Blog

Five Essential Fraud Prevention Solutions

November 10, 2015

Pet osnovnih rešenja za prevenciju prevara

In today’s world, where the number of online transactions is growing rapidly, the number of fraud attempts is growing as well. The number of online card transactions made by users from Serbia increases by a double-digit percentage every year. Following this growth trend, we would not be surprised if the total value of online payments reaches 150 million euros or more as early as next year, 2016. But card fraud is also a serious business. It is vital for every serious online merchant to take certain measures to stop online fraudsters in their tracks. We will mention some solutions that will help you protect yourself and your customers.

Manual Reviews

Manually checking the validity of every single transaction is certainly neither productive nor financially justified. Fortunately, there is a solution available to our users that is part of our standard offering. The system works by assigning each individual payment transaction a certain number of negative points for every detected behavior that does not match expectations. The points collected this way are added up before the transaction is sent. Of course, all of this together takes only a fraction of a second.

If the number of negative points is below the threshold, the transaction is immediately sent for authorization. If the number of negative points is above the allowed limit, the transaction is not even sent to the bank but is declined immediately. However, when the number of negative points is somewhere around the threshold, the merchant is given the option to review such a transaction “manually” before deciding whether to send it for authorization or not.

Typically, the merchant then checks the details in the system on why the transaction received negative points and, based on that, uses the available methods to verify whether the suspicion about the transaction is actually justified.

For example, if the transaction received most of its negative points because the card bears the name of one person while the delivery address lists another, the merchant can, for instance, check on social networks whether the customer exists, or call the customer by phone and ask why the customer’s name differs from the cardholder’s. Ultimately, the merchant then decides whether to decline or accept the transaction.

Pet osnovnih rešenja za prevenciju prevara

PCI DSS Compliance

PCI DSS is the security standard that applies to the payment card industry. All organizations that process, store or transmit payment card information must do so securely and in a secure environment. This applies to banks and processors as well as to merchants themselves. That is why it is of the utmost importance whether the company providing your payment services (payment gateway) is PCI DSS compliant and whether you, as its user, are automatically PCI compliant.

3-D Secure

Known as ‘Verified by Visa’, ‘American Express SafeKey’ or ‘MasterCard SecureCode’, 3-D Secure used to require users to type in a password to authorize a purchase.

For years, criticism of this 3-D Secure approach was based on the fact that passwords could easily be bypassed using various methods known to hackers. The general impression among merchants was that the card schemes were adding friction for customers without any real contribution to payment security.

With the introduction of the improved 3-D Secure 2.0, we arrive at something far more acceptable to customers. This new version eliminates the need for static passwords and instead introduces authentication achieved by sending a message to a previously registered phone number before the transaction can be completed. What we expect in the next phase of improvements is a greater role for biometrics.

Pet osnovnih rešenja za prevenciju prevara

Card Security Code (CSC)

Better known as the card’s CVV/CVV2 number, it can generally be found on the back of most cards (although on American Express cards it is on the front). This number is checked against the data held by the card issuer. It is never used on any document and provides an additional level of security for online card payments.

Tokenization

Tokenization is a process in which data is converted into a unit called a token. During a card transaction, sensitive card data is encrypted and turned into tokens. These can later be decrypted, and therefore used, only on specially built, secure, certified servers. Tokens are thus used instead of card data. This modern solution increases security because the merchant not only does not store card data at its point of sale, but also does not send card data over the internet during the transaction – it only exchanges a token that cannot be decrypted outside the processor’s servers. Tokens are also useful because they allow merchants to “register” the card of a customer who wishes to do so, enabling features such as one-click payments and recurring payments. A good example of this in practice is Amazon “1 Click Ordering”.

Ready to Launch Online Payments?

Send a request and our team will get back to you shortly.