When theÌýpandemic hit, ecommerce blew up.
With people locked down andÌýwith little toÌýdo, buying online seemed theÌýonly escape. The global ecommerce market jumped toÌý. Customer habits, too, were changing. InÌýone survey, agreed that
But itÌýwasn’t just theÌýsales that were soaring. And itÌýwasn’t just theÌýecommerce industry’s businesses that were
InÌýjust aÌýsingle year (between 2020ÌýandÌý2021), : from $17.5Ìýbillion toÌý$20Ìýbillion. One look atÌýtheÌýsimilarly burgeoning
The bottom line? Ecommerce fraud isÌýsomething you can’t afford toÌýturn aÌýblind eye to. After all, it’s not just aÌýthreat toÌýyour profits but your brand image. IfÌýcustomers don’t feel they can pay securely through your website, they won’t trust you. Once you lose that consumer confidence, it’s extremely difficult toÌýwin back.
Below, we’ll unpack theÌýstate ofÌýpayment security, starting with theÌýmost common types ofÌýecommerce fraud. We’ll also offer actionable advice forÌýprotecting your customers, your website,
Most Common Types ofÌýEcommerce Fraud
AsÌýtheÌýworld ofÌýecommerce expands andÌýevolves, soÌýtoo doÌýits villains. SoÌýover theÌýlast few years, it’s not only theÌýnumber ´Ç´ÚÌý´Ú°ù²¹³Ü»å³Ü±ô±ð²Ô³Ù
From pharming andÌýaccount takeovers toÌý“friendly” andÌý“silent” fraud (not toÌýmention
Pharming
Pharming isÌýaÌýtype ofÌýecommerce fraud inÌýwhich fraudsters redirect web users (without their knowledge orÌýconsent) toÌýaÌýfraudulent website. This website might look andÌýfeel like theÌýone theÌýcustomer intended toÌýreach, but with aÌýkey
Designed only toÌýsimulate theÌýoriginal website, its fake counterpart exists forÌýone reason
Chargeback Fraud
Also known asÌý“friendly fraud,” chargeback fraud isÌýwhen aÌýcustomer fraudulently attempts toÌýclaim aÌýrefund byÌýabusing theÌýchargeback system.
AÌýchargeback isÌýaÌýstep introduced byÌýbanks way back inÌýtheÌý’70s toÌýboost public confidence inÌýtheÌýcredit card (which, atÌýthat stage, was aÌý
Let’s say you’re off toÌýSantorini forÌýaÌýholiday, andÌýyour card isÌýstolen atÌýtheÌýairport. ByÌýtheÌýtime you get toÌýGreece, you realize theÌýthief has made $700ÌýinÌýfraudulent purchases onÌýyour card. InÌýthis situation, you could (quite legitimately) request aÌýchargeback.
The problem? When it’s not legitimate. Whether maliciously orÌý“innocently” (customers forgetting about aÌýtransaction onÌýtheir statement orÌýaÌýrecurring billing cycle), fraudsters can take advantage ofÌýtheÌýchargeback process toÌýclaim money back onÌýtotally valid purchases.
The worst part? That, when aÌýchargeback claim isÌýupheld byÌýtheÌýbank, theÌýbank then claims theÌýmoney (along with aÌýfee onÌýtop, forÌýtheir troubles!) back from you. Add that toÌýtheÌýstock you’ve already lost toÌýtheÌýfraudster, andÌýchargebacks offer anÌý
Identity Theft
Because ofÌýpopular movies dealing with theÌýsubject (The Talented Mr. Ripley, anyone?), identity theft isÌýone ofÌýtheÌýmore
Here, aÌýfraudster falsely assumes another person’s identity: using their name, personal information, andÌýdocuments toÌýopen credit cards, then hitting theÌýhigh street.
Beyond theÌýimpact onÌýtheÌývictim, why isÌýthis bad news forÌýyour online business? After all, you’re still selling…right?
Wrong. Think back, forÌýaÌýsecond, toÌýour Santorini example above. Pretty soon, theÌýperson whose identity was stolen will become aware ofÌýtheÌýlitany ´Ç´ÚÌý´Ú°ù²¹³Ü»å³Ü±ô±ð²Ô³Ù purchases made under their name
Making upÌý, identity theft isÌýbyÌýfar theÌýmost common type ofÌýecommerce fraud. Plus, fraudsters are also becoming more sophisticated, now using theÌýpersonal devices, IPÌýaddresses, andÌýuser accounts ofÌýtargets toÌýassume their identities, which makes them aÌýthreat toÌýbeÌýalert to.
