Addressing thousands of declines
Hello all,
We've had a couple days already this month with thousands of declines. Two records (both now deleted) are responsible for 17k+ declines--nearly all by IP. Thankfully, they are being caught and declined. That said, we get these types of attempts, but we're already at 60% of 2019's total declines. I'm just wondering what we can do to prevent these that doesn't also hamper the donor experience. CAPTCHA is available, but I'm not sure that's going to help our conversion (although maybe a worthwhile test).
Anyway, open to ideas beyond that. Thanks in advance!
We've had a couple days already this month with thousands of declines. Two records (both now deleted) are responsible for 17k+ declines--nearly all by IP. Thankfully, they are being caught and declined. That said, we get these types of attempts, but we're already at 60% of 2019's total declines. I'm just wondering what we can do to prevent these that doesn't also hamper the donor experience. CAPTCHA is available, but I'm not sure that's going to help our conversion (although maybe a worthwhile test).
Anyway, open to ideas beyond that. Thanks in advance!
Tagged:
0
Comments
-
Hi JD,
There's a few options here, the BC SPCA had a similar issue a while back- https://spca.bc.ca/donations/make-a-donation/ uses an LO integration for WordPress to deal with this (additional security layers that are unobtrusive to users but block bots/card running).1 -
JD,
Have you contacted Support for help?
0 -
...additional security layers that are unobtrusive to users but block bots/card running...
I'm interested. Can you elaborate on what you added?
BPM0 -
Brian Mucha:
...additional security layers that are unobtrusive to users but block bots/card running...
I'm interested. Can you elaborate on what you added?
BPMSure, no problem- I added a honeypot trap, timestamp detector, and a measurement of failures per ip address that can result in a bans at the plugin level,and I integrated google's invisible recaptcha v3 (no challenges, just monitors your site behaviour to see if you're a real user and blocks with an error message if you are below a certain human threshold). There's a couple changes/new security things I'll be adding shortly to it as well (the security for the integration changes over time as we swap out old methods via security updates when they are no longer effective). I also encourage clients to install a decent application level firewall/bot list like WordFence security. Overall that cuts down on card running!
Edit: I actually gave a presentation of this at BBCon this year, I've uploaded a pdf if anyone wants to review it.
1 -
We also added a honeypot field (https://secure.nationalmssociety.org/site/Donation2?df_id=63293&63293.donation=form1&mfc_pref=T) and made the form two pages. If a bot populates the field, the "next" button doesn't go to the next page. This cut down on the card running as well as those bots creating bogus records in our system. We instituted the honeypot field on our event donation forms (example: https://secure.nationalmssociety.org/site/Donation2?62768.donation=form1&idb=1744579740&df_id=62768&FR_ID=30911&mfc_pref=T&PROXY_ID=9913980&PROXY_TYPE=20) as well but didn't make they two page forms. We've not a seen any decline / issues with completion rates since the switchover.1
-
Hi all,
Thanks for the feedback and considerations. It wasn't quite a priority at the time, but we've started seeing even more declines, especially in the past week -- and even today. So, here I am again.
We don't use Wordpress, so the plugin doesn't appear to be an option.
Sean Staggs - It seems your honeypot solution would be most relevant for our purposes. Would you mind sharing how you implemented that field?
Thanks again!0 -
I am interested on this topic too and wanted to see if anything we could tap into due to we have also been seeing this carding attempts in bulk hitting our donation forms.
In my opinion, although the honeypot and these stated solutions will help stemmed issue associated with bots spamming through the front-facing form, it might not likely addressed those attackers that hits the end point without having to go through the front-facing form (i.e. cURL POST or REST API submission done directly through tools like POSTMAN)
The non API donation 2 forms have that CAPTCHA data element that I believe is a server-side which will likely address the above, however this is currently not compatible with LO API forms and not to mention the 'intrusive' aspect adding extra steps for end user to donate.
Has anyone else experiencing this type of carding attack where the hacker might not necessarily hit your actual front facing form? Pretty sure there's that honeypot schema on the non API (donation 2) forms yet we are still seeing attacks time to time despite.
Thanks in advance!
regards,
Daniel0 -
Sean, is your honeypot solution still working successfully? Would be grateful to hear an update.
Thanks,
Jessica0
Categories
- All Categories
- 6 Blackbaud Community Help
- 211 bbcon®
- 1.4K Blackbaud Altru®
- 402 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 1.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- 15 donorCentrics®
- 360 Blackbaud eTapestry®
- 2.6K Blackbaud Financial Edge NXT®
- 655 Blackbaud Grantmaking™
- 576 Blackbaud Education Management Solutions for Higher Education
- 3.2K Blackbaud Education Management Solutions for K-12 Schools
- 941 Blackbaud Luminate Online® and Blackbaud TeamRaiser®
- 84 JustGiving® from Blackbaud®
- 6.7K Blackbaud Raiser's Edge NXT®
- 3.7K SKY Developer
- 248 ResearchPoint™
- 120 Blackbaud Tuition Management™
- 165 Organizational Best Practices
- 240 Member Lounge (Just for Fun)
- 34 Blackbaud Community Challenges
- 37 PowerUp Challenges
- 3 (Open) PowerUp Challenge: Grid View Batch
- 3 (Closed) PowerUp Challenge: Chat for Blackbaud AI
- 3 (Closed) PowerUp Challenge: Data Health
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Product Update Briefing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports+
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Email Marketing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Gift Management
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Event Management
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Home Page
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Query
- 796 Community News
- 3K Jobs Board
- 54 Blackbaud SKY® Reporting Announcements
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)




