Fraudulent tips/donations?

For the last couple of weeks, I’ve been getting a series of fraudulent payment attempts through my Ghost tip form (15 individual payments, starting March 8). All were blocked by Stripe, fortunately, until one got through today.

My first thought was to temporarily disable Tips & Donations in settings, but looks like that’s not an option. As long as there’s no risk on my end when they fail, I’d rather keep tipping open anyway, but I guess I’ll just have to be vigilant to catch any that get through.

Is this happening to anyone else? And is there anything else I should do?

Haven’t seen this before! What sort of patterns are you seeing in the payment attempts?

Here’s what I’m finding with the 15 attempts so far:

  • All are under $3, and all random amounts ($2.18, $2.40, $2.24, and so on.).
  • Most use Hotmail addresses, but a few are also Gmail and Yahoo.
  • Some provide names, which are usually matched by the email address.
  • Most are located in US, one Costa Rica.
  • Variety of failure reasons:
    • Invalid card number
    • “Blocked by a default Radar rule due to a high risk of fraud.”
    • “Blocked by Stripe”
    • “3D Secure attempt failed”
  • No pattern on time of day or how frequently, but never more than three per day.

Happy to email a CSV export of all of these, if it helps!