Fraud Prevention
3 minute read

Have you noticed small, unexplained card payments to your firm?

Fraudsters can use ‘pay online’ pages on law firm websites to test stolen credit and debit card information. If you allow anyone to make a card payment to your firm through your website, you may inadvertently be enabling card fraud.

What is card testing fraud?

Card testing fraud, also known as card cracking or account testing, is a type of fraudulent activity in which criminals test stolen or generated credit or debit card information to see if it is valid. This information can be obtained through phishing attacks, data breaches, or other malicious means.

Once the criminals have a list of card numbers, they will attempt to make small, unauthorised transactions through the payment pages of company websites - such as those of a law firm.

These transactions are typically for low amounts, such as £1 or £2, and are often made at different times and locations. If a transaction is approved, the criminal knows that the card is valid and can then use it to make larger purchases or sell it to other criminals.

Consequences of card testing fraud

Card testing results in remote purchase (card not present) fraud. According to the latest figures from UK Finance over 2 million cases were recorded in the last year alone (July 2022 - June 2023) with losses totaling more than £370m.

Card testing fraud can have a number of negative consequences for both the company taking the card payment, as well as their customers:

  • The company may lose money on fraudulent transactions that are approved.
  • Companies may also be charged fees by their payment processors for fraudulent transactions.
  • Customers will face the inconvenience of cancelling their existing cards, as well as potentially having to identify and claim back money lost through their bank.
  • Customers may also have their credit scores damaged as a result of fraudulent activity - especially if they cannot pay other bills because their balance is lower than it should be due to fraudulent activity.

How law firms can prevent card testing fraud

There are a number of things that law firms can do to prevent card testing fraud taking place through the payment services on their website today:

  • Set a minimum card payment amount to prevent criminals testing low amounts (e.g. £100 minimum).
  • Implement website traffic checks to limit the number of times a given IP address can access payment pages in a given period of time.
  • Require additional authentication factors before the website payment page can be accessed (e.g. make it password protected).

In order to better prevent card testing fraud in the long term, firms should consider using a secure payment gateway, such as Safe Capital. In addition to helping to prevent card testing and other payment fraud, Safe Capital helps firms ensure that card and bank payments are only coming from known clients.

Read our latest white paper to find out more >>>

About Safe Capital

Safe Capital makes it simple for law firms to request, receive or return client money swiftly, safely and securely.

Share & Receive Bank Details Securely

Find out more

Residual Balance Management & Reduction

Find out more

Swift Secure Client Payments

Find out more

Related Articles

See All
Bank Account Name Checks - When a Match may be Misleading
When making a payment, a positive match from the account name check is not confirmation that the bank account belongs to a client.
Five Tips for Preventing Residual Balances
This article explores residual balances, how they arise, and the importance of proper safeguards to ensure client funds are protected.
Accountant’s Reports: When are Residual Balances a Red Flag?
This article considers situations where an accountant might need to issue a "qualified" report due to residual balances
Published: 31st October 2023
Credits

Any questions?

Email us at hello@safecapital.co.uk

Need Support?

Email us at help@safecapital.co.uk

Logo

© 2024 Luris Systems Ltd, trading as Safe Capital. Luris Systems Ltd is a limited company registered in England and Wales (registered number 15361556). Our registered office address is 41 Bridgeman Terrace, Wigan, England, WN1 1TT. Registered with the ICO (registration number ZB645907).

Safe Capital is powered by Moneyhub Financial Technology Limited who are authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 for the provision of payment initiation and account information services (firm reference number 809360).

We use cookies to distinguish you from other users of our Site and analyse our traffic. Learn more