• Follow all terminal prompts;
• Keep the terminal in sight during each transaction
and recover it from the customer as soon as they have
entered their PIN;
• Be aware if a customer tries to distract you whilst the
transaction is being undertaken, especially during the
authorisation stage, as they may be trying to prevent
you from noticing a problem with the authorisation;
• If an authorisation code has been manually entered
into the terminal, it will state that on the receipt. If you
are suspicious of a ³¦³Ü²õ³Ù´Ç³¾±ð°ù’s behaviour with the
terminal, you should check the receipt before
completing the sale. If a manual authorisation code
has been entered, you must cancel the transaction
and complete a new transaction.
• Be aware of ‘o³Ü³Ù of the ´Ç°ù»å¾±²Ô²¹°ù²â’ purchases e.g.
the bulk purchase of random goods or of clothes in
varying sizes. Most customers take care when making
a purchase and try clothing on, whilst a fraudster is
more likely to be careless and hasty and will look to
buy goods that they can easily re-sell.
If transactions are undertaken by way of magnetic strip
and signature or PKE make sure that:
• The security features on the card are present and
correct;
• The signature strip has not been tampered with or
that another strip has not been placed over the top of
the original;
• The signature appears original. If the word ‘v´Ç¾±»å’
appears on the strip, it may indicate that the original
signature has been removed. If the signature is in felt-
tip pen it may be over-writing the original, which
should be in ballpoint pen;
• The cardholder’s signature matches that on the card;
• The gender of the card presenter matches the title on
the card; and
• The last four digits of the card number on the receipt
match those on the front of the card.
Card-Not-Present Transactions
Given the increased risk posed by CNP transactions, you
and your staff should be aware of the warning signs that
may indicate that a transaction or transactions may be
fraudulent:
• Unmatched CVV2 and/or AVS data - consider
undertaking additional checks to verify the
transaction and/or rejection of it;
• Multiple orders on the same or different card numbers
from the same customer;
• A first-time customer who places multiple or
high value orders – known customers are clearly of
lower risk;
• The purchase of high volumes of goods which are easy
to re-sell and desirable, for examle electrical
equipment (televisions, computers, mobile phones),
and jewellery;
• Multiple orders on cards that contain the same first
six digits (BIN), especially if one or more of the card
numbers is declined and an alternative offered
immediately afterwards;
• Multiple transactions on various different cards, from
either the same or different customers, where the
goods are to be delivered to the same address;
• A request for urgent delivery when any additional
delivery costs are of no concern to the customer;
• An out of the ordinary purchase where delivery is to
an overseas address – if overseas orders are unusual,
take time to consider why this customer has chosen
your business;
• Orders where the delivery address is different to the
billing address, especially if the delivery address is for
example a PO box or hotel;
• A request to hand goods over to a third party e.g. a
taxi driver, courier, messenger or chauffeur sent by
the customer to collect them.
Within the E-commerce environment, also look out for:
• Any alert from your PSP that may indicate that the
transaction is of higher risk;
• The same IP address being used by multiple customers
e.g. orders originating from the same IP address but
with different shopper names and e-mail addresses;
• Orders where the cardholder billing country, IP
country and card issuer country do not match;
• An e-mail address that bears no resemblance to the
shopper name, or where the shopper details (e-mail,
name, address) are illogical or fictional characters;
• Multiple transactions being attempted by one
shopper on multiple cards;
• Card testing – where multiple transactions are
attempted on cards that appear to run in close
sequence.
Minimise the risk of becoming a victim of CNP fraud by
always following these guidelines and making use of the
security tools available. For MOTO transactions use
CVV2 and AVS checking and for E-commerce
transactions also offer cardholder authentication
through Verified by Visa, MasterCard SecureCode and
UnionPay Secure Plus.
If suspicious, take steps to further verify your
³¦³Ü²õ³Ù´Ç³¾±ð°ù’s identity. Try contacting them using the
contact details (e-mail and phone number, a landline is
preferable) that they have given you.
Always try to deliver goods to the individual who placed
the order and to ³¦²¹°ù»å³ó´Ç±ô»å±ð°ù’s billing address, do not
hand goods over to someone waiting outside. Obtain a
signature from the cardholder as proof of delivery and
keep this with your transactional records in case a
dispute arises.