 4 merchants are the most widespread when driving in the United States.

From all of the above, I want to summarize a little.

No matter what merchant or payment gateway is used in the store, never ignore the rules for successful embedding. You never know for sure which developer's scoring system is following you at the moment.

If your payment failed, but your card is 100% valid, it only means that you have accumulated too many fraudballs. With the exception of a small number of cases when the bank simply rejected the transfer or limited the card.

YOU can'T kill the card by entering it correctly, just as you can't limit it(this applies if the payment behavior matches and the card has a sufficient balance). If the card is blocked or sent to the froud dept after the checkout, it means that the payment gateway has sent information to the bank that the transaction is fraudulent. If the order passed but later received a ticket, it only means that in this store all orders are verified manually!

Thanks for attention. The topic with merchants was closed. Let's move on.

Payment behavior​


It will be short, but to the point

Friends, do you know that "using the phone" in our work is synonymous with the word "increase the chances of success"?

By purchasing a subscription to the service with caller ID substitution , you save money on bank cards and increase your profit.

There is such a belief that you can buy a card of the highest class and successfully drive a Rolex watch for $ 100,000. Even if there is a balance of $ 1,000,000, the bank can block the card.

Did you ever have such a thing that when you drove in an amount of $ 1,000 , you were refused at the premium level of the card? But, having driven in another place a gift for $ 100-everything went smoothly as clockwork. The question is, why? There is also a balance of 10 thousand green cards...

Initially, I will point out that the bank and the shop do not care about you. They don't care how old you are, that you order an Xbox or a radio-controlled helicopter in your 90s with a ponytail.

It makes absolutely no difference to the store what the order amount is. The main thing is to have money on the card and successfully pass auto-manual verification + scoring and AF.

What is important and why don't orders for high amounts pass? What to do? After all, I bought an infinity level card:

Together with a card of any level, you simply have to top up your account in the number substitution service and break through the ssn-dob of the holder.

What for? We will call the bank before EACH drive-in.

Let's say the situation.

The card was purchased. Holder Mr. Johnson Smith

Johnson uses this Premium-level card to make purchases exclusively online, pay monthly fees of less than $ 200, and pay for online games.

Average Johnson card usage = $ 1,000 per month.

Naturally, we don't know about this. We did great, bought a map, saw the goal and go to achieve it. Warming up, filling in data, in the basket is an item for $ 2000. Checkout-dekline. To hell with it, I didn't pass the AF, we think.

The second shop, as always, gives you the golden key. Warming up more time, filling in data, in the basket is an item for 1300 dollars. Checkout-dekline.... What the hell?.. Card receipt, the card is live...

Double three and the bank already blocks the card on suspicion of fraud. Naturally, in an hour, several tranches online for large amounts.

Or vice versa, take three, driving a sneaker on a great bill spike worth 200 bucks and track in a couple of hours at the post office.

What went wrong? Maybe there isn't enough money on your balance? How do I avoid this mess?

This is where a phone number substitution call comes to our aid.

In the vast majority of large and small banks, in order to find out the balance and history of recent transactions, you just need to call from the billing number and dial the card number and ZIP code in tone mode.

In some cases, you will need an SSN and-or DOB. In very rare cases, you will need to talk to the operator in person or provide an answer to a secret question or enter a pin code.

We call the bank's number, which we find in advance on the Internet for the request "%bankname% balance check phone number " We get to the automated system and follow the instructions. Enter the card number and let's assume a ZIP code. Iviar tells us the current balance of your own funds and credit limit(if any).

Hmm.. Johnson's map has more than 30,000 totals. The balance is good. Why do declines fly?

Really antifraud did not pass..? Set up something wrong..?

No!

In tone mode, click the number that the transaction history is linked to (listen to iviar).

This is where we understand when they list us the history of spending that the holder does not have transactions for large amounts.

As much as possible, we hear write-offs of $ 200-300 per transaction.

Although we do not have a complete understanding of the picture, since only the last 5-10-20 tranches are automatically issued(depending on the bank), we can still assume how much the holder spends on average per month.

And if we hear on the last 5 transits that:

June 3 spending 150 dollars

June 12 spending 3 dollars

June 21 spending $ 230

June 23rd spending 25 dollars

June 30 spending $ 100


So, we can make the most accurate conclusion that holder's expenses for the last month are less than $ 1,000.

This means that the bank will automatically block a transaction for a one-time purchase for an amount higher than the AVERAGE monthly spend. Something like this.

Naturally, if the amount of debits is $ 1,000 per month in small transactions on the holder's card, the bank simply will not allow you to make a one-time purchase for an amount several times higher.

This is not a typical payment behavior, but a suspected fraud. The average holder will call the bank and warn you about such a large payment.

In the best case scenario, the bank will simply refuse to pay you and the gateway will issue a decline.

In the worst case scenario, the card will fly away to fraud(you can pull it out) or it will be blocked with a forced re-issue.

Now we know what to do and we do it beautifully.

Purchased a signa-level Ms. Julia Montana card

We call the bank and enter the data into the automated system.

Checking the balance. Let's say it is 15,000 own funds.

We listen to the transaction history, which tells us that:

June 16 spending 3,200

18 waste 700

26 waste 2500

27 waste 460

30 waste 1600


Based on the data obtained, we conclude that a transaction of 2000-2500 dollars will not be a surprise for the bank. And already at 100-200, even more so.

We go to the shop, warm up, drive in the information, in the basket there is an item for 2000, the checkout order has passed.

We are waiting for a couple of hours, the track is in the mail, so everything is done beautifully!)))

You're the best!

If you have a complex drive - in for a huge amount and need a detailed analysis of information-go to the bank's website and make a rollout.

If the bank gives you the opportunity, then make a guest one. Less than palev, alerts will not be sent to the holder and the bank will not send the acc for verification.

Who owns information-owns the world...... and makes progress!
 
Top