Credit Card Phishing Checklist

If your organization is experiencing credit card phishing, here are some helpful tips you can check to help prevent fraudulent activities.


  • Make sure your campaigns are set with a minimum amount. Usually, bots that do the phishing either push $1 donations to test if the cards can go through successfully. Setting up a minimum amount higher than $1 can help prevent those bots from even attempting. We suggest to set at least $9 as a minimum amount. *Note: Before setting up a minimum amount, please contact your processor first as some processors need to set the minimum amount donation on their side as well. Once your processor side is set, you can go ahead and add the minimum in Site Stacker.


Learn how to set up minimum/maximum amounts for campaigns.


  • Make sure you have Google reCAPTCHA set in your checkout page. Setting up a Google reCAPTCHA can also help with preventing bots in phishing fraudulent donations. Most of the time, Google reCAPTCHA can stop the transactions from the checkout page before the bots can even submit the donation process. If you are experiencing credit card fraud, we highly suggest that the Google reCAPTCHA is set.


Learn how to setup the Google reCAPTCHA in your Checkout page.


  • For successful fraudulent donations, you will have to refund those transactions back. You can also choose to delete the transactions after you refunded them and delete the donor's CRM record as well.


Learn how to refund donations.


  • Report the fraudulent transactions to your payment processor. They can provide more information on how to handle this situation and maybe able to help you in refunding some of the successful transactions.


*Note: For Payment Spring clients, we suggest that you enable AVS and CVV verification. This can be done in your Payment Spring dashboard. You can connect with their support to better assist you in enabling those.


Lastly, if the fraudulent transactions still persist, the last resort we can do is to put the site offline. This is not the ideal solution, but putting the site offline for a specific time can help in stopping active credit card phishing activities in your website. We highly suggest connecting with our support team should you wish to put the site offline for a specific timeframe.


Modified on Tue, 26 Sep 2023 at 04:18 PM

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select atleast one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article

Make sure these features are added to your Site Stacker installation by learning how to run updates here!