Something went wrong. Try again later

rorie

Hello!

7888 1502 54 39385
Forum Posts Wiki Points Following Followers

The Incredible Tale of the PCI DSS SAQ

People often ask me what I do around here, and it's a valid question, since so much of what I do is not publicly visible. Needless to say, there's a lot of weird stuff that Giant Bomb has going on in the background that other sites in the CBSi family don't have to deal with, largely because many of them don't feature subscription services, nor do they have storefronts through which they sell merchandise. So I figured I'd start writing the occasional blog about what keeps me busy on a day to day basis.

No Caption Provided

Lately it's been monitoring our store. You may have used the store in the past to get a t-shirt or poster or something, and if you did, then thanks! We don’t make a huge amount of money from the store, since we generally try to offer merchandise of a decent level of quality without making the prices too crazy, which means our costs are pretty close to the list price of most of the items we offer. We make some money on each order, but no one’s taking baths in Cristal or anything.

Normally, that’s all fine and good, except when we start getting people trying to make fraudulent orders, as has been happening with increasing frequency of late. Our store is run through Shopify, which automatically takes a look at each order and pops up various flags based on suspicious activity, such as billing address not matching where the credit card’s registered and CVVs not matching.

EDIT: To be clear, none of the below should be taken as an indicator that Giant Bomb has any kind of security issue with its store. We don't even have access to your credit card numbers; everything we do is through third-party vendors that keep all that stuff locked up good and tight. People are using credit card numbers they've stolen elsewhere; felt like a good idea to make that clear.

Those are both pretty good indicators that someone’s using a stolen credit card to place an order, especially the mismatched CVV. The CVV’s the little three-digit code on the back of the card that you’re usually asked to enter when placing an order online; the Payment Card Industry Data Security Standard prevents it from being stored, so when credit card records are breached, hackers usually just get the card number but have to make a guess at the CVV. It’s pretty rare that anyone using a valid card won’t know or be able to access their CVV, since it’s right there on the back of the card, so mismatched CVVs are usually an excellent indicator that an order is fraudulent.

No Caption Provided

(As an aside, I’m also the guy who has to report on our PCI compliance, which involves wonderful things like payment data flow diagrams and something called a PCI DSS SAQ. It’s pretty thrilling stuff.)

Anyhow, there are enough steps in our ordering chain that sometimes a fraudulent order will slip through, which will generally lead to a chargeback later on down the line. Since we keep records of where we ship, we can supply those to Paypal to prove that an order was shipped and signed for, which usually result in Paypal contesting the chargeback with the credit card company, after which I have no idea what happens. I presume that credit card companies simply eat a certain number of fraudulent charges as part of the cost of doing business.

Recently, though, there’s been a bit of an uptick in fraudulent orders to the store, mostly being placed from Venezuela with shipping addresses in southern Florida. From what I can tell, it looks like there’s some kind of well-organized credit card scamming gang that rip off tons of credit card numbers and convert them into physical goods before the numbers are shut down. That might sound paranoid, but googling some of the shipping addresses have led to things like Yelp listings for the businesses there, which in turn lead to plenty of reports of other merchants reporting the addresses being associated with stolen CC numbers. I guess someone in Venezuela or Miami really likes Giant Bomb, because they’ve been ordering plenty of merchandise over the past few months. Or they just use it to smuggle cocaine, or something. Edit: Someone on Twitter suggested that they might just be trying to place small orders to see which credit card numbers were still active before using them for large purchases elsewhere, which makes sense.

So, I’ve been trying to keep track of all the orders that are coming in and have been manually cancelling anything that looks suspicious. That hasn’t stopped the orders from coming in, of course, even though I make sure to send emails back indicating that the orders were cancelled because they’re suspected to be fraudulent. Not that anyone’s reading them; I’m pretty sure the email addresses are as fake as the orders themselves.

