• Dan

    (@gtsclothing)


    Hey – I’m hoping someone may be able to point me towards a solution here… Here’s some context into what I have going on:

    It seems my site has been targeted by a group of people who complete purchases through my website using what I assume to be stolen credit cards, and they always put their shipping address as somewhere in Miami, Florida. They use fake emails that are always different, random names that are sometimes just “aahhhhhhddddjjjj” and things like that. We NEVER ship their orders out, and sometimes they’ll place 10-20 orders within a half hour or so, usually with different names, emails, and Miami addresses used throughout. I’ve tried blocking IP addresses, but it seems very easy for them to use another one to bypass the block. The payments go through, but we always mark the payment with a custom order status of “Suspicious Payment” and refund the payment source. When I track the IP address it’s from places all over the world – Thailand, South America, other random countries, when I sell men’s and women’s yoga clothing and activewear inside the US. It’s very easy to tell that these are spam/fraud orders, but they’re real people putting them through.

    How can I put a stop to this!!! I’m sick of it and it’s really getting out of hand. I’ve installed plugins to monitor the problem but haven’t found a solution to actually STOP them from coming through. I can’t blacklist emails or addresses because they’re always new and fake and they tweak single letters, etc to bypass. Is there any way to permanently block this type of order from going through?! All help is appreciated.

    Thanks for your time.

Viewing 5 replies - 1 through 5 (of 5 total)
  • Hello Dan;

    That’s a tough issue to deal with. I’ve seen similar before, and I don’t really have any solid solutions for you, but maybe if I throw some ideas around it will help.

    Many times when dealing with these type of issues it can become a burden on your own customer base while trying to solve them. If your allowing guest checkout, you may need to temporarily disable it. And from there facilitate a email verification system. Make any new registrants verify their email before they can login.

    It makes it a pain for your primary customers, but after a month or so you can try disabling the verification check. By the time the frauds will probably have found a new target.

    • This reply was modified 9 years, 6 months ago by GLWalker.
    Thread Starter Dan

    (@gtsclothing)

    That’s a very helpful solution that I haven’t tried yet! Do you know if the verification process is customizable? This isn’t exactly related to the spam orders, but it relates to the guest checkout. Is it possible to change the level of requirements for creating a new username and password? Right now the “strength checker” seems to be pretty strict and users have to struggle to come up with a combo that pleases the system. Just a thought.

    Thanks for trying to help me through this.

    Thread Starter Dan

    (@gtsclothing)

    Actually… I already had guest checkout disabled, so these spam people are actually creating accounts with what seem to be real email addresses? I’m not sure if the regular account setup has them verify their account via their email address – or does it?

    We really don’t know if they’re actually creating email addresses to go along with orders, but if so, maybe they are not into checking them and verifying their account.

    I was thinking along the lines of using a plugin similar to this: https://wordpress.org/plugins/woo-confirmation-email/ or this: https://wordpress.org/plugins/miniorange-otp-verification/

    Then they have to click that verification link in the email in order to gain acess to your site to complete an order.

    Only manual check can help, stupid gangs sometimes target some websites but give up soon because all their orders always are canceled. No wonder where these gangs are located and/or where they come from…

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Massive fraud/spam problem’ is closed to new replies.