The five scams every merchant will eventually meet
Merchants face their own fraud economy: overpayment scams that turn your refund into the payout, skimmers planted on unattended readers, phishing that arrives by email, text and phone call, card-testing bots that burn your checkout, and refund fraud that weaponizes your goodwill. Every one of them has a boring, reliable countermeasure, and most come down to the same rule: money out only travels the path the money came in.

Scope: For business owners and the staff who handle payments, refunds and 'urgent' calls from the bank that are not from the bank.
1. The overpayment scam: your refund is the payout
The setup is disarming: a customer pays too much, by 'mistake', a cheque above the invoice, a card payment doubled, an e-transfer with an extra digit, and asks you to refund the difference, often urgently and often by a different method. You send the refund. Days later, the original payment collapses: the cheque bounces, the card charge is disputed as fraud, the transfer is reversed. The 'overpayment' never existed; your refund was the whole point.
The defence is a single inviolable rule: refunds travel back on the rail the payment arrived on, to the same instrument, and only after the original payment has genuinely cleared. A real customer with a real overpayment loses nothing by waiting for settlement or receiving the refund to the same card. A scammer loses the whole scheme. Any pressure to refund faster or differently is the tell, not an inconvenience.
2. Skimmers: the attack on your hardware
A skimmer is a parasite fitted over or inside a card reader that copies card data as customers pay. Chip cryptograms killed skimming's golden age, but magnetic stripes still exist, unattended terminals still get tampered with, and a compromised reader at your business is your reputation on the line regardless of who planted it.
The countermeasures are physical and take seconds. Know what your terminals look like: weigh in your hand, check the seams, note the serial numbers. Inspect daily on unattended and customer-facing units: anything loose, bulky, misaligned or freshly scratched gets the terminal pulled and your provider called. Lock devices down after hours, control who can 'service' them, and treat any unannounced 'terminal technician' as an incident until verified. Modern certified terminals also carry tamper detection that bricks the device when opened, which is one of the quiet arguments for current hardware.
3. Phishing, smishing and vishing: one scam, three channels
Phishing is the fraudulent email, smishing the text message, vishing the phone call, and for merchants the payload is consistent: something urgent about your merchant account, your deposits are frozen, your terminal needs a security update, verify your login now, that routes you to a credential-harvesting page or extracts codes over the phone. With your dashboard credentials, an attacker redirects deposits, mines stored customer data or runs refund fraud from the inside.
The pattern to teach staff is urgency plus credentials: any contact that manufactures time pressure and asks for a password, a one-time code or 'confirmation' of banking details is hostile until proven otherwise. Real providers do not ask for your password, ever, on any channel. The safe reflex costs thirty seconds: hang up or close the email, and contact your provider through the number or dashboard you already know. Add two-factor authentication and per-employee logins with least-privilege roles, and a stolen password stops being a stolen account.
4. Card testing: bots that use your checkout as a laboratory
Fraudsters holding thousands of stolen card numbers need to learn which still work, so they run them against someone's checkout in small rapid-fire transactions. If it is yours, you inherit the wreckage: authorization fees on floods of declines, a spiking failure rate that degrades your standing with issuers, and disputes from the few that succeeded.
Starve the laboratory: velocity rules that cap attempts per card, IP and session; CAPTCHA triggered by failed-payment streaks rather than punishing every customer; CVV and AVS required so bare numbers fail cheaply; and alerts on decline-rate spikes so a 3 a.m. bot run pages somebody instead of billing somebody. A checkout that is expensive to test against gets crossed off the list, because the bots have cheaper laboratories to visit.
5. Refund and return fraud: the abuse of your goodwill
Refund fraud spans wardrobing (use it, return it), receipt games, empty-box returns and, increasingly, 'refund-as-a-service' operators who dispute or return purchases on customers' behalf for a cut. Individually small, it compounds into a real margin leak for retail.
Policy is the defence, applied evenly: receipts or order lookup required, refunds only to the original payment method, serial numbers checked on high-value goods, and return windows that are generous but finite. The 'original method only' rule does double duty here, it also breaks the overpayment scam, which is why it belongs in writing, at the counter and in the checkout terms.
Behind all five scams sits the same architecture: clear rules, small daily habits and tooling that watches