You may see blocked transactions in your Stripe dashboard flagged as high fraud risk. This typically indicates card-testing activity, where fraudsters use stolen card details to attempt small-value payments (usually under £20) to check if cards are still active. Stripe blocks most of these attempts, but some may succeed. When they do, the constituent and transaction are added to Donorfy.
⚠️ Important: Take prompt action if you notice a sudden increase in low-value blocked transactions, as this may indicate a coordinated attack.
Reduce Fraud Risk When Using Web Widgets
If fraud attempts occur on a widget-based donation page, you can reduce risk by generating a new WidgetId.
Change Your WidgetId
Go to Online Donations, then open your existing widget and create a new version.
Configure the new widget using the same settings as your current one.
View the generated HTML and scroll to the bottom to locate the WidgetId field.
Copy the new WidgetId.
Edit your website’s donation page HTML, locate the old WidgetId, and replace it with the new value.
Return to Online Donations and delete the original widget from the list.
📌 Note: The WidgetId field appears similar to:
<input type="hidden" id="WidgetId" value="b1234fb5-111e-1f11-b333-ff00002220b4" />
Reduce Fraud Risk on Campaign Donation Pages
Donorfy has introduced improvements to help block fraudulent activity on Campaign Donation Pages.
Reset a Campaign Donation Page
Contact Donorfy Support and request a page reset.
Once reset, monitor Stripe for reduced fraudulent activity.
Reduce Fraud Risk on Donorfy Forms
Donorfy Forms include enhanced controls to detect and block high-risk traffic. Blocked IP addresses appear in Forms, then Security.
Create and Replace a Form
If fraudulent attempts continue:
Create a copy of the affected form.
Update the form URL suffix so it is unique.
Replace the form embedded on your website with the new version.
Open the original form in Donorfy and set it to Inactive to prevent it from displaying online.
If the issue persists, delete the original form.
Enhance Stripe Fraud Controls Using Radar
Stripe Radar offers optional rules that can strengthen your fraud-prevention setup.
Check Standard Radar Rules
Log in to your Stripe Dashboard.
Navigate to Radar, then Rules.
Ensure that standard verification rules for CVC and ZIP/postcode checks are enabled.
Block Transactions with Missing CVC Codes
In Radar, go to Rules.
Add a new rule that blocks any transaction where CVC is not provided.
Save the rule to activate the block.
📌 Note:
To add custom Radar rules, Stripe Support must enable the feature.
Additional Stripe fees may apply. Check Stripe pricing for up-to-date costs.
