Card Testing
Hi All,
We've just gone through a major issue with Card Testing. This is where hackers use scripts to verify stolen or generated Credit Card numbers through a donation link. We've had more than 10K of these types of charge attempts.
Generally, these donations are at the $1 mark because it flys below most people's radar.
Since there are no docs yet about this by Foundant, I will suggest that you set your minimum donation amount to $10. This will at least stop most of the $1 card testing scripts.
Foundant has some security features in place, but at times they appear not to be working. They are supposed to stop a certain number of charges to the same IP address. I think they said after 5 attempts.
They are also using Google ReCAPTCHA on the donation pages. Though, that did not appear to stop these $1 charges. Hackers are always one step ahead of security.
If you are using Stripe as your payment processor, their radar system does catch most of these charges and cancels them.
These charges can be damaging to your Foundations and should be taken seriously. Foundant seems to be taking card testing seriously, but they currently do not have any documentation about it. I've asked that they add documentation to the site about this.
Keep an eye on your Stripe account.
https://www.cybersource.com/en-us/blog/2020/what-you-need-to-know-about-card-testing-fraud.html
Comments
@hankdrew Thanks for the heads up. I'll be more diligent about checking stripe.
Bettie
Bettie Stammerjohn
Executive Director
Community Foundation of Greene County, Pennsylvania
Hi Hank,
Thanks for the email and conversations around what you're seeing with Stripe. Below are the security protocols we have in place today on the donation portal. These are in direct alignment with recommendations from Stripe as well, see documentation from Stripe here https://stripe.com/docs/card-testing#mitigations.
Online tools that accept credit cards deal with bot activity constantly. Bots are built to do a few different things depending on why they were created. This can range from testing a list of stolen credit card numbers, to a competitive analysis firm using bots to test competitors functionality.
If there are additional questions, please let me know! (grant.elliott@foundant.com)
Thanks @GrantElliott. It's been nice working with you on this.