Basic Fraud Prevention for Internet Merchants

This article talks about a very important issue forlimitations, because this may impact your
Internet merchants . . . preventing online fraud.decision-making about how to treat bad
Most of the attention in the press surroundingverification results:
online fraud is focused on consumers...whether its-The AVS system isn't always reliable; bad results
having their credit card numbers stolen bycan be triggered unnecessarily because people
hackers or being suckered into giving theirmove, or because some people report five-digit
personal and financial information by a phony emailzip codes and some report nine-digit zip codes.
phishing scam. But barely any attention has beenThis may generate a response stating that the
given to the other side of the coin...the Internetaddress matches, but the zip code does not
merchants who are defrauded by crooks posingmatch.
as legitimate consumers.-The AVS system can't handle addresses outside
One of the first things you need to do as athe U.S., so if you decide to ship only to
merchant to prevent fraud is to always verifyaddresses with good AVS results, you will rule out
who the consumer is. On card-presentall international orders. Online merchants typically
transactions, this can easily be done by asking fordo not rely solely on the AVS result to accept or
a valid photo identification card, for example, areject an order. Most online merchants use the
driver's license or state issued ID card. Onaddress verification service as part of an overall
card-not-present-transactions, this is a much morefraud prevention program and in conjunction with
difficult task for the merchant to accomplish.several other tools to help them prevent fraud.
There are two basic steps that every onlineNow we'll talk about the second step in basic
merchant should follow to ensure that thefraud prevention - Card Code Verification
consumer is legitimate.To help reduce fraud in the card-not-present
The first step in preventing fraud in a card-notenvironment, credit card companies have
present environment is called address verificationintroduced a card code program. Visa(R) calls this
or AVS. The consumer should be required tocode Card Verification Value (CVV);
enter their billing address when they are filling outMasterCard(R) calls it Card Validation Code (CVC);
their credit card information. The paymentDiscover(R) and American Express call it Card ID
gateway will then send this information to the(CID).. The card code is a three- or four- digit
payment processor for verification. The paymentsecurity code that is printed on the back of cards.
processor will then pass the address informationThe number typically appears at the end of the
to the issuing bank who will then match thatsignature panel. This program helps validate that a
information with the address information theygenuine card is being used during a transaction.
have on file for that card. The payment gatewayCard code verification works similar to address
will then send back some codes to let you knowverification. The payment gateway passes the
whether or not the AVS was a match. AVS onlycode entered by the consumer to the payment
compares the street number and ZIP codeprocessor who then compares it to what is on file
against the information on file with the card issuingat the card issuing bank. The payment gateway
bank.. So if the street address was 1234 Mainthen returns a code to let you know whether the
Street and the ZIP code was 90210, thenumbers matched. This helps to verify that the
transaction processor would compare 1234 andperson using the card has the card in their
90210 with the issuing bank's information.possession at the time they place the order.
Once this process is completed, you will get anWe advise all merchants to require this code for
AVS code that tells you how well the addressall credit card transactions to help combat fraud. It
matched the bank's records. If you get an AVSis important to note however that these numbers
code indicating that the address and/or zip codecan be obtained by fraudsters just as credit card
do not match, it is up to you to decide whethernumbers are obtained if they are stored by the
you wish to accept the risk and ship the goods tomerchant. It is for that reason that the card
the customer. We recommend that you do notassociations prohibit merchants from storing these
ship goods in cases where the zip codes do notcodes in their system.The use of CVV2, CVC2 ,
match. This will not only help to preventand CID by online merchants has continued to
chargebacks but will also prevent problems fromincrease, rising from 44% of online merchants
occurring if the consumer works during the day.using this tool in 2003 to 66% today. It appears
The shipping companies have become sothat asking for the CVV2 , CVC2, and CID has
inundated with packages from the ever-growingbecome standard practice for the majority of
Internet world that they will drop the package atonline merchants.
the door, often times not waiting for a signature.So there you have it. Two very basic and easy
Without a signature, you do not have proof offraud prevention tools that every online merchant
delivery. And without proof of delivery it is veryshould use to prevent fraud and eliminate
hard to fight a chargeback.chargebacks.
It is important to know that AVS has some