Preventing online payment fraud
binpress.com
Preventing online payment fraud
1–10 of 25 posts
Re: Preventing online payment fraud
#2I don't exactly love conflating buyer's remorse with payment fraud, since buyer's remorse is a psychological phenomenon and happens independently of fraudulent intent. Then again that's a bit hairsplitting.
So, you're a digital goods business. What can you do to reduce the odds that a customer requests a transaction get reversed, given that the customer initially did authorize the transaction?
1) Do nothing. Treat this as a cost of doing business. This works astounding well for many client populations, which have naturally low refund rates. (I'll give you a refund for any reason whatsoever, and I give out substantially less than 2%. Not worth optimizing.)
But maybe you've made the decision to target poor customers, startups, infovores (they buy more books/videos/etc on X than they can consume or make effective use of, and have disproportionately high refund rates), or an audience demographically dissimilar to American housewives. OK, we still have options:
2) Add value to the one-time download by, e.g., providing a support channel gated on having an account in good standing. Note that this also lets you do fantastically lucrative things like e.g. the club model for digital goods (recurring payment for one-time downloads), which e.g. put WooThemes on the map.
3) For infovore-heavy niches, many people will suggest forcing delayed gratification on the customer. For example, let's say you have just sold someone 5 videos / ebooks / etc with expected consumption time of 2 hours each. Rather than hitting them with 10 hours of video all at once, you drip them out to the user at 2 hours per week for 5 weeks. This can be timed such that they don't get the final video until after your money-back guarantee expires. That's totally optional, though. The theory is that a) you avoid overwhelming people and b) getting in their inbox 5 times with announcements of even more value they got from you helps to prevent a common problem of "Oh, didn't actually have enough time to read/watch/act on that because I totally forgot to make that time, guess I should return it."
4) A lot of savvier folks in this space have customer communities where a) the interaction between customers adds value on top of the product, b) desire to maintain the interaction incentivizes people to not leave, and c) customers will (for their own reasons) do significant amounts of boring work for free, such that you don't have to add a not-so-lucrative "Infinite free support" sideline to a lucrative digital goods business.
5) Too late for you now, but for the benefit of everyone else, a great way to avoid getting emails by someone whining about getting a refund for the $8 they spent on your ebook is to never ever ever ever ever do business with people at the $8 price point. SearchHN [patio11 pathological customers] for more on this.
Re: Preventing online payment fraud
#3This article is amazingly worth your time. Endorsement out of the way I have one quibble and some elaboration: I don't exactly love conflating buyer's remorse with payment fraud, since buyer's remorse is a psychological phenomenon and happens independently of fraudulent intent. Then again that's a bit hairsplitting. So, you're a digital goods business. What can you do to reduce the odds that a customer requests a tra…
For some products, what you say makes perfect sense, but for us, since what we sell are code licenses, you can't 'undo' what you learned by using the code. Regardless, we offer 14-day money-back guarantee, and people still sometimes choose to take this approach - issuing a chargeback on their transaction, when it's obviously not regular fraud.
We usually try to communicate with the buyer to understand why he issued a chargeback, and in a few cases we managed to resolve it (so I would never suggest going with your first approach - always try and contact them first). Otherwise we just "eat" the cost and get on with it.
Re: Preventing online payment fraud
#4Thankyou.
Re: Preventing online payment fraud
#5This article is amazingly worth your time. Endorsement out of the way I have one quibble and some elaboration: I don't exactly love conflating buyer's remorse with payment fraud, since buyer's remorse is a psychological phenomenon and happens independently of fraudulent intent. Then again that's a bit hairsplitting. So, you're a digital goods business. What can you do to reduce the odds that a customer requests a tra…
I am the author of the article - thanks for the positive overall comment. I agree with you to a point regarding "buyer's remorse" - perhaps I didn't word it strongly enough. For some products, what you say makes perfect sense, but for us, since what we sell are code licenses, you can't 'undo' what you learned by using the code. Regardless, we offer 14-day money-back guarantee, and people still sometimes choose to tak…
One thing I didn't really see was "previous successful purchase" - that should be a strong indicator of "not fraud". Even if other details look dodgy.
