The problem with fraud apart from it being absolutely dispicable is the fact that it’s happening right under people’s noses and they’re not doing the simple things needed to prevent it. It’s the ecommerce equivalent of having a stranger look after your wallet for 5 mins and not checking that the £50 still in there when you get it back.
A fraudulent transaction on your Magento store can instantly leave merchants tens of thousands of pounds out of pocket, which in some cases could leave them in dire straits. It’s something that should be protected against in every way possible. As well as extra vigilance when handling orders there are also some useful tools that you can install into your Magento site to help combat against fraud. Below are a few tips to watch out for…
The most common targets for fraud are your most expensive items. If your AOV is about £40, then you suddenly get a £4,000 order, get it fully checked out first! Another thing to watch out for is large quantities of the same product being ordered. If someone is trying to order 30 bluray home cinema players for delivery to China, alarm bells should be ringing.
This counts double if you don’t normally ship to other countries. If you’re a UK store and the order is carried out in Tokyo and to be delivered to Kansas – you’d be foolish not to find that suspicious.
If you’re contacted before an order is placed you’ll often find the email will be badly written and will mention their availability for payment, which is not something that customers traditionally come forward with.
If the customer has paid a £90 delivery charge for the next day delivery of a hot tub, it’s fair to question why someone would need it so quickly – unless the delivery address is Hugh Hefner’s mansion. Also if your courier finds that the customer is not home when they deliver the item, they usually leave a pickup slip. This is another common methods used by fraudsters because they can collect the goods away from the property in question.
Now that you’re going to be much more vigilant with your orders, why not go a bit further and use the following extensions and payment gateways to get yourself better protected.
What BlockThatProxy does is it monitors the customers checking out on your store. It requires a paid subscription, but you get a lot of tools for your money. Firstly it will email to warn you if someone is ordering from a proxy or a blacklisted IP address. You also have the option to add a separate order confirmation page for suspicious customers – this means that you can force them to confirm their order.
http://www.magentocommerce.com/magento-connect/Wickings/extension/4560/blockthatproxy

This extension is a simple one, using GeoIP it can block products from being sold in certain countries based on your very own Access Control List. This eliminates one of the biggest causes, as mentioned earlier – international fraud. Got a problem with fraudulent transactions in France? Unlike the England rugby team, you can block France’s access.
http://www.fmeextensions.com/extensions/catalog/geoip-country-lock-products.html
We all like scoring stuff – when I read videogame reviews I go straight to the rating and very rarely read the writeup. Not reading the fine details is probably why I end up with a bunch of games I never complete. Directshop Solutions have come up with an excellent extension which provides each order with a score out of 100. The higher the score, the more issues the order has with fraud and therefore the more your concern should be raised. It allows you to control the risk limits and even to block IP addresses.
You have to sign up for a Maxmind account to use this extension, but the extension itself is relatively cheap.
http://www.magentocommerce.com/magento-connect/Directshop/extension/1394/directshop_fraudscreening_featuring_maxmind
All respectable payment gateway providers will now be signed up with 3D secure, an extra level of security which can be enforced during checkout. Not only does it require a password from customers, but it matches the Postcode and CV2 number. An absolutely essential addition to your checkout.
Ebizmarts and Sage Pay have integrated it into their gateway to perfection.

It’s not as if we’re trying to prevent the events of Die Hard 4.0, it’s just a few common sense steps that will ensure that your store will never be a victim of fraud. If you follow all the advice listed above you’ll be fine. My personal recommendation is BlockThatProxy combined with 3D Secure – that along with being extra vigilant will be enough (Bruce Willis not required).
If you know of any further solutions to this issue, please let me know in the comments. Hope this has been helpful, thanks for reading the Magento Blog at E-commerce Website Design.
Adam Moss Author Page
View the original article here