Account Takeovers
AtÌýsome stage orÌýother while shopping online, all our customers have done it. Ticked that box that says “Save MyÌýCredit Card Details.” It’ll save them aÌýminute theÌýnext time they come back toÌýmake aÌýpurchase, soÌýit’s aÌý
Right. Unless that is, aÌýfraudster isÌýable toÌýget their
And when they do? Expect chargebacks from theÌýreal customer, leaving your business out ofÌýpocket.
Malware andÌýRansomware
Does your computer keep freezing up? Are there ads popping upÌýeverywhere? DoÌýlinks take you toÌýtheÌýwrong destination, orÌýare new icons appearing onÌýyour desktop andÌýbrowser?
IfÌýso, you may have inadvertently installed malware (mal =Ìýbad, ware =Ìýsoftware…it’s bad software) onÌýyour device. Even theÌýterm “malware” itself includes aÌýrange ofÌýdifferent malicious code types, each more nefarious than theÌýlast. These include spyware, “Trojan Horses,” andÌý
The problem forÌýecommerce store owners isÌýthat malware, whether onÌýyour system orÌýthat ofÌýyour customers orÌýadmins, can steal sensitive data. That includes theÌýnames andÌýaddress details ofÌýyour customers, asÌýwell asÌýtheir payment information. IfÌýanyÌýofÌýthat’s compromised, itÌýwon’t just beÌýprofits orÌýdata you’ll beÌýlosing, it’ll beÌýyour credibility.
What’s more, malware attacks pave theÌýway forÌýanÌýemerging form ofÌýecommerce deception called “silent” fraud. After using malware toÌýillegally access aÌýnumber ofÌýaccounts, fraudsters, instead ofÌýsnatching thousands, hundreds, tens, orÌýeven ones, swipe aÌýfew cents alone. Done atÌýscale andÌýwith regularity, these thefts can total huge amounts ofÌýstolen funds. Not soÌý“silent” after all!
Ways toÌýProtect Your Customers
Knowing what theÌýmain types ofÌýecommerce fraud are isÌýone thing. But being able toÌýeffectively insulate you andÌýyour customers from fraud’s ill effects isÌýquite another.
Below, we’ve rounded upÌýour top tips forÌýhelping you, your customer base, andÌýyour business remain beyond theÌýcovetous clutches ofÌýfraudsters.
Safeguard Customer Information
The first way you can protect your customers? Safeguarding their most important details. Here’s how:
Firewalls
ByÌýfiltering andÌýmonitoring incoming (and outgoing) traffic, firewalls help maintain theÌýsecurity ofÌýyour website, acting, basically, asÌýaÌýliteral wall between your network andÌýtheÌýwild, wild West ofÌýtheÌýinternet atÌýlarge.
Through this lens, firewalls are vital not only forÌýsecuring your data systems but forÌýmaintaining PCI compliance. PCI DSS (Payments Card Industry Data Security Standards) isÌýaÌýset ofÌýregulations all businesses accepting credit andÌýdebit cards must follow. PCI compliance isÌýaÌýkind ofÌý“seal ofÌýapproval” that shows your customers, regulators, andÌýtheÌýwider market that you can beÌýtrusted toÌýhandle sensitive data.
IfÌýyou sell online with ºÚÁÏÃÅ byÌýLightspeed, your store isÌýalready PCI DSS compliant. ºÚÁÏÃÅ byÌýLightspeed isÌýaÌýPCI DSS validated Level 1ÌýService Provider. This isÌýtheÌýhighest international standard forÌýsecure data exchanges forÌýonline stores andÌýpayment systems.
Enable Two-Factor Authentication (2FA)
Ensure 2FA isÌýimplemented, soÌýanyone attempting toÌýaccess your business’s backend platforms andÌýprocesses will need toÌýlog inÌýthrough two devices. IfÌýyou orÌýone ofÌýyour team members isÌýlogging inÌýfrom aÌýdesktop computer, forÌýinstance, you’ll also need toÌýconfirm theÌýattempt onÌýanother device, such asÌýyour phone, toÌýgain access.
Other variations include:
Two-step variation (2SV): involves receiving aÌýone-time code orÌýpassword via email, message, orÌýphone call which you must enter toÌýlog in.Multi-factor authentication: aÌýmix ofÌýmultiple forms ofÌýauthentication forÌýone ofÌýtheÌýhighest levels ofÌýsecurity.