Re: Preventing online payment fraud
#6Earlier quoted context omitted.
I am the author of the article - thanks for the positive overall comment. I agree with you to a point regarding "buyer's remorse" - perhaps I didn't word it strongly enough. For some products, what you say makes perfect sense, but for us, since what we sell are code licenses, you can't 'undo' what you learned by using the code. Regardless, we offer 14-day money-back guarantee, and people still sometimes choose to tak…
Loved the write-up. If you expand outside paypal/ccs into other methods like direct debits (common for Germany) I would be curious to hear similar stories. Accidental chargeback rates are way up on direct debits so any stories for dealing with that efficiently would be very interesting. One thing I didn't really see was "previous successful purchase" - that should be a strong indicator of "not fraud". Even if other d…
Glad you liked it, we had to learn most of this stuff the hard way :)
Re: Preventing online payment fraud
#7Earlier quoted context omitted.
Loved the write-up. If you expand outside paypal/ccs into other methods like direct debits (common for Germany) I would be curious to hear similar stories. Accidental chargeback rates are way up on direct debits so any stories for dealing with that efficiently would be very interesting. One thing I didn't really see was "previous successful purchase" - that should be a strong indicator of "not fraud". Even if other d…
Not sure if "previous successful purchase" is enough of an indicator. If someone can hijack a Paypal account or obtain sensitive credit-card details, you should assume he can also hijack an account on your service. Glad you liked it, we had to learn most of this stuff the hard way :)
May be business dependent tho. I guess selling source code means the people interested in defrauding you are fairly tech savvy too.
And yes, really liked it :)
Re: Preventing online payment fraud
#8I use Cybersource for payment processing on an e-commerce site. I've been really happy with their fraud screening service- automated rules, similar to the list in this post, flag certain orders for manual review. These automated rules have been able to catch orders that, otherwise, might have gone unnoticed and saved a lot of time in the process.
Re: Preventing online payment fraud
#9This article is amazingly worth your time. Endorsement out of the way I have one quibble and some elaboration: I don't exactly love conflating buyer's remorse with payment fraud, since buyer's remorse is a psychological phenomenon and happens independently of fraudulent intent. Then again that's a bit hairsplitting. So, you're a digital goods business. What can you do to reduce the odds that a customer requests a tra…
"a great way to avoid getting emails by someone whining about getting a refund for the $8 they spent on your ebook is to never ever ever ever ever do business with people at the $8 price point."
I have one of those "yes, if," or "no, but" reactions to this statement. If you're doing business at the $8 price point, you should be doing it in the volume business. The scale business. A gazillion tiny purchases at $8 apiece, wherein the userbase is large and fairly undemanding. If the userbase is demanding about anything in this space, you want it to be demanding about price alone, and you want your $8 to be an insanely competitive price.
You should NOT do business at $8 per transaction if your good or service involves a lot of transaction costs -- whether in post-sale servicing, a salesforce of any kind, high-touch / personal presales, high return rates, or, generally speaking, any sort of customization that can't be automated to scale. In very simplistic terms, low prices should not be paired with high costs -- be they high COGS in the traditional sense, or high intensity of time and effort. In the case of most ebooks, I would agree with you here: a low unit cost like $8 [1], positioned to a very demanding niche audience, is a recipe for nightmares.
[1] Temporarily leaving aside, for the sake of everyone's collective sanity, any tangential philosophical debate about whether $8 is a "low" price.
Re: Preventing online payment fraud
#10The first is 3DSecure (or VbV). They are the most secure ways to accept credit cards, though they aren't as easy for users to use. However, they do go a long way to protecting the merchant. If your handling b2b transactions that are high risk, you might consider enforcing this. Again, it's not a solution to wield lightly, but it is a solution.
Also, you can require out-of-band authentication. Generally, this is in the way of making a telephone call, and requiring the user to input a 4-digit pin. This, combined with everything else, will help hinder potential fraud. More importantly, it helps to protect against friendly fraud.
Of the two, telephone authentication is easiest to implement, but do not discount 3DS for higher priced purchases.