Skip to main content
Michelle Chang (SPUR) a posé une question dans #Nonprofit

Hi amazing community, 

Our nonprofit website is getting more and more frequent fraudulent credit card attacks on our payment site. Bad actors are using our site to test out credit cards with $3 dollar charges. Sometimes they run 5 charges to 80 charges at a time. Luckily our payment portal's fraud tools prevents any of these transactions but it leaves us with technical debt (contacts being created). Is there any way to prevent this from happening in the first place? Does it depend on which payment portal we are using? Are there ways to discourage use of our website for these criminal purposes? We can't just turn our payment gateway off. Would love to know if this happens to others and for any advice.  

 

#Nonprofit  #Nonprofit Success Pack  #Paymentgateway  #Payment Method

1 réponse
  1. 6 nov. 2025, 19:25

    Good afternoon, Michelle, 

     

    I took a look at SPUR’s donation page and noticed you already have CAPTCHA in place, which is a great first step to block automated bots. A few clarifying questions would help guide the best approach to reduce fraudulent card testing while keeping the donation process accessible: 

     

    1. Which payment processor are you using? Does it support features like velocity checks, per-IP limits, AVS/CVV verification, or other fraud scoring tools? 

     

    2. Would it be acceptable to enforce a slightly higher minimum donation in the “Other” box or temporarily block repeated very small-dollar submissions from the same IP or card? 

     

    3. Do failed or blocked transactions still create Contacts or other records in Salesforce? Would automation to flag or clean up these attempts be useful? 

     

    4. Do you need donors from across the Bay Area (or beyond) to always succeed, even if there are multiple small donations from shared IPs? Are more aggressive anti-fraud measures acceptable if they reduce card testing? 

     

    Some payment gateways like Stripe offer built-in fraud protection (velocity limits, IP restrictions, CVV verification, and fraud scoring) for a fee. On the lower-cost side, keeping CAPTCHA, slightly increasing the minimum donation could provide meaningful protection. 

     

    Be well- Katende

0/9000