Live data from Hacker News

Candy Japan hit with credit card fraud

candyjapan.com

41–50 of 208 posts

Re: Candy Japan hit with credit card fraud

#42
post #37

But why? Ordering periodic shipments of candy from Japan? Most credit card fraud involves something that can be resold. This service gets you a small envelope of candy. It's not like getting cases of Pocky.

" The stolen cards originate from credit card security breaches, resulting in a big list of card numbers. These are later sold online in packs filtered to working card numbers only, which can be purchased for about $10 per valid card.

To be able to compile and sell these packs, the carders need to know which ones are valid. To do this, they will use an online store or service to place an order for the sole purpose of seeing if the charge goes through or not.

Re: Candy Japan hit with credit card fraud

#44
post #37

But why? Ordering periodic shipments of candy from Japan? Most credit card fraud involves something that can be resold. This service gets you a small envelope of candy. It's not like getting cases of Pocky.

Test on one site, buy something substantial on another?

Re: Candy Japan hit with credit card fraud

#45

Did you considered to accept Bitcoin payments? This way you wouldn't have to worry about chargebacks.

Bitcoin is not the best thing for recurring payment. But it would be great to pay a year in advance with Bitcoin - and yes that solves chargebacks or fraud issues.

Re: Candy Japan hit with credit card fraud

#46
post #43
post #29

Earlier quoted context omitted.

ZIP codes are just a funny name for post codes, and most places have postcodes.

Damn you Ireland and your "no postcodes" hell.

We have postcodes now! Or well, eircodes. Which are totally not postcodes, but rather unique house identifiers that happen to look as postcodes. And that noone will use.

http://www.eircode.ie/

Re: Candy Japan hit with credit card fraud

#47
I don't understand the search conversion statistic. If a guy is testing a bunch of cards, wouldn't he just find your site once and try them all sequentially?

If a bunch of people had bought these packs of stolen cards, wouldn't they be spreading out over a bunch of different sites?

Re: Candy Japan hit with credit card fraud

#48
post #6

Earlier quoted context omitted.

This issue is so costly and prevalent that I feel its a huge disservice for companies that offer credit card services to merchants to not either 1) mention this issue and recommend a fraud check service, or 2) include fraud protection in their service. I actually ran into an issue a little while ago in that I allowed my MaxMind account to run out of queries. Not realizing this, I saw a few days of higher than normal…

Since pro accounts initially cost £6 for month, it turns out that this is low enough that it won't send red flags to stolen cards That's interesting (scary). What is the minimum transaction that Visa actually gives a monkeys about? And why, if a card is stolen, does not any activity flag up? Edit: more importantly I never even thought Inwoukd need to implement fraud detection - is there a primer on "things you never…

It's not normally a single transaction that triggers the fraud detection, but a small initial transaction (say So if you sell something small, you'll be used to validate newly bought cards before they go off and buy $1000 of something else.

Re: Candy Japan hit with credit card fraud

#50
i simple solution to cut down on this is never allow more than 2 or 3 failed card attempt from a single ip address. You have to link it by ip because they will just make a new account if you do it by account. Carder will move on to another site if running cards is not simple and fast
Post reply on HN