Merchant Fraud Prevention Guide
Stop Online Card Fraud Before It Costs You.
If you’re seeing a rash of fraudulent cards entered on your website, you’re likely being targeted by a card testing attack. The good news: it’s very preventable once the right controls are in place.
What’s Actually Happening
Fraudsters use automated bots to run stolen card numbers through public checkout pages, testing which ones are still active.
It’s called card testing or a BIN attack. Bots submit hundreds or thousands of stolen card numbers against your checkout in a short window. Most transactions decline. The ones that approve get sold or used for fraud elsewhere. Either way, you absorb the damage:
- Decline fees from your processor on every failed attempt
- Card brand penalties if your decline ratio crosses certain thresholds
- Chargebacks on the transactions that do go through
- Potential account review or MATCH list placement if it continues
Fraud Prevention Happens at Three Layers
Most merchants assume the processor handles all of this. They don’t. Real protection requires controls at every layer.
01
Your Website
The first line of defense. CAPTCHA, rate limiting, and checkout hardening stop most attacks before they ever reach your gateway.
02
Your Gateway
Where most fraud tools actually live. AVS, CVV, velocity filters, 3D Secure, and fraud scoring are all configured here, not at the processor.
03
Processor & Issuer
The final check. By the time a transaction reaches the processor and issuing bank, most of the damage is already done.
What to Turn On Immediately
In order of priority. The top items stop the bleeding within hours, not weeks.
Website & Checkout
Add CAPTCHA to your checkout form. Google reCAPTCHA v3 is invisible to real customers and stops most bot traffic cold.
Rate-limit checkout attempts by IP address. If one IP submits 10 or more transactions in a minute, block it.
Require email verification before checkout on higher-value items.
Gateway Settings
Require AVS match (zip code at minimum) and decline on mismatch.
Require CVV on every transaction and decline on mismatch.
Enable velocity filters that cap attempts per card number, email address, and IP per hour.
Turn on 3D Secure 2.0. This also shifts chargeback liability from you to the issuing bank on authenticated transactions.
Enable the gateway’s fraud scoring tool if one is available. Most modern gateways include one.
Block high-risk countries by IP if you don’t do international business.
Processor Side
Confirm fraud monitoring is enabled on your merchant account.
Ask where your decline ratio stands. Excessive declines can trigger card brand penalties, and those get expensive quickly.
The Strongest Single Control
3D Secure 2.0: Worth the Setup Effort
3D Secure 2.0 authenticates the cardholder with their issuing bank at checkout, usually invisibly through device fingerprinting. On authenticated transactions, chargeback liability shifts from you to the issuing bank. It is the single strongest fraud control available to an online merchant.
Roughly 80 to 90 percent of 3DS2 transactions are frictionless. The customer sees nothing. The remaining transactions get a challenge screen where the customer verifies with their bank via SMS, app push, or biometric.
How to Turn It On
1
Ask your gateway to enable it on your account
Most gateways have 3DS2 available but gated behind a support request or admin toggle. It may be called Payer Authentication, Cardinal Consumer Authentication, Cardinal Cruise, or just 3DS2.
2
Update your checkout integration
Your developer inserts a 3DS authentication call before the authorization call. Device fingerprinting happens invisibly, and the authentication result gets passed along with the charge.
3
Test in sandbox, then go live
Every major gateway provides test cards that trigger both frictionless and challenge flows. Test both before flipping it on in production.
Gateway-Specific Setup
Exact steps vary by platform. Here’s where to start on the most common gateways.
Authorize.Net
Call support and request Cardinal Consumer Authentication on the account. Integration uses the Cardinal Cruise SDK. Enable Advanced Fraud Detection Suite (AFDS) at the same time for additional filters.
NMI
Enable through your ISO or reseller. Has native Cardinal integration for 3DS2. Also enable iSpyFraud for velocity and pattern detection.
PayTrace
Contact PayTrace support to enable 3DS2 on your account. API endpoints are available for the authentication flow.
Stripe
Nothing to turn on. 3DS2 is built in. Radar rules decide when to require it automatically, and you can force it on any Payment Intent.
Braintree
Built in. Your developer calls threeDSecure.verifyCard() in the SDK. Enable it in your Braintree control panel first.
Shopify Payments
Already on. 3DS2 is enabled by default and triggered automatically based on Shopify’s fraud rules. No action required.
WooCommerce
Depends on your payment plugin. Modern Stripe, Authorize.Net, and Square plugins have 3DS2 as a checkbox in settings. Older plugins may need updating.
Custom-Built Sites
Plan for a developer project of several days to a week. The 3DS server call happens before the authorization, and the authentication result (CAVV, ECI, dsTransID) must be passed with the charge request.
Questions About Your Processing Setup?
weAudit identifies overbilling on merchant credit card processing statements. If you’re questioning your fees, fraud controls, or contract terms, a free audit is the best place to start. Low fixed monthly fee based on your processing volume and account complexity. No advisory fees, ever.
weAudit.com
America’s #1 Credit Card Processing Auditing Firm
Founded by Robert Day, More Than a Decade as an Executive at Fifth Third Processing Solutions, later Vantiv and Worldpay, now part of Global Payments, the world’s largest card processor, Wharton alumnus, Forbes Business Council member, Entrepreneur Contributor, Vistage member and speaker, and author of The Great American Heist.