Announcement

Collapse
No announcement yet.

Fraudulent orders via Secpay and 'Mandatory digest checking'

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Fraudulent orders via Secpay and 'Mandatory digest checking'

    Anyone here understand this? I've been getting loads of orders from fraudsters trying to use my site. Secpay have sent this... Can anybody tell me what I need to do?

    This is an urgent notification regarding the current security options you have chosen for your account, pedigr01.

    We have noticed a small number of merchants being targeted by fraudsters who are exploiting merchants' accounts to verify stolen or generated card numbers. In each instance this has been because Manadatory Digest Checking has not been enabled on the account.

    Unfortunately it would appear that you do not currently have Mandatory Digest Checking enabled on your account which leaves you vulnerable to this kind of activity.

    We do give merchants the opportunity to use all the security features that our system provides to block fraudsters but we have to allow these features to be deactivated because occasionally our clients have legitimate business reasons to do so.

    However merchants that opt out of these features do so at their own risk and it is therefore the merchants' responsibility to ensure the validity of the transactions processed through their account.

    You need to be aware that you will be liable for any charges arising from this kind of fraudulent activity.

    We therefore strongly recommend that you implement Mandatory Digest Checking in your website communications with SECPay as a matter of priority.

    Please refer to our Integration Guide section 9 for details on how to implement this relatively straightforward change.

    http://www.secpay.com/secpay/index.p.../full/664.html

    Once the digest has been implemented and tested, please send a confirmation e-mail to admin@secpay.com and request that the 'req_digest=true' option be added to your account.

    By implementing Mandatory Digest Checking you will be protected against this method of fraud.

    #2
    Given that it has a spelling mistake in it, i'd proceed with caution and advise you ring them to confirm it is actually from them.

    Comment


      #3
      Can anybody tell me what I need to do?
      B****r all. Actinic doesn't support the digest hash in the outgoing connection. If secpay turn on "req_digest=true" then all your customers will see is a page that says 'possible fraud attempt' rather than the payment page.

      I would suggest you get on to Actinic about it and give them an earful. It's not a difficult thing to do but Actinic are playing dumb on this.

      Mike
      -----------------------------------------

      First Tackle - Fly Fishing and Game Angling

      -----------------------------------------

      Comment


        #4
        Thanks for the response chaps.

        Given that Actinic doesn't support this feature then is the only option to change to a different payment gateway like ProTx. Or will the same issue happen then?

        And, sorry if this is a dumb question, but would having an SSL on the site help in any way?

        TIA

        Chris

        Comment


          #5
          SSL might make a difference as presumably it could mean the handover to secpay is encrypted and therefor harder for someone else to spoof. I can only say that of the two sites I have that use secpay, the one that suffered from this problem is the one without SSL.

          There might be progress on this issue though. I followed up on secpay's recent message and just got this in reply:

          The Actinic SECPay Payment Module does not currently support digest authentication from merchants to SECPay.

          We have been speaking with Actinic to try to agree a way forward to implement this functionality and hope to resolve this very soon.
          'Very soon' sounds rather positive.

          Mike
          -----------------------------------------

          First Tackle - Fly Fishing and Game Angling

          -----------------------------------------

          Comment

          Working...
          X