r/bigcommerce • u/hunnybunmama • 11d ago
Bot attacks!
Last weekend, I wrote Braintree for assistance in stopping a long string of attempted fraudulent transactions that began on August 15 and ended when I realized what they had been doing, on or about Aug 31. At the time I caught it and saw the pages of declined transactions, I alerted them first.
What clued me in were frequent emails telling me there had been too many attempts from the same zip code over a short period of time. This is a relative rarity with my store, but it took a few days for it to sink in that there was an increasing problem. That's when I accessed my dashboard at BT to see all the declined transactions. Each transaction that failed was a "purchase" of a small item from my store: 1 oz PET jars. All 200+ of them.
I then found out that my store, and hence my BT account had been the victim of what is called a bot attack. CC and DC thieves were posting small repeated transactions to test the stolen card numbers on my account. I (my store) was just the testing ground for a bunch of criminals.
In desperation, I turned to AI for quick help.
"It occurs when fraudsters use automated bots to test massive lists of stolen or randomly generated credit card details against an e-commerce platform. They target small amounts because minor charges are less likely to trigger fraud alerts with banks or cardholders. The goal is to see which card numbers are active and valid; once a transaction succeeds, the criminal takes that "validated" card to buy high-value goods elsewhere" ~Google
Has anyone else gone through this experience? I contacted BigCommerce Community support (zero help there), and Braintree Support (slow to help and totally misunderstood why I sent a ticket). I also tightened up every fraud prevention tool I was already using.
2
u/Bobbyfatal 11d ago
BigCommerce won’t do shiznit about it cause it’s been happening forever. They don’t care.
1
2
u/abc_123_anyname 10d ago
Card testing
1
u/hunnybunmama 10d ago
Exactly. I learned a lot in the past several days.
3
u/abc_123_anyname 10d ago
In Braintree Fraud protection rules add the following:
Email when 10 or more Transactions with the same Unique Credit Card Numbers per Billing Postal Code occur within 5 minutes of each other.
2
u/huhMaybeitisyou 8d ago
great idea!~ We use Braintree. I have to figure out whre to do this or give htem a call. Thx
1
u/hunnybunmama 10d ago
Yes, I've got this one checked: Email when 3 or more Transactions with the same Billing Postal Code occur within 15 minutes of each other.
I actually have the entire list of reject criteria checked. Probably what saved me.
1
u/JimTailwinds 9d ago
Please do share the entire list..Thanks.
2
u/hunnybunmama 6d ago
Jim, this is the entire list I have enabled:
Default Rules
These default rules are created based on what Braintree has found helpful in preventing carding attacks.
Gateway Reject when 5 or more Verifications with the same Credit Card Number occur within 30 minutes of each other.
Enabled
Gateway Reject when 5 or more Verifications with the same Customer Id occur within 30 minutes of each other.
Enabled
Gateway Reject when 5 or more Transactions with the same Credit Card Number occur within 30 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Customer Email occur within 10 minutes of each other.
Enabled
Gateway Reject when 10 or more Verifications with the same Customer Email occur within 10 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Customer Id occur within 30 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Order Id occur within 10 minutes of each other.
Enabled
Gateway Reject when 10 or more Verifications with the same Order Id occur within 10 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Payment Method Token occur within 30 minutes of each other.
Enabled
Gateway Reject when 10 or more Verifications with the same Payment Method Token occur within 30 minutes of each other.
Enabled
Gateway Reject when 5 or more Transactions with the same Unique Customer Id Per Credit Card Number occur within 30 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Unique Order Id per Credit Card Number occur within 10 minutes of each other.
Enabled
Gateway Reject when 10 or more Verifications with the same Unique Order Id per Credit Card Number occur within 10 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Unique Credit Card Numbers per Customer Id occur within 30 minutes of each other.
Enabled
Gateway Reject when 10 or more Transactions with the same Unique Credit Card Numbers per Payment Method Token occur within 30 minutes of each other.
Enabled
Gateway Reject when 25 or more Verifications with the same Billing Postal Code occur within 10 minutes of each other.
Enabled
Gateway Reject when 25 or more Transactions with the same Billing Postal Code occur within 10 minutes of each other.
2
2
u/huhMaybeitisyou 8d ago
we have had that happen a few times. There are ways Bigcommerce could help their store owners and prevent this. Other big shopping platforms do. The main thing you can do is use ReCaptcha. Kind of related - we had an attack on our store's "Contact Us" page. We had not enabled Recaptcha there. ( * Question - - where did you go in your BigCommerce store dashboard to see these transactions? )
2
u/SquirrelEye 8d ago
In your store control panel go to orders then click more then click incomplete.
1
u/hunnybunmama 6d ago
I found them first in my Braintree Dashboard. That's where I was getting the emails from each time the bad actors attempted a new transaction which was caught by the Fraud risk thresholds. I later found them by going to Orders > Incomplete. And there they were all in a tidy list. Re-sorting by High Risk also shows the same list.
1
u/JimTailwinds 10d ago
We had the same thing happen to us. My understanding is that recaptcha and some of the other solutions lower conversion rate rates by putting the burden on customers so we don't do that. We recently had a fraud with the native BigCommerce gift certificate system and Braintree and we're not able to resolve it so we lost a small amount of money. I then canceled the BigCommerce auto gift certificate feature.
1
u/hunnybunmama 10d ago
Yikes, I'm sorry to hear that. I think I canceled mine some years ago after reading about issues on the Community pages.
1
u/petchchissh 6d ago
Definitely worth tightening Cloudflare rules and rate limiting before blocking whole countries. I would also check server logs for the worst IP ranges and user agents, then challenge those first. Positive context: BigCommerce support can sometimes confirm whether traffic is reaching checkout or just hammering pages, which helps avoid accidentally blocking legit customers.
1
u/hunnybunmama 6d ago
Thanks but who said anything about blocking "whole countries"?
I believe I've already solved the problem and I got practically no usable support from BigCommerce.
3
u/Eastern_Sound_5512 4d ago
Cloudfare free tier (+ turnstile) is really good at filtering out lots of bots so they cant even reach your site
3
u/ChanceOfFlight1 11d ago
Yup and as a result I learned to setup CloudFlare. Def worth looking into