Business owners selling online with ºÚÁÏÃÅ byÌýLightspeed can use their Google orÌýFacebook accounts toÌýsign inÌýtoÌýtheir ºÚÁÏÃÅ store. forÌýyour Google orÌýFacebook account andÌýthus protect your login information forÌýºÚÁÏÃÅ asÌýwell.
IfÌýyou want toÌýadd other team members (like fulfillment staff orÌýaÌýdesigner) toÌýyour ºÚÁÏÃÅ store, never share your ºÚÁÏÃÅ login with them. Instead, forÌýeach user inÌýyour store. Staff accounts have separate logins andÌýdon’t have access toÌýyour profile andÌýbilling pages.
Use aÌýSecure Payment Gateway
IfÌýyou want toÌýoffer your customers theÌýhighest level ofÌýpayment peace ofÌýmind possible, aÌýsecure payment gateway isÌýaÌýmust.
AÌýpayment gateway isÌýtheÌýtech merchants use toÌýaccept credit andÌýdebit card purchases: both
ºÚÁÏÃÅ byÌýLightspeed isÌýintegrated with dozens ofÌý. You can choose aÌýpayment system that isÌýconvenient both forÌýyour business andÌýyour customers.
More: How toÌýPick aÌýPayment System For Your Ecommerce Store
Share Advice andÌýInfo with Your Customers
One ofÌýtheÌýeasiest ways toÌýprotect your customers? Informing them.
Whether through emails, texts, orÌýdedicated sections onÌýyour website, let your customers know ofÌýtheÌýfraud that exists andÌýhow they can protect themselves from it. (And help you protect them from it!)
BeÌýsure toÌýclearly lay out:
- How your business greets its customers (so they can spot discrepancies)
- How your business doesn’t greet its customers, andÌýwhat itÌýwon’t request (i.e., their login details orÌýtoÌýclick aÌýlink toÌýlog in)
- Clear, actionable tips forÌýcustomers toÌýkeep their account details safe (if your business keeps customer accounts)
- How toÌýget inÌýtouch ifÌýsomething doesn’t look right orÌýifÌýtheÌýcustomer has questions
- What security checks you’re introducing, ifÌýany
- How theÌýcustomer can safely update their details
- What toÌýdoÌýifÌýthey receive aÌýscam email (i.e., aÌýfraudster posing asÌýyour business) andÌýhow toÌýreport theÌýfraudulent communication
Needless toÌýsay, these kinds ofÌýcomms are vital. Not only doÌýthey inspire trust andÌýoffer anÌýexcellent user experience, but they also help reduce theÌýrisk ofÌýyour customers falling prey toÌýecommerce fraud.
Remember, too, toÌýmake this info asÌýaccessible asÌýpossible. Your customers might not read their emails orÌýthoroughly read through your website. SoÌýtheÌýmore channels you can publicize this advice on, theÌýbetter!
Keep Your Site Updated andÌýConduct Regular Security Audit
Earlier, weÌýanalogized theÌýwider internet asÌýaÌýkind ofÌý“Wild West”: aÌýfrontier state where bandits andÌýlawlessness abound.
Now, while that might beÌýaÌýlittle onÌýtheÌýharsh side, there are plenty ofÌýthreats out there andÌýmyriad methods via which phishers, hackers, andÌýfraudsters can derail your business:
- DoS (Denial ofÌýService) attacks: aÌýhacker attempts toÌýstop users from accessing your site’s services.
- DDoS (Distributed Denial ofÌýService) attacks: theÌýperpetrator doesn’t attack you directly but instead uses your site asÌýaÌý“zombie” with which toÌýharm another site. InÌýaÌýDDoS attack, your servers are inundated byÌýrequests from aÌýbunch ofÌýuntraceable IPÌýaddresses, crashing your site, andÌýstopping traffic andÌýsales.
- Brute force attacks: here, hackers hit your website with thousands ofÌýdifferent password combinations inÌýanÌýattempt toÌýgain access.
- Man inÌýtheÌýmiddle (MITM) attacks: ifÌýyour customer isÌýaccessing your site via aÌývulnerable network (i.e., public WiFi), hackers can “listen in” toÌýtheÌýtransaction andÌýuse itÌýtoÌýextract sensitive data.
- SQL injections andÌý
cross-site scriptings: these attacks exploit vulnerabilities inÌýyour site. InÌýanÌýSQL injection, hackers target your forms toÌýgain access to, corrupt andÌýsteal information from your site’s backend. InÌýcross-site scripting, hackers insert malicious snippets ofÌýcode that steal your visitors’ information.
