Skip to content
Risk & Compliance

Blacklist

Database of blocked customers, cards, or IPs due to fraud or abuse. Critical for high-risk merchant protection.

Overview

What is Blacklist?

A blacklist is a database of blocked entities - customer names, email addresses, card numbers (hashed BINs), IP addresses, device fingerprints, or shipping addresses - that your payment system automatically declines due to previous fraud, chargebacks, or abuse. For high-risk merchants fighting elevated fraud rates, blacklisting prevents repeat offenders from making additional fraudulent purchases after their first successful fraud attempt is discovered.

Effective blacklisting operates at multiple levels: card-level blocking (block specific card BIN ranges associated with prepaid fraud cards), customer-level blocking (block email addresses, names, and phone numbers from previous fraudsters), IP/device blocking (block device fingerprints and IP addresses from fraud attempts), and shipping address blocking (block addresses receiving fraudulent orders). Sophisticated systems use fuzzy matching to catch variations - blocking "[email protected]" also blocks "[email protected]" and "[email protected]".

Shared blacklists multiply effectiveness by leveraging industry-wide fraud data. Instead of only blocking fraudsters after they defraud you, shared blacklists block known fraudsters before their first attempt against your business. Services like Ethoca/Verifi maintain shared fraud databases across thousands of merchants - a fraudster successfully defrauding Merchant A gets blacklisted across all participating merchants. For high-risk verticals with organized fraud rings, shared blacklisting prevents 60-75% of fraud attempts by blocking known bad actors preemptively.

Balance against false positives requires careful management. Overly aggressive blacklisting blocks legitimate customers: shared family IP addresses, corporate networks, hotels, and VPNs generate false blocks. The optimal blacklisting strategy combines permanent blocks (confirmed fraudsters, chargebacks for fraud), temporary blocks (suspected fraud pending investigation), risk scoring increases (flagged entities require additional verification), and whitelist overrides (manually approved customers bypass blacklist checks). MIDs' fraud platform provides tiered blacklisting with automatic decay - low-confidence blocks expire after 90 days while confirmed fraud blocks remain permanent.

In depth

Everything you need to know.

Fraud screening extracts email, IP, addresses, device fingerprint, card BIN. System queries blacklist. Exact matches auto-decline. Fuzzy matches increase fraud score. Merchants add manually or via rules. Shared blacklists sync hourly.

Prevents repeat fraud. Fraudster with $200 order attempts 5-10 more. Without blacklisting, lose $1,000-2,000 plus chargebacks. Blacklisting stops after first. Shared blacklists block 60-75% of attempts (1,200-1,500 of 2,000 annual). At $150 average, prevents $180K-225K annually - 20X+ ROI.

Illustrative example — not a specific client engagement.

  • Fraud ring: 8 fraudsters, 45 orders, $6,800. Returned monthly for 6 months, $40K total. With blacklisting, limited to $6,800.
  • Gaming subscribed Ethoca ($8K annually). First month blocked 280. At $180 average, prevented $50K - 6.3X ROI. Annual: $600K+.
  • Auto-blacklisted fraud chargebacks. Blocked 1,200 repeat but 40 legitimate (shared IPs). Manual review reduced false positives 40 to 8.
  • Blacklist multiple: email, IP, device, shipping - fraudsters change all
  • Fuzzy matching for emails/names automatically
  • Tiered: permanent for confirmed, 90-day suspected, whitelist override
  • Subscribe shared blacklists (Ethoca, Verifi) - prevent 60-75%
  • Review monthly: remove expired, analyze false positives (<2%)
  • Auto-blacklist fraud chargebacks
  • IP/device: shorter durations (30-60 days) avoid blocking shared infrastructure
  • Only blacklisting after chargebacks - fraud already occurred
  • Not fuzzy matching - fraudsters change johnsmith@gmail to johnsmith123
  • Permanent blocking shared IPs - blocks hundreds legitimate
  • Not using shared blacklists - only blocking who already hit you
  • No review - can't remove false positives
  • Not blacklisting all identifiers - email but not IP/device

Keep exploring

Related terms

APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.