Fraudulent transactions on NC website

Options
We are getting a ton of fraudulent donations through our donation page this month. We've asked BB to blacklist the IP addresses (we're hosted) but so far that isn't slowing the crooks down. Is everyone using reCAPTCHA on their donation pages? We hesitate to put that on our main donation page because we feel it will be a deterent for our "true" donors & we'll lose donations as a result. For those who've implemented reCAPTCHA, did you see a drop in donations after installing?
Tagged:

Comments

  • Hey Tracie and anyone else reading this,



    Just wanted to mention the some other things we like to tell people to do that are struggling with fraudulent transactions.



    Set a minimum donation amount on the form. If the person submitting the fraudulent donations can't do them for small amounts it makes your site less attractive and they may move to easier prey.



    Blocking IPs tends to not work because it's very easy to use a proxy to change your IP on the fly. Anyone who's testing credit cards in volume will likely know how to do this, and employ this tactic.



    Increasing your AVS and CVC settings may help, but like reCAPTCHA it runs the risk of deterring real donations as people make typos in their address and things like that.



    Sorry if this is repetitive Tracie! I'm mostly posting it for others reading the thread. I'm sure we told you at least some of this stuff already.



    Thanks!


    Karen
  • Karen Badham:
    Hey Tracie and anyone else reading this,



    Just wanted to mention the some other things we like to tell people to do that are struggling with fraudulent transactions.



    Set a minimum donation amount on the form. If the person submitting the fraudulent donations can't do them for small amounts it makes your site less attractive and they may move to easier prey.



    Blocking IPs tends to not work because it's very easy to use a proxy to change your IP on the fly. Anyone who's testing credit cards in volume will likely know how to do this, and employ this tactic.



    Increasing your AVS and CVC settings may help, but like reCAPTCHA it runs the risk of deterring real donations as people make typos in their address and things like that.



    Sorry if this is repetitive Tracie! I'm mostly posting it for others reading the thread. I'm sure we told you at least some of this stuff already.



    Thanks!


    Karen
    I agree 100% with Karen's advice. It's exactly what we tell organizations who run into this type of situation.



    Here's a blog post that I wrote in 2011 on the subject: http://www.npengage.com/nonprofit-res...

Categories