Practical eCommerce

Manage Subscriptions · Subscribe Now · F.A.Q.'s

HOME · Sunday, May 11, 2008

Shopping Carts & Online Payments

Effective Tools to Detect Stolen Credit Cards, Part 2 Of 3

Telephone and email verfication; different types of geolocation

By: Jennifer D. Meacham
Comments: 5

Many online merchants are already on board with fraud-detection technology. To fill in the gaps, here is part two of a comprehensive list of fraud detection strategies. Previously we discussed authorization and address and credit card verification. Here are five more ways to catch fraudsters in the act.


Telephone verification

The telephone number can be used for several fraud checks. First, the area code can be cross-checked against the address, to see if the two match. "I use WhitePages.com's 'Reverse Lookup' tool for that," says Michelle Rahm, owner of the jewelry selling site JewelryImpressions.com. "It's free and easy."

Phone numbers also can be used by merchant-initiated services such as VariLogiX, PhoneConfirm, StrikeIron and MaxMind to automatically place a call. The person on the other end of the line is given a 4-digit code and then must enter that code into the order form. The payment process can proceed if the correct code is entered. Fraudsters notified of this in advance are likely to ditch the order, rather than have a phone number traceable to them. One merchant using MaxMind said that this service lowered its fraud numbers to "virtually zero." Cost is 5 to 20 cents per automated call.

Finally, a growing group of merchants are picking up the phone themselves, calling customers as a "customer service" before shipping out goods. It's a move that both verifies that the number isn't disconnected or changed (a big red flag if so) and that the person at the other end of the line wants your merchandise (a verification that bolsters a merchant's case in the event of a chargeback).

"Before making the call, take a look at Google Streets or Google Maps," says Ori Eisen, founder and chief innovation officer for Scottsdale, AZ-based 41st Parameter, a fraud detection service. "Ask the person to verify their address, and ensure that you have the nearby cross streets right. The real customer would know the nearest cross streets."

Email verification

Merchants that require a customer's email address on the order form can use this as a peek into the order's legitimacy. Emails from free email service providers, like AOL and Yahoo, or nonexistent websites have a higher chance of being fraudulent, according to several sources. Merchants can type a given email address into Google to come up with associated names, as a side verification.

If the email address matches the card holder's name, email a "thank you for your order." This provides one more link in the paper trail and allows what could be the real-email user a chance contest a fraudulent purchase before it's charged to their card.

IP geolocation

Using data from the customer's Internet provider, this tool can identify the country, city or state where a customer actually placed the online order. Some can check to see if the IP (Internet protocol) address is a proxy, which merely shields the users real IP address.

Country-level tracking is available for free at IP2Nation.com, which provides IP matches as a downloadable sql file. IP2location.com provides city-specific results for as little as $49 per server. IP tracking codes also can be added in the hidden "Environmental Report" field of a merchant's order forms. Form handlers such as FormMail, SendMail and Blat.exe each require different codes; ask for the respective one. Once coded, IP information will be included when each order is submitted.

"The geographic location of a proposed transaction can be a significant indicator of potential fraud, particularly when that location doesn't match the address provided by the customer," says Kerry Langstaff, vice president of marketing for Quova Inc., one of the many IP geolocation providers. She says that 68 percent of orders with registration addresses in one U.S. state with orders placed in another turn out to be fraudulent and that registration addresses from outside the U.S. represent nearly 50 percent of credit-card chargebacks.

Meanwhile, "IP geolocation matching is not going to stop a sophisticated thief, since he's going to hook up with a proxy server in Ohio for an order in Ohio," Clements says. "Now the companies providing those services are having to check for proxy servers." Additionally, IP masking services-like that at RegNow.com for $34 per address-could hide potentially authentic customer's IPs worried about privacy.

Advertisement

Device identification

Services like 41st Parameter will track down the computer source for each order, even going so far as identifying the time zone where an order was placed and the browser language setting on the ordering computer. "We saw attacks that tried to take $500,000 a day from one merchant with the shipment of 42-inch plasma TVs," says Eisen at 41st Parameter, which offers device tracking. "All the data looked perfect, until you looked at time zones and device IDs and browser language settings and realized they were all coming from the same computer. That could take a smaller merchant down."

BIN country matching

The first six digits of a credit card number identify the issuing bank. Known as the issuer or bank identification number, IIN or BIN, the six numbers can be entered into free BIN lookup tools like that at BINdatabase.com or subscription tools like MaxMind's minFraud to get the name of the bank and its location. Rule of thumb: If the bank is in one country, the order should be coming from the same. JetPay.com even offers BIN blocking, automatically blocking settlements based on BIN or country.

Stay tuned in the coming weeks for more real-time fraud detection and prevention strategies.

