Card Running
Options
Has anyone experienced card running via website? We're currently being hit hard by one individual who is running small amount transactions ($5.00), using different email addresses and different credit card numbers. We've contacted Support to get assitance with this. One option was to block the IP address, which we did, to no avail. They're recommending adding Addresses Verification Service (AVS) which will match the donors address to the card, which Blackbaud warns results is fails for legitimate donors if they haven't typed their information in properly, which can be frustrating for the donor.
Below are the AVS options. I'm wondering if anyone uses this to protect from card running and have you seen an adverse affect on online donation rates as a result?
Below are the AVS options. I'm wondering if anyone uses this to protect from card running and have you seen an adverse affect on online donation rates as a result?
For zip code matching (PARTIAL_ZIP), the zip code at the bank can create a false failure if the bank has the zip+4 and the constituent does not enter in the +4 at the time of donating.
For either matching (PARTIAL), the matching is the same as the other partial matches but it will accept either. So if I type in the wrong street number but the correct zip code, the transaction will be accepted and vice versa.
For complete matching (FULL), the matching is the same as the partials, but everything has to be correct. So if I type in either my street number or my zip code incorrectly, the transaction will fail.
Tagged:
0
Comments
-
Hi Veronica -
Phishing can happen almost anywhereIf you already talked to Support then you've probably already been advised to consider changing the minimum amounts on donation forms. Since your phisher is semi-smart and they've already jumped the IP block hurdle, then you can start with the PARTIAL_ZIP and see if you get any donor complaints. If phishing continues, then you still have higher levels of AVS settings that you can trigger.
The biggest pain for you as the account owner will be the credit card charge-back fees and those can out weigh the handful of donor complaints.
Good luck,
Sara
1 -
Ditto what Sara said! Online fundraising is a balance between costs (including donor frustration) of fraud prevention and administrative pain of fraud tolerance! If you accept donations online, you will have some fraud. Your trick is to find that pivot point for your organization where the cost of tolerance outweighs the cost of prevention - you don't want to loose more money to preventing fraud than the fraud itself costs you. Just be sure to consider everything - intangibles of reputation, media, frustration and tangibles of fees, time, etc.
The one thing I'm curious about, you seem certain that it is one individual... What is the basis of that determination? Typically it would be IP setting, but since that didn't work, is there something else that you are using to identify the individual? There are other options beside just IP address that you might consider depending on the profile of these carding runs. Support can enable and configure options that have to do with the velocity of run - number of cards within a period of time... That can often be more successful than a simple IP block, but it can be problematic if you have events like corporate donation days where a number of people at one location a donating to you as part of a drive or something.0 -
We had the same issue, got the same advice, and implemented AVS. The small (for us, fraudulent) transactions were a big enough headache for us to take the risk, and we haven't had any issues with AVS so far.
We have an automated report that runs weekly (we could look at it more often) showing us declined transactions and we didn't see an uptick in declines. We do have one consistuent who consistently has AVS issues but it's due to user error and she knows it!0 -
This is the best:
due to user error and she knows it!
0 -
I believe that this is happening and that it is a problem, but I'm a little curious as to why a criminal would be using credit cards to give to a charity. What is there to gain? Maybe I don't fully understand what is happening in these cases.0
-
Carding runs are used to verify the usability of an unscupulously gained credit card. The risk of capture in giving a $5 donation to a non-profit is far less than the risk of capture at an ecommerce site. Non-profits are hardwired to make it as easy as possible to give money (relatively speaking) where as ecommerce is hardwired to protect the business profites (and therefor the delivery of goods).
If the card works on your site, it can then be sold off as a working card to be used for much higher transactions that make the risk "worthwhile." Stolen card numbers have a life span measured in hours, so it is a segment of the market that continuously validates and re-validates the "integrity" of the "product."2
Categories
- All Categories
- Shannon parent
- shannon 2
- shannon 1
- 21 Advocacy DC Users Group
- 14 BBCRM PAG Discussions
- 89 High Education Program Advisory Group (HE PAG)
- 28 Luminate CRM DC Users Group
- 8 DC Luminate CRM Users Group
- Luminate PAG
- 5.9K Blackbaud Altru®
