logo
Welcome to our new AbleCommerce forums. As a guest, you may view the information here. To post to this forum, you must have a registered account with us, either as a new user evaluating AbleCommerce or an existing user of the application. For all questions related to the older version of Gold and earlier, please go to AbleCommerce Gold forum. Please use your AbleCommerce username and password to Login. New Registrations are disabled.

Notification

Icon
Error

Options
Go to last post Go to first unread
Lynsperf  
#1 Posted : Thursday, December 7, 2023 8:23:49 AM(UTC)
Lynsperf

Rank: Member

Groups: HelpDesk
Joined: 11/15/2021(UTC)
Posts: 10

Recently I started getting a bunch of abandoned carts in my Reports section of the customer abandoned carts.
For one day they had racked up over a million dollars worth of product orders using the same product multiple times added to the cart.
Sometimes they went in as a guest, but other times they used ficticious emails tocreate an account.

Anyone else experienceing this?

Wanna join the discussion?! Login to your AbleCommerce Forums forum account. New Registrations are disabled.

judy at Web2Market  
#2 Posted : Friday, December 8, 2023 6:45:22 AM(UTC)
judy at Web2Market

Rank: Advanced Member

Groups: Developers
Joined: 11/7/2018(UTC)
Posts: 289

Thanks: 21 times
Was thanked: 5 time(s) in 5 post(s)
We had one site report it going further- they had someone placing bunches of orders for the same product using fraudulent credit card numbers. I think when I searched for the user name, there were 800+ instances because they were allowing anonymous checkout. By the way- they were accepting orders that hadn't passed AVS and CVV checks. When they changed those settings the orders stopped coming in, but I don't know if the person quit trying.
ray22901031  
#3 Posted : Friday, December 8, 2023 12:14:00 PM(UTC)
ray22901031

Rank: Advanced Member

Groups: Authorized User, Developers
Joined: 2/17/2019(UTC)
Posts: 827

Thanks: 3 times
Was thanked: 13 time(s) in 13 post(s)
This is probably being done automatically through a logarithm trying to hack the site. This is where a firewall with rate limiting rules comes in extremely handy. If the firewall sees the same pattern within a given time frame, it will ask for verification to ensure you are a human, or you can slow down the process by adding pause gaps.

-Ray
Users browsing this topic
Guest (2)
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.