Blinklist | Del.icio.us | Furl | Ma.gnolia | Newsvine | Spurl | Reddit | Technorati

Published on Monday, May 05, 2008

Comments:

BINdatabase.com is no longer online. MasterCard forced them to shut down.

Posted by: Will
Wednesday, April 30, 2008

MaxMind also offers a fraud tool based with IP geolocation and proxy detection. We use that in conjunction with telephone verification.

Posted by: Dave
Thursday, May 01, 2008

Thank you Will for pointing out that BINdatabase.com is no longer online. I talked to the company point person, and he confirmed your information. Another BIN lookup tool can be found at mars-soft.net/banksbase.htm.

Meanwhile, thank you Dave for sharing your strategy on integrating the various fraud detection tools, from phone verification to IP geolocation, into your order-taking process.

Posted by: Jennifer D. Meacham
Monday, May 05, 2008

ah, much better content this go around, thanks for the info...

Posted by: Tai Kahn
Tuesday, May 06, 2008

Thank you for stopping back by Tai. My pleasure...

Posted by: Jennifer D. Meacham
Thursday, May 08, 2008

↑ Back to Top

Leave a comment:

Please enter the following security code exactly as it appears.


Comments are stripped of HTML code upon submission. All comments are submitted for approval prior to being published. Please allow up to 24 hours for the approval process to take place. Practical eCommerce reserves the right to remove any comment at any time for any reason.

 


Related Articles

Articles at Practical eCommerce related to Effective Tools to Detect Stolen Credit Cards, Part 2 Of 3:

Related Podcasts

Podcasts at Practical eCommerce related to Effective Tools to Detect Stolen Credit Cards, Part 2 Of 3:

RSS 2.0 Feeds

Atom 1.0 Feeds

Technorati Tags

Ecommerce Articles

Browse All Articles
Browse our complete archive of ecommerce articles.
Accounting, Management & Legal
Ecommerce articles related to managing a small business including ecommerce accounting, business strategy and legal considerations.
Conversion & Usability
Online business articles about converting web site visitors into customers and how to gauge and improve your business website's usability.
Development & Programming
Articles to help designers, developers and programmers create successful, search engine friendly ecommerce websites and improve existing ones.
Hosting, Infrastructure & Software
Articles for ecommerce businesses about ecommerce web hosting, business infrastructure, business strategy and helpful ecommerce & small business software.
Interviews & Profiles
Interviews with prominent ecommerce business personalities and profiles of successful online businesses.
Inventory & Shipping
Ecommerce articles about inventory management, ecommerce order fulfillment and product shipping considerations.
Marketing & Revenue Growth
Articles relating to online marketing, email marketing and using the Internet to growing your business.
Search Engine Optimization
Search engine optimization articles for ecommerce business owners, strategists, marketers and developers.
Shopping Carts & Online Payments
Articles covering ecommerce shopping cart platforms and options for choosing an online payment gateway.
Training & Education
Tutorials and articles providing training and education for ecommerce business owners and developers of ecommerce websites.

Search Articles

Ecommerce Community

Ecommerce Blogs
Read our blogs about ecommerce topics written by industry professionals.
Community Forum
Connect with other ecommerce professionals to trade advice and answers in our community forum.
Podcasts
Check out our ecommerce podcasts covering topics ranging from interviews to tutorials.
RSS Content Feeds
Subscribe to our RSS feeds and have fresh ecommerce content delivered to you.

Ecommerce Resources

Free Email Newsletter
Sign up for Ecommerce Notes, our free email newsletter for ecommerce business owners and developers.
Ecommerce Directory
Browse our directory of ecommerce products and services, or submit your own listing in our directory.
Ecommerce Glossary
Familiarize yourself with terminology or submit terms to help others with our Ecommerce Glossary.
Events Calendar
Find out about upcoming ecommerce events or invite other ecommerce professionals by posting your own event.
Press Releases
Browse ecommerce related press releases and post your own press release for distribution.
Ecommerce Store & Back Issues
Pick up back issues of Practical eCommerce magazine along with other merchandise from Practical Ecommerce

About Practical eCommerce

Frequently Asked Questions
Look at frequently asked questions regarded using our website, subscribing to our magazine and more.
Advertising Information
Information about advertising in Practical eCommerce magazine, on our website, or in our email newsletters.
Editorial Sharing
Learn about options for sharing our content with your visitors, customers or employees.
About Us
Learn more about Practical Ecommerce magazine and meet our staff.
Contact Us
Contact Practical Ecommerce at any time for more information. We'd love to hear from you.
AdvertisementClearCartArial Software

Copyright 2007 Confluence Distribution, Inc. and Practical eCommerce.
All Rights Reserved.

Privacy PolicyConditions of UseContact Us