The fact that all these modes ofÌýattack exist? That’s theÌýbad news. The good news, however, isÌýthat these hackers are opportunists. They’re looking forÌývulnerabilities inÌýyour site’s security andÌýfraud prevention setup. That means, byÌýkeeping your site updated andÌýregularly identifying, understanding, andÌýplugging its vulnerabilities you can reduce theÌýrisk ofÌýaÌýhacker targeting your website andÌýbusiness.
ToÌýdoÌýthis, conduct regular security audits. Assess your site’s infrastructure forÌýloopholes, exploring theÌýbackend andÌýcode (including extensions andÌýthemes) forÌýanything hackers can exploit. Ensure:
- Your passwords are strong
- Your software isÌýupÌýtoÌýdate
- Your site’s (Secure Sockets Layer) certificate isÌýupÌýtoÌýdate
Speaking ofÌýSSL certificates, ifÌýyou created your ecommerce website with ºÚÁÏÃÅ byÌýLightspeed, you already have anÌýSSL certificate byÌýdefault.
IfÌýyou added your ºÚÁÏÃÅ store toÌýanÌýexisting website, you already have theÌýfree SSL certificate forÌýyour store. However, theÌýrest ofÌýtheÌýwebsite isÌýaÌýseparate matter. You need toÌýpurchase anÌýSSL certificate toÌýprotect sensitive information. Learn how toÌýdoÌýthat inÌýtheÌý.
Another way toÌýprotect your website isÌýtoÌýrevise theÌýlist ofÌýyour online store’s staff accounts andÌýremove theÌýstaff members that you doÌýnot work with anymore. This way, you prevent hackers from taking advantage ofÌýthese “back channels” toÌýgain access toÌýyour site.
Key Times toÌýProtect Your Website
So, now that we’ve explained what fraud toÌýlook forÌýandÌýhow toÌýprotect your website from it, let’s look atÌýtheÌý
Public Holidays
“The Federal Bureau ofÌýInvestigation (FBI) andÌýtheÌýCybersecurity andÌýInfrastructure Security Agency (CISA) have observed anÌýincrease inÌýhighly impactful ransomware attacks occurring onÌýholidays andÌý
Christmas, Easter, Memorial Day, Independence
Increased distraction onÌýtheÌýpart ofÌýtheÌýcustomer orÌý
Against this backdrop, don’t let your business get caught out. Don’t wait until theÌýnext holiday toÌýset your site’s security upÌýforÌýsuccess, orÌýfind yourself scrambling toÌýaudit your site mere days before theÌýlong Mother’s Day weekend. Remember that old Chinese proverb?
The best time toÌýplant aÌýtree was 20Ìýyears ago. The second best time isÌýtoday.
Weekends
Hackers tend toÌýtarget businesses when they’re most vulnerable andÌýwhen they’re closed.
That’s why weekends, particularly long ones, where public holidays are involved, are ripe opportunities forÌýhackers. Still, that doesn’t mean you should let your guard down during theÌýrest ofÌýtheÌýweek. Hackers, onÌýaverage, attack aÌýstaggering , soÌýyou need toÌýremain vigilant.
Conclusion
AsÌýtheÌýopportunities ofÌýecommerce evolve, soÌýdoÌýits threats.
With soÌýmany scaremongering statistics out there, itÌýcan beÌýeasy toÌýwant toÌýput your fingers inÌýyour ears, turn aÌýblind eye, andÌýtake anÌý“ignorance isÌýbliss” approach.
But this mentality doesn’t take into account that with those threats come even more exciting opportunities.
ToÌýmake theÌýpayment process safer, easier, more convenient andÌýmore consistent than ever before. ToÌýbuild your brand, engender customer loyalty, andÌýboost trust with your audience byÌýshowing them that you value their privacy andÌýrespect theÌýsensitivity ofÌýtheir data. And, inÌýtheÌýprocess, lay theÌýfoundations forÌýyour ecommerce business’s solid, sustainable success.
Ìý
- Data Privacy inÌýEcommerce: Emerging Trends andÌýBest Practices forÌý2024
- The State ofÌýEcommerce Payment Security
- How toÌýUse HTTPS Protocol andÌýSSL Certificates toÌýProtect Your Online Store
- Ecommerce Fraud: How toÌýProtect Your Store From Online Shopping Scams
- How ToÌýProtect Your Online Store From Cyber Threats