I also had something like this happen on a site I built for my wife's work's site, a Boys & Girls Club[0]. I had a donation button that let people make an open donation to the club. It's such a tiny site with little traffic, but apparently the SEO must be decent because somehow it got targeted by people appearing to come through Brazil and Poland. Suddenly one day, hundreds of donation attempts. Checking the failed t…
Wait, why would someone fraudulently donate somewhere? I don't understand the motive.
1: Using the site as a credit card validator. Only the real ones will get through.
2: By making donations to places with a stolen credit card little bits at a time, it establishes a wider pattern of use for that card. Fast forward a couple steps ahead, the purchases are getting a little weirder each time, and before you know it, you're at whatever level people use stolen cards to buy.
3: Tiny non-profits generally do not have a great deal of extra man-power to deal with such things, and there's a better chance that this sort of behavior goes unnoticed.
4: When people see weird charges on their card, some people are more likely to feel bad enough taking away money from a non-profit organization that they won't report the abuse, or they may not question it if the card is joint-used.
I'm sorry that I don't have sources on these, the research was from a couple of months ago. It's pretty frustrating and there seems to be little retribution for things. You have to just change your charge flow and move on. :/