- 58 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 409 bbcon®
- 2.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- donorCentrics®
- 1.1K Blackbaud eTapestry®
- 2.8K Blackbaud Financial Edge NXT®
- 1.1K Blackbaud Grantmaking™
- 527 Education Management Solutions for Higher Education
- 1 JustGiving® from Blackbaud®
- 4.6K Education Management Solutions for K-12 Schools
- Blackbaud Luminate Online & Blackbaud TeamRaiser
- 16.4K Blackbaud Raiser's Edge NXT®
- 4.1K SKY Developer
- 547 ResearchPoint™
- 151 Blackbaud Tuition Management™
- 61 everydayhero
- 3 Campaign Ideas
- 58 General Discussion
- 115 Blackbaud ID
- 87 K-12 Blackbaud ID
- 6 Admin Console
- 949 Organizational Best Practices
- 353 The Tap (Just for Fun)
- 235 Blackbaud Community Feedback Forum
- 55 Admissions Event Management EAP
- 18 MobilePay Terminal + BBID Canada EAP
- 36 EAP for New Email Campaigns Experience in Blackbaud Luminate Online®
- 109 EAP for 360 Student Profile in Blackbaud Student Information System
- 41 EAP for Assessment Builder in Blackbaud Learning Management System™
- 9 Technical Preview for SKY API for Blackbaud CRM™ and Blackbaud Altru®
- 55 Community Advisory Group
- 46 Blackbaud Community Ideas
- 26 Blackbaud Community Challenges
- 7 Security Testing Forum
- 3 Blackbaud Staff Discussions
- 1 Blackbaud Partners Discussions
- 1 Blackbaud Giving Search™
- 35 EAP Student Assignment Details and Assignment Center
- 39 EAP Core - Roles and Tasks
- 59 Blackbaud Community All-Stars Discussions
- 20 Blackbaud Raiser's Edge NXT® Online Giving EAP
- Diocesan Blackbaud Raiser’s Edge NXT® User’s Group
- 2 Blackbaud Consultant’s Community
- 43 End of Term Grade Entry EAP
- 92 EAP for Query in Blackbaud Raiser's Edge NXT®
- 38 Standard Reports for Blackbaud Raiser's Edge NXT® EAP
- 12 Payments Assistant for Blackbaud Financial Edge NXT® EAP
- 6 Ask an All Star (Austen Brown)
- 8 Ask an All-Star Alex Wong (Blackbaud Raiser's Edge NXT®)
- 1 Ask an All-Star Alex Wong (Blackbaud Financial Edge NXT®)
- 6 Ask an All-Star (Christine Robertson)
- 21 Ask an Expert (Anthony Gallo)
- Blackbaud Francophone Group
- 22 Ask an Expert (David Springer)
- 4 Raiser's Edge NXT PowerUp Challenge #1 (Query)
- 6 Ask an All-Star Sunshine Reinken Watson and Carlene Johnson
- 4 Raiser's Edge NXT PowerUp Challenge: Events
- 14 Ask an All-Star (Elizabeth Johnson)
- 7 Ask an Expert (Stephen Churchill)
- 2025 ARCHIVED FORUM POSTS
- 322 ARCHIVED | Financial Edge® Tips and Tricks
- 164 ARCHIVED | Raiser's Edge® Blog
- 300 ARCHIVED | Raiser's Edge® Blog
- 441 ARCHIVED | Blackbaud Altru® Tips and Tricks
- 66 ARCHIVED | Blackbaud NetCommunity™ Blog
- 211 ARCHIVED | Blackbaud Target Analytics® Tips and Tricks
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- Luminate CRM DC Users Group
- 225 ARCHIVED | Blackbaud eTapestry® Tips and Tricks
- 1 Blackbaud eTapestry® Know How Blog
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)
- 1 Blackbaud K-12 Education Solutions™ Blog
- 280 ARCHIVED | Mixed Community Announcements
- 3 ARCHIVED | Blackbaud Corporations™ & Blackbaud Foundations™ Hosting Status
- 1 npEngage
- 24 ARCHIVED | K-12 Announcements
- 15 ARCHIVED | FIMS Host*Net Hosting Status
- 23 ARCHIVED | Blackbaud Outcomes & Online Applications (IGAM) Hosting Status
- 22 ARCHIVED | Blackbaud DonorCentral Hosting Status
- 14 ARCHIVED | Blackbaud Grantmaking™ UK Hosting Status
- 117 ARCHIVED | Blackbaud CRM™ and Blackbaud Internet Solutions™ Announcements
- 50 Blackbaud NetCommunity™ Blog
- 169 ARCHIVED | Blackbaud Grantmaking™ Tips and Tricks
- Advocacy DC Users Group
- 718 Community News
- Blackbaud Altru® Hosting Status
- 104 ARCHIVED | Member Spotlight
- 145 ARCHIVED | Hosting Blog
- 149 JustGiving® from Blackbaud® Blog
- 97 ARCHIVED | bbcon® Blogs
- 19 ARCHIVED | Blackbaud Luminate CRM™ Announcements
- 161 Luminate Advocacy News
- 187 Organizational Best Practices Blog
- 67 everydayhero Blog
- 52 Blackbaud SKY® Reporting Announcements
- 17 ARCHIVED | Blackbaud SKY® Reporting for K-12 Announcements
- 3 Luminate Online Product Advisory Group (LO PAG)
- 81 ARCHIVED | JustGiving® from Blackbaud® Tips and Tricks
- 1 ARCHIVED | K-12 Conference Blog
- Blackbaud Church Management™ Announcements
- ARCHIVED | Blackbaud Award Management™ and Blackbaud Stewardship Management™ Announcements
- 1 Blackbaud Peer-to-Peer Fundraising™, Powered by JustGiving® Blogs
- 39 Tips, Tricks, and Timesavers!
- 56 Blackbaud Church Management™ Resources
- 154 Blackbaud Church Management™ Announcements
- 1 ARCHIVED | Blackbaud Church Management™ Tips and Tricks
- 11 ARCHIVED | Blackbaud Higher Education Solutions™ Announcements
- 7 ARCHIVED | Blackbaud Guided Fundraising™ Blog
- 2 Blackbaud Fundraiser Performance Management™ Blog
- 9 Foundations Events and Content
- 14 ARCHIVED | Blog Posts
- 2 ARCHIVED | Blackbaud FIMS™ Announcement and Tips
- 59 Blackbaud Partner Announcements
- 10 ARCHIVED | Blackbaud Impact Edge™ EAP Blogs
- 1 Community Help Blogs
- Diocesan Blackbaud Raiser’s Edge NXT® Users' Group
- Blackbaud Consultant’s Community
- Blackbaud Francophone Group
- 1 BLOG ARCHIVE CATEGORY
- Blackbaud Community™ Discussions
- 8.3K Blackbaud Luminate Online® & Blackbaud TeamRaiser® Discussions
- 5.7K Jobs Board