No Caption Provided

What’s interesting is that the orders from southern Florida have mostly subsided (with a few exceptions) in favor of orders from places like Lithuania, Tunisia, Albania, and other exotic locales. It’s interesting to see the purchasing habits of people who’re playing with other people’s money. One order was for a single t-shirt and a hoodie, but still managed to be $236 thanks to a mammoth $181 shipping charge. (If you’re ordering from eastern Europe, you might want to opt for something cheaper than overnight shipping.) What’s curious is that a lot of these new orders are passing the CVV checks. Presumably this means that these orders are being placed from credit cards that were actually physically stolen, or perhaps issued by legitimate vendors based on fraudulent applications.

I’ve been refreshing the orders page pretty regularly lately, examining all of the orders coming in, and cancelling all the fraudulent ones; at this point I'm pretty sure that I've pissed someone off, because the frequency has increased to the point where over half of all orders coming in are fraudulent, with over $1200 in fraudulent orders in the last couple of days alone. I’m not going to go into the criteria I use to detect suspicious orders, but suffice to say that the “is this order legitimate” game is pretty fun sometimes, especially since I rarely play actual games at work nowadays. Undoubtedly there’ll be a legitimate order that I accidentally cancel at some point, so if you wind up getting an order cancelled mysteriously, let me know and I’ll look into it. I'm looking into some Shopify apps that add a second level of protection against fraudulent orders in the meantime.

And that’s one of the things that I've been up to. So there!

84 Comments

84 Comments

Avatar image for rorie
rorie

7888

Forum Posts

1502

Wiki Points

0

Followers

Reviews: 4

User Lists: 3

I think there are online vendors who are compromised and they never report the theft of their data out of fear of losing business. I've had two credit cards used for fraudulent purchases at different times, one of which was caught immediately and the other which the CC company made me eat of all outcomes. Either that or there are insider thefts at online retailers and meatspace retailers as well. Pretty easy to photograph both sides of a credit card quickly if you have access to one at your place of employment.

I still remember the time that a woman at my credit card company called me up to confirm that I actually wanted to purchase $600 worth of sneakers. I didn't! Some companies will apparently look at what you've spent in the past to try and verify that future orders are legitimate, which is both kind of scary and kind of nice of them.

Avatar image for rorie
rorie

7888

Forum Posts

1502

Wiki Points

0

Followers

Reviews: 4

User Lists: 3

Edited By rorie

Haha, this read was more interesting than I expected it to be. Sure you're not sharing too much, Rorie? The compromised/hacked staff account issue from a few months ago comes to mind; why does CBSi's cyber crime unit/legal team/whatever handle that guy, but not these fraudulent orders?

The earlier hacking was a completely separate issue, fortunately. In this case, none of our security measures have been compromised; we're dealing with the results of other company's poor storage of credit card data, for the most part. I'd love to be able to report this stuff to credit card companies or some kind of federal agency, but if it's just a couple thousand dollars I doubt they'd want to spend much time on it, especially when the orders are being placed from overseas.

Avatar image for roomrunner
Roomrunner

1811

Forum Posts

93

Wiki Points

0

Followers

Reviews: 4

User Lists: 5

This is the Bay Area version of Papers, Please.

Can the player process enough orders to buy enough liquor for yourself and your friends...

Avatar image for bkbroiler
bkbroiler

1739

Forum Posts

438

Wiki Points

0

Followers

Reviews: 0

User Lists: 11

@rorie said:

@bkbroiler said:

So these fraudulent orders are from people who really, actually want Giant Bomb merch? Or are they somehow making money off the stuff they buy? Both realities seem absolutely nuts.

Someone on Twitter pointed out that these are likely just test purchases where people are trying out card numbers to see which ones work before using them for huge purchases elsewhere, or reselling them. Sounds plausible.

So you're actually stopping crime BEFORE it can start? You're a superhero!

Avatar image for castiel
Castiel

3657

Forum Posts

0

Wiki Points

0

Followers

Reviews: 14

User Lists: 0

Good read.

