Bad actors often use website donation pages to test stolen credit card numbers, making small donations in the $1.00 - $2.00 range, to verify if the card can be used.
https://www.thenonprofittimes.com/npt_articles/crooks-use-online-donations-test-credit-card-fraud/
To protect against this type of fraudulent activity, the following items are recommended:
Enable CAPTCHA Security on your donation page:
iMIS 2017 GA (20.2.64.xxxx/20.2.65.xxxx):
https://documentation.advsol.com/imis/v3.0/docs/enabling-captcha-security
iMIS Cloud Enterprise (20.3.xx.xxxx):
https://documentation.advsol.com/imis/docs/contact-settings-account-management#recaptcha-settings
Enable the card security code (CSC) option for credit cards:
iMIS 2017 GA (20.2.64.xxxx/20.2.65.xxxx):
https://documentation.advsol.com/imis/v3.0/docs/authorizing-credit-cards-and-debit-cards
iMIS Cloud Enterprise (20.3.xx.xxxx):
https://documentation.advsol.com/imis/docs/payment-methods-and-payment-method-sets
Require an address and email address. iMIS uses the Address Verification Service (AVS) to verify the address is valid.
Create a donation payment alert on a Staff Dashboard page to alert staff of low dollar amount donations (ie $1.00 - $2.00 range), if this is not normally given.
Sign up for Fraud Protection Services from your credit card processing vendor.
*Also see the following TechAlert article:
0 Comments