Title: Carding Attacks
Last modified: August 30, 2024

---

# Carding Attacks

 *  Resolved [joshparkagw](https://wordpress.org/support/users/joshparkagw/)
 * (@joshparkagw)
 * [1 year, 11 months ago](https://wordpress.org/support/topic/carding-attacks/)
 * Has anyone else recently got hit with a massive amount of carding attacks? 
   I
   have recaptcha enabled on all the sites I’m using but they’re still somehow getting
   past.

Viewing 6 replies - 1 through 6 (of 6 total)

 *  Plugin Author [Clayton R](https://wordpress.org/support/users/mrclayton/)
 * (@mrclayton)
 * [1 year, 11 months ago](https://wordpress.org/support/topic/carding-attacks/#post-17986067)
    1. Are actual WooCommerce orders being generated?
    2. What’s the Braintree API request for these card requests?
 * Carding attacks are part of operating an online business. Make sure you have 
   advanced fraud tools enabled. The answers to 1) and 2) will help me better understand
   the source of your specific carding attack.
 * Thanks
 *  [Dominik Traskowski](https://wordpress.org/support/users/ones/)
 * (@ones)
 * [1 year, 11 months ago](https://wordpress.org/support/topic/carding-attacks/#post-17990946)
    1. Braintree use some javascript on checkout that which allows you to bypass the
       captcha
    2. We enable advanced fraud tools and we got the same problem
    3. Actual order being generated
 * We’ve got the same problem, we’ve got the captcha, we change the braintree plugin
   that need to first check captcha and then 3d secure is generated. But somehow
   they bypass that.
 * The plugin should, in my opinion, use the standard wordpress functions to check
   captcha and unfortunately this is not how it works. I don’t know if this is only
   the case with 3d secure or always. In this respect it is a total bummer, the 
   developers of the plugin should integrate captcha on their own in this case.
 *  Plugin Author [Clayton R](https://wordpress.org/support/users/mrclayton/)
 * (@mrclayton)
 * [1 year, 11 months ago](https://wordpress.org/support/topic/carding-attacks/#post-17991930)
 * > Braintree use some javascript on checkout that which allows you to bypass the
   > captcha
 * Examples please?
 * > The plugin should, in my opinion, use the standard wordpress functions to check
   > captcha and unfortunately this is not how it works.
 * What standard WordPress functions are you referring to exactly?
 * > the developers of the plugin should integrate captcha on their own in this 
   > case.
 * If your 3rd party recaptcha plugin is being bypassed, what makes you think adding
   our own custom solution would somehow resolve that? Can you provide an explanation
   of how your current recaptcha plugin is being bypassed?
 *  [Trinitech](https://wordpress.org/support/users/trinitech/)
 * (@trinitech)
 * [1 year, 11 months ago](https://wordpress.org/support/topic/carding-attacks/#post-17992226)
 * We are also seeing an insane amount of fake orders on our website. We also have
   recaptcha at checkout via third party but the attacker somehow bypass that.
 *  Plugin Author [Clayton R](https://wordpress.org/support/users/mrclayton/)
 * (@mrclayton)
 * [1 year, 11 months ago](https://wordpress.org/support/topic/carding-attacks/#post-17992710)
 * > We also have recaptcha at checkout via third party but the attacker somehow
   > bypass that.
 * You should enable the WooCommerce option to require an account during checkout.
   See if that reduces the number of fake orders.
 * Carding attacks don’t indicate a Braintree plugin issue.
 * Thanks
 *  [dev1526](https://wordpress.org/support/users/dev1526/)
 * (@dev1526)
 * [1 year, 8 months ago](https://wordpress.org/support/topic/carding-attacks/#post-18147710)
 * I see given thread was last active 2 months and 2 weeks ago. However, because
   of someone able to bypass captcha it is causing lot of trouble. It should be 
   inbuilt flow or should be provided as hook to amend the process of card verification.
   PayPal is chasing us for the same.
 * ![](https://wordpress.org/bc5f950c-3e68-461a-b942-9f6a6d9eb365)

Viewing 6 replies - 1 through 6 (of 6 total)

The topic ‘Carding Attacks’ is closed to new replies.

 * ![](https://ps.w.org/woo-payment-gateway/assets/icon-256x256.png?rev=2142799)
 * [Payment Plugins Braintree For WooCommerce](https://wordpress.org/plugins/woo-payment-gateway/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woo-payment-gateway/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woo-payment-gateway/)
 * [Active Topics](https://wordpress.org/support/plugin/woo-payment-gateway/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woo-payment-gateway/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woo-payment-gateway/reviews/)

 * 6 replies
 * 5 participants
 * Last reply from: [dev1526](https://wordpress.org/support/users/dev1526/)
 * Last activity: [1 year, 8 months ago](https://wordpress.org/support/topic/carding-attacks/#post-18147710)
 * Status: resolved