Avatar image for zornack
Zornack

263

Forum Posts

162

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Speaking of the store, are you able to say why the Ryan Davis memorial shirt was taken down?

Avatar image for abendlaender
abendlaender

3100

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Wait, you mean you do things other than looking up pictures of puppies ot taking pictures of them yourself?

Why would you do that?

Avatar image for selfconfessedcynic
selfconfessedcynic

3005

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 12

@rorie nice to have an update!

... though I wish you'd stream more Dark Souls :D

Avatar image for thompson820
Thompson820

425

Forum Posts

1857

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Edited By Thompson820
Avatar image for earlessshrimp
EarlessShrimp

1853

Forum Posts

2735

Wiki Points

0

Followers

Reviews: 3

User Lists: 10

Who needs Papers, Please? when you can just play Is This Order Legitimate?

When Rorie got to the end and mentioned that game, I had exactly these sentiments. I really want to see something like this come out now...

Avatar image for christoffer
Christoffer

2409

Forum Posts

58

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

I never really thought you were slacking but it's nice to hear about your workday. Still, I agree with some of the other comments, it's a shame we don't get to see more of your writings around here.

Avatar image for jacobgray
jacobgray

70

Forum Posts

74

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Hm. Who knew reading about someone else's battle against online fraud would be interesting...but there it is. Keep up the good fight, Rorie.

Avatar image for beepmachine
beepmachine

631

Forum Posts

280

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

@the_laughing_man said:

Give us the fake delivery addresses and we can mess these guys up!

Like Jay and Silent Bob style? "Did you place an order for 16 giant bomb hoodies with this credit card? Order declined biatch!"

@rorie The more I think about this, the more I am convinced this is an act of guerilla warfare by GameBomb.ru

They are testing the defences. Soon the assault will begin.

Avatar image for the_laughing_man
The_Laughing_Man

13807

Forum Posts

7460

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

@the_laughing_man said:

Give us the fake delivery addresses and we can mess these guys up!

Like Jay and Silent Bob style? "Did you place an order for 16 giant bomb hoodies with this credit card? Order declined biatch!"

@rorie The more I think about this, the more I am convinced this is an act of guerilla warfare by GameBomb.ru

They are testing the defences. Soon the assault will begin.

Yes.....And I am sure @rorie can even send us a giant book like in the movie.

Avatar image for mrchup0n
mrchup0n

353

Forum Posts

21580

Wiki Points

0

Followers

Reviews: 7

User Lists: 4

Edited By mrchup0n

@rorie If only we could get, "Quick Look: 'Is This Order Fraudulent Or Not' Game"! But then someone would watch it and figure out how to break your system.

Avatar image for mrmazz
MrMazz

1262

Forum Posts

0

Wiki Points

0

Followers

Reviews: 2

User Lists: 1

Edited By MrMazz

yay Giantbomb is a test site for Credit Card Fraud I think that's a sign you've made it

Avatar image for trafalgarlaw
TrafalgarLaw

1715

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

@rorie No Nigerians? I used to get crazy orders from so-called englishmen currently living in america wanting to buy my "item" to sell in a new japanese merchandise store opening up in Nigeria. Hilarious to read them day after, even moreso when I didn't sell items but provided a service to restore bricked consoles.

Avatar image for pingolobo
pingolobo

129

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Boss of Bosses was a gamespot thing but you could still post a video where you tear through a hard game just to show them kids how it's done. That was amazing.

Avatar image for deactivated-64b8656eaf424
deactivated-64b8656eaf424

1450

Forum Posts

12205

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Giantbomb should get some new shirts and bring back the wizard shirt.

It would also be great if the shirts were better quality. :p My first bomb shirts from few years back were much better quality than the most recent one I got.

Just saying.

Avatar image for markwahlberg
MarkWahlberg

4713

Forum Posts

3782

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

Oh man, this totally explains why that dude gave me a key wrapped in a China Don't Care shirt.

I mean *cough* what

Avatar image for tiny_tank
tiny_tank

123

Forum Posts

1

Wiki Points

0

Followers

Reviews: 3

User Lists: 1

Edited By tiny_tank

@rorie Wow that is very interesting as everyone else on here has said, and also you do write very well. Also please thank @patrickklepek for putting this in the Worth Reading which is where I saw it, as I don't generally have/take the time to look at stuff in the forums very often at all.

Avatar image for planetfunksquad
planetfunksquad

1560

Forum Posts

71

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Oh man, this totally explains why that dude gave me a key wrapped in a China Don't Care shirt.

I mean *cough* what

Dude. Not cool. I told you not to talk about that. Our mutual friends will be paying you a visit tonight.

Avatar image for monkeyking1969
monkeyking1969

9098

Forum Posts

1241

Wiki Points

0

Followers

Reviews: 0

User Lists: 18

I suppose the upside of Rorie looking at all orders and using a fine tooth comb is the fact that after awhile the thieves learn to not test stolen cards on GB...it is a waste of time and leads to their operation being on radar one step earlier than with another retailer who scrutinizes less.

Avatar image for evil_gordita
evil_gordita

77

Forum Posts

72

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@rorie said:

I was reading something on this, and apparently some of the places in south Florida are used by people overseas who want to order stuff from the States but don't want to pay large shipping fees. So apparently some of these places consist of actual buyers who'll get a bunch of merchandise, ship all of it at once, and then reship it to the individual buyers back in the other country to cut down on costs. No idea if it's true or not!

It probably is true. I know that there are people in Japan who offer a deputy service where you can commission them to buy goods from local shops and websites who don't deal with overseas orders. I haven't used a deputy service myself, but it's something I've considered doing.

Avatar image for nictel
Nictel

2698

Forum Posts

202

Wiki Points

0

Followers

Reviews: 2

User Lists: 2

Edited By Nictel
@rorie said:

Presumably this means that these orders are being placed from credit cards that were actually physically stolen, or perhaps issued by legitimate vendors based on fraudulent applications.

Don't rule out employees at restaurants/shops that make a quick snapshot of your cc

Avatar image for umdesch4
umdesch4

787

Forum Posts

135

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@rorie Oh man, as soon as you mentioned PCI DSS compliance, and flowcharts, I just started laughing my ass off. I've been working on some authentication process stuff for my company, and it's been a royal shitshow. The first cut of everything I built (to spec, which was handed down to me, and I assumed had been verified for compliance) had to be completely thrown out. Once I went back to the drawing board, I took it upon myself to make sure what we're building is really compliant, and it's painful, to say the least...

Avatar image for fox01313
fox01313

5256

Forum Posts

2246

Wiki Points

0

Followers

Reviews: 1

User Lists: 19

Definitely need more posts like this from Matt & the rest to see some of the behind the scenes of Giant Bomb until Matt has some free time to get in on the bombcasts. After dealing with all the stuff you put in this post about the crazy store events Matt, you definitely deserve all the puppy attention. (can't recall where the photo is from but too cute to not pass along)

No Caption Provided

Avatar image for zachmorrissey--DEF
ZachMorrissey

21

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

We really appreciate your work Rorie!

Avatar image for zakn
zakn

72

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Bah no Pugs in the OP

Avatar image for nach0sanchez
Nach0Sanchez

120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

RORIE GIMME THAT MASKKKK BOYYYY

Avatar image for nach0sanchez
Nach0Sanchez

120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

PLEASE

Avatar image for nach0sanchez
Nach0Sanchez

120

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

No Caption Provided

my dog needs it

Avatar image for mike
mike

18011

Forum Posts

23067

Wiki Points

0

Followers

Reviews: -1

User Lists: 6

@nach0sanchez: Please stop with the spam. This topic is over 5 years old. One reply was probably too much, over and over is disruptive.