Fraud doesn't just cost you money directly. High fraud rates drive up your chargeback ratio, trigger processor reviews, and can result in account termination. By the time fraud is visible on your statement, it's already affecting your risk profile with your processor.
The fraud problem merchants actually face
Most merchants think about fraud as a revenue loss problem. It is, but that's only the beginning. Every fraudulent transaction that results in a chargeback counts against your dispute ratio. A fraud wave at high volume can push you into a Visa or Mastercard monitoring program within a single billing cycle.
The tools that prevent this look different depending on your business model, your volume, and how your customers transact. A rules set that protects a $50K/month business often creates unacceptable false-positive rates at $500K/month. We build fraud strategies that fit your actual situation.
Where fraud enters and how to stop it
Velocity controls
Limit the number of transactions, declined attempts, or card number variations from a single IP, device, or shipping address in a given window. The single most effective first line of defense against card testing.
Device fingerprinting
Identify devices attempting multiple orders across different card numbers or customer accounts. Fraudsters rotate cards; device fingerprinting catches patterns human review would miss.
AVS and CVV rules
Address Verification and card security code matching are basic but frequently misconfigured. We review your current rules to make sure you're declining the right failures without over-blocking legitimate orders.
Geolocation screening
Flag or block orders where billing address, shipping address, IP location, and card issuer country don't match expected patterns for your customer base.
Third-party fraud tools
Kount, Signifyd, Sift, and similar platforms add machine-learning fraud scoring on top of basic gateway rules. We help you select, configure, and tune these tools for your transaction profile.
Manual review queues
High-value or high-risk orders that don't trigger automatic decline but warrant a closer look. We help you build review workflows that don't slow down legitimate orders or create customer service problems.
The false-positive problem
Aggressive fraud rules block fraud. They also block legitimate customers. A false-positive rate above 2 to 3% is costing you real revenue and creating customer service issues. Getting the balance right requires tuning rules against your actual transaction data, not a default ruleset.
CambridgeCommerce reviews your decline rates, false-positive estimates, and fraud loss data together to find the right calibration. The goal isn't zero fraud; it's a fraud rate low enough to protect your account and margins without over-screening your customers.
Card testing: A common attack pattern where fraudsters use stolen card data to make small test purchases and verify which cards are active before making larger fraudulent purchases. Velocity controls and CAPTCHA are the primary defenses. If you're seeing unusually high declined transaction rates on small-value orders, you may be under a card testing attack right now.
"We had a card testing attack hit us over a weekend. Cambridge identified it Monday morning from our transaction patterns, told us exactly what to change in our gateway rules, and we had it stopped by Tuesday. The damage was limited because they caught it fast."Ecommerce merchant, consumer electronics Card testing attack contained within 48 hours