Cyber Weekend Cyber Security

Liz Morton
Liz Morton


Comments

As the busy Q4 holiday shopping rush heats up, so do fraudsters' efforts - especially online. There are many articles that tackle the subject from the buying side with helpful advice about avoiding phishing scams, being wary of "too good to be true" deals, and protecting your personal information.

Don’t fall for these clever Black Friday scams this year
Scammers don’t take time off during the holidays. Here’s what to look out for and how you can protect yourself.
Fraud warning over ‘too good to be true’ Christmas bargains
If it seems too good to be true, it probably is.
6 Black Friday scams and how to avoid them
A look at common Black Friday scams and help on how to do your holiday shopping without becoming a victim in 2021. Plus, learn what to do if you get scammed.

But what should merchants be doing to protect themselves, and their legitimate customers, from security breaches and fraud attempts?

First and foremost, make sure whatever ecommerce platform or site builder you're using is running with the most recent security patches and updates. The same goes for any payment processing software or third party apps you may be using.

Hackers used this software flaw to steal credit card details from thousands of online retailers | ZDNet
Hackers used flaw in popular e-commerce software.

It's also a good idea to partner with payment processors who offer seller protection for unauthorized transactions and/or engage the services of fraud detection and prevention companies that specialize in protecting ecommerce companies from fraud.

If you use PayPal to process credit card payments on your site, you may be eligible for Chargeback Protection for additional fees. If your payment processor doesn't offer that type of protection, there are many software as a service solutions like Signifyed, Kount, Eye4Fraud, NoFraud and more.

I don't endorse any particular solution. Every business is different and you'll need to research to see what best fits your specific budget and needs. But I do highly endorse having some kind of fraud detection and prevention plan in place.

If you're concerned about the expense and weighing whether it's worth it - trust me, you don't want to be scrambling to put something in place after you've already been hit with hundreds of thousands of dollars in fraudulent orders.

Triangulation Fraud - What Is It & How Can You Protect Yourself?
Multi-channel ecommerce businesses using 3rd party marketplaces may be targeted by this sophisticated fraud.

If you sell on third party marketplaces, you'll want to take additional precautions for those parts of your business as well. The marketplaces provide the security infrastructure and seller protection policies for their sites and there is very little control you may have in that regard, but sellers can still work to mitigate their exposure to fraud through these marketplaces.

The following advice can be applied broadly to any marketplace, but since this site is dedicated to the eBay selling experience I'll give more eBay specific examples as well.

One of the most important ways to protect yourself is to secure your account credentials and information. Account takeover fraud is a serious problem, especially on eBay.

This type of fraud occurs when bad actors gain access to your account and use it to create fake items for sale or change payment details to siphon off funds from your existing listings.

A few years ago, fraudsters would simply change the PayPal email address on listings to divert money to their own accounts.

Ebay fraudsters scammed me 11,000 separate times and cost me £54,000
Camped inside Richard Crisp’s eBay account like a virus, scammers set up fake PayPal accounts that were almost identical to his one and changed a small number of eBay listings each day.

eBay has stated that Managed Payments will prevent this type of fraud going forward because they are required to collect and verify information about accountholders under various Know Your Customer laws and regulations. In theory, that should prevent fraudsters from placing fake listings and diverting funds to alternate bank accounts, but in practice that doesn't seem to be slowing them down much.

Grimsby businessman facing ruin after eBay account ‘hacked’
Phil Green has had to lay off staff and more could suffer after £14,000 hacking scam on his Nunsthorpe business

It takes many forms, from the triangulation fraud I personally experienced to the ubiquitous eBay car scams and across all categories on eBay, but one thing they have in common is the use of compromised accounts to perpetrate fraud on the platform.

Unfortunately in these situations, even once the fraud is discovered and the account has been re-secured, there is often a huge cost to the seller.

I've seen reports that eBay may attempt to recover refunds and fees for the fraudulent orders from the legitimate seller's bank account or payment method on file, even though they did not receive the original funds and are an innocent victim in the scheme. Some sellers have even had their accounts shut down and been hounded by collection agencies over unpaid fees stemming from fraudulent orders.

It's not clear exactly how these accounts are being compromised - is it lazy password and security practices on the part of the accountholder or have bad actors discovered reliable ways to access accounts through brute force measures or larger security vulnerabilities?

Here are some basic security measures all sellers should be taking to secure their marketplace accounts:

  • Unique Log In Credentials That Are Changed Often - never use the same password for your selling account that you use for any other online accounts or transactions and change passwords often. To take it a step further, create an email address specifically for your selling account and don't use it anywhere else on the web.

  • Don't Click On Links In Emails or Text Messages - Phishing scams can be elaborate and sophisticated and it's not always easy to tell if an email is real or not. The easiest way to avoid this trap is to simply open a new browser window and navigate directly to a site to log in rather than clicking through from an email or text.

  • Separate Bank Account - if you're doing any real volume of business as an online seller, there are many good reasons to keep your business accounting separate from your personal finances and fraud is definitely one of them.

  • Two Factor Authentication (2FA) - there are mixed feelings on this one in the cyber security world, especially when the authentication is done through SMS text messaging. However, generally speaking, I think it is still an important precaution to take when possible.

More from eBay on how to get help with a compromised account -

Get help with a hacked account
If you think someone is trying to take over your account—or already has—we’ll work with you to secure it. For your protection, we may place a temporary hold on your account.

Have you been a victim of account takeover fraud? I'd love to hear your story! Leave a comment below or reach out on Twitter, Facebook or email.

eBayFraud

Liz Morton Twitter Facebook LinkedIn

Liz Morton is a seasoned ecommerce pro with 17 years of online marketplace sales experience, providing commentary, analysis & news about eBay, Etsy, Amazon, Shopify & more at Value Added Resource!


Recent Comments