How to Avoid Phishing in Your Business | Sales Layer
How to Avoid Phishing in Your Business
Miguel Giner · May 17, 2021
Table of Contents
What is phishing
Phishing is a fraudulent practice that consists of impersonating someone's identity to steal personal data, payment details, and passwords, generally to make online purchases or steal money from their funds.
According to The Paypers' Fraud Prevention in Ecommerce Report 2020 / 2021, ecommerce fraud has grown by 18% since 2017, and this has been exacerbated by the global COVID-19 pandemic.
In light of the situation, shoppers feel more confident about shopping online. However, this has posed challenges for online retailers and payment platforms. According to Google, phishing sites grew by 250% between January and March 2020, which is a concerning trend.
Fortunately, best practices to prevent phishing in ecommerce and strengthen security are also on the rise.
Types of phishing to watch out for
All types of phishing aim to gain access to a shopper's accounts through their details in ecommerce, facilitating illegal transactions.
Phishing via email or phone
Users receive emails that appear to be from their bank, requesting personal data or attempting to install malware.
Impersonation
This involves holding a user's account details for illegal actions and crafting fake ecommerce sites to steal payment details.
Click & Collect / BOPIS fraud
Fraudsters steal customer's credentials to pick up orders made in-store on their behalf.
CDN (Card not present)
Online transactions are made by fraudsters without having the genuine bank card.
BEC (Business Email Compromise)
This is easier due to lower security at home offices, which can be exploited by phishers.
Fake profiles on marketplaces
Scammers replicate real company profiles on marketplaces to attract purchases without ever shipping products.
How to avoid phishing on your ecommerce site
Educate the shopper
Inform shoppers about secure shopping and payment practices to help eliminate targets.
Secure payment process
While simplicity is important, shoppers are often willing to go through a longer payment process in exchange for extra security.
Good identification practices
Ensure rigorous checks for customer identity when verifying orders.
Strong data encryption
Business must collect and store payment data securely using tokenization to protect sensitive information.
Consult a specialist
Companies should regularly review their cybersecurity status and update reports to address potential phishing risks.