Skip to content
Risk & Compliance

Phishing

Fraud technique using fake emails/websites to steal payment credentials. Merchants must protect customers with security education and anti-phishing measures.

Overview

What is Phishing?

Phishing is a fraud technique where criminals send fake emails or stand up counterfeit websites that closely mimic a legitimate business, tricking victims into handing over payment credentials, account passwords, or personal information. It targets both directions of a merchant relationship — fake "order confirmation" or "shipment delayed" emails aimed at customers, and fake PSP or vendor emails aimed at merchant staff requesting account updates or credentials.

A typical campaign works like this: fraudsters send emails or build a near-identical copy of a merchant's checkout page, victims click through and enter their details, and the fraudsters capture the data for account takeovers, fraudulent purchases, or resale on the dark web. Merchants rarely process the phishing fraud itself, but they absorb the fallout: chargebacks from transactions made with stolen credentials, a spike in confused customer-service contacts, and reputational damage from association with the scam.

The scale can be significant even at low conversion rates — a campaign reaching 50,000 targets with just a 1% click-through still produces 500 victims entering a fake site, and if 40% of those go on to submit payment details, that's 200 compromised accounts generating fraud, support tickets, and chargebacks the legitimate merchant has to absorb. High-risk merchants already facing extra scrutiny from banks and card networks can least afford the added association with a phishing scam.

Defense is mostly about visibility and hardening: monitoring for brand impersonation and typosquatted domains, implementing email authentication (SPF, DKIM, DMARC) so fraudsters can't spoof the merchant's real sending address, educating customers on what legitimate communication looks like, and having a takedown process ready for fake sites. After a confirmed campaign, notifying affected customers and prompting password resets limits how much damage a stolen credential can still do.

In depth

Everything you need to know.

Fraudsters create fake emails mimicking merchant brands: 'Your order shipment' with malicious links. Or fake merchant websites: exact copies of legitimate checkout pages. Victims click links or visit fake sites, enter credentials. Fraudsters capture data. Later use stolen credentials: account takeovers on real merchant sites, using stolen payment info for fraud, selling credentials on dark web. Merchants face fallout: chargebacks from fraudulent transactions, customer complaints, brand damage.

Phishing attacks damage merchant reputation and create fraud exposure. A phishing campaign impersonating your brand reaches 50,000 victims via email. Even 1% click rate (500 victims) entering credentials creates exposure. 200 provide payment info. Fraudsters use this for: account takeovers, fraudulent transactions, credential resale. Merchant faces chargebacks from fraud transactions, customer service volume from confused victims, negative reviews/social media, brand damage. High-risk merchants already facing skepticism cannot afford phishing association. Educational efforts prevent customer losses and maintain trust.

Illustrative example — not a specific client engagement.

  • Supplement merchant phishing campaign: 40,000 fake 'shipment delayed' emails. 800 clicked, 150 entered credentials. Fraudsters used for account takeovers: 80 unauthorized orders totaling $12K before detection. Merchant refunded customers, ate losses, faced reputation damage.
  • Gaming platform didn't implement email authentication. Fraudsters sent phishing emails from spoofed addresses appearing legitimate. 300 customers entered credentials. 120 accounts taken over, $28K fraudulent transactions. Implemented SPF/DKIM/DMARC, eliminated sender spoofing.
  • E-commerce merchant discovered fake website (typo domain) operating for 3 months. 200+ customers entered payment info on fake site. Merchant only learned after chargeback wave from fraud transactions. Submitted takedown, registered typo domains defensively, prevented future incidents.
  • Monitor for phishing: Google Alerts for brand name + phishing, check domain registration for typosquatting
  • Implement email authentication: SPF, DKIM, DMARC prevent sender address spoofing
  • Customer education: explain legitimate email format, never requesting passwords, bookmark real site
  • Report phishing sites: submit takedown requests to hosting providers, register common typo domains defensively
  • After phishing campaigns: notify affected customers, recommend password changes, monitor for fraud
  • Use security indicators: SSL certificates, trust badges, consistent branding help customers identify legitimate sites
  • Enable 2FA for customer accounts - limits damage from stolen passwords
  • Not monitoring for phishing campaigns impersonating brand - discover only after customers complain
  • No customer education about legitimate communication - customers can't distinguish real from fake emails
  • Not implementing email authentication (SPF, DKIM, DMARC) - fraudsters easily spoof sender addresses
  • Ignoring reports of fake websites - allowing phishing sites to remain active for weeks
  • No incident response plan - scrambling when phishing campaign detected
  • Not warning customers after phishing campaigns - victims unaware credentials may be compromised

Keep exploring

Related terms

APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.