Card testing fraud
Malicious third parties may try to use your website to determine if stolen credit card details are valid. They try many small payments using different credit card numbers and expiry dates. The approved cards are then used to defraud another merchant for a larger amount. This is called "card testing".
Websites with minimal validation rules that allow an attacker to try many credit card numbers are often targets. This can include websites used for making donations or paying invoices.
Protect against card testing
If you make card testing difficult, your website is less likely to be a target.
If you are using the PayWay REST API or classic API and your payment website is generally available on the Internet you must:
- send the customer IP address to PayWay
- add a captcha or other fraud protection mechanism
You can also:
- Validate the payment reference number has an outstanding balance
- Set a minimum payment amount
- Use 3D Secure
- Use PayWay Fraud Guard
Contact us
For sales, help and technical support contact us.