← Blog

· Irene Llamas

Do you think your eCommerce is secure?

Online stores need to guarantee technical and legal security amid the rise of scams and fraud committed by parties seeking illegal gain

Do you think your eCommerce is secure?

Payment security in eCommerce. Online commerce needs to guarantee technical and legal security amid the rise of scams and fraud committed by parties seeking illegal gain.

Here’s what this blog will cover:

  • These four principles must be guaranteed
  • What are the most widely used security indicators?
  • What needs to be checked manually?
  • How is fraud managed?
  • What types of fraud exist?

These four principles must be guaranteed:

  1. Authenticity: that the person or company claiming to be on the other side of the network is who they say they are.
  2. Integrity: that whatever is transmitted over the network has not been altered.
  3. Privacy: that the data transmitted has not been seen during the electronic transfer.
  4. Non-repudiation: that what was transmitted cannot be denied. A service that provides proof of the integrity and origin of the data.

The security of your eCommerce online payments is a key factor for the conversion rate and builds consumer trust.

What are the most widely used security indicators?

  • SSL
  • 3D Secure
  • CVV2
  • PCI/DSS

SSL – Secure Socket Layer

  • A security protocol that enables information to be sent safely between sender and receiver.
  • A closed padlock in our browser indicates that information is being transmitted securely.
  • It guarantees:
    • Confidentiality
    • Integrity
    • That the website is “who it says it is”.
  • SSL does not confirm the buyer’s identity to the seller, nor does it assure the buyer that the seller is a trustworthy company.

3D-Secure – the three-domain security system

The authentication tasks are split into three parts:

  • The issuing bank authenticates its cardholder directly and by whatever means it deems most appropriate (issuer domain)
  • The acquiring bank authenticates its cardholder directly and by whatever means it deems most appropriate (acquirer domain)
  • The banks authenticate each other and the payment processors through their own established systems (interoperability domain).

CVV2

The CVV2 is the three-digit number that appears on Visa and MasterCard cards (on the back), which cannot be deduced from the card number and is not printed on any receipt or statement.

Stockagile

Put it into practice with Stockagile

Discover how Stockagile helps you with online sales and marketplaces to grow without breaking your operations.

Discover it →

Knowing this number guarantees that the card has been physically handled, which limits the chances of fraud.

PCI / DSS

  • Payment Card Industry / Data Security Standard

  • When banking data is stored, eCommerce sites are required to comply with this standard.

  • We must certify with our acquiring bank that we comply with the requirements set out in the standard.

What needs to be checked manually?

  1. Especially these three types of transactions:
  • High-value purchases
  • Repeat purchases from the same customer
  • Repeated products within the same purchase
  1. Purchases with an international shipping address or a shipping address different from the card’s country of issue.
  • Use IP-checking tools and verify that the IP address and the card’s billing address match.
  1. New buyers who ask to have their purchases shipped urgently, especially if the purchases are made at night.

  2. Orders placed with the same shipping address but different cards, or orders placed with different shipping addresses but the same billing address.

  3. Purchases made from multiple cards but from the same IP

  4. Customers with free email accounts or with email sequences that suggest they were created in bulk.

  5. Keep a record of potentially dangerous postal codes and manually review orders with a delivery address in them.

Seguridad

How is fraud managed?

It is essential to review transactions and payment methods in order to minimize the risk of fraud and guarantee security in eCommerce.

Main actions companies take against fraud:

  • 74% of companies use CVV2
  • 53% Customer history and blacklists
  • 42% IP geolocation

What types of fraud exist?

  • Phishing: deceives the user through an email inviting them to carry out a banking transaction on a page that looks like their bank’s. (identity theft)
  • Pharming: the user accesses, from their browser, a web page that is a duplicate of the original, where confidential data is requested. (identity theft)
  • Internal fraud: an eCommerce site’s employees use their customers’ data in a fraudulent manner.
  • Re-shipping: a fraudster buys from an online store with a stolen card, and the goods are received by a third party.
  • Friendly fraud: the consumer claims not to have received the products and disputes the transaction when in fact they did receive their order.

Discover which type of warehouse fits your eCommerce logistics.

Stockagile

Put it into practice with Stockagile

Discover how Stockagile helps you with online sales and marketplaces to grow without breaking your operations.

Discover it →

Written by

Irene Llamas

Content · Stockagile

Irene writes about inventory management, retail operations and omnichannel strategy. Her guides help merchants understand and improve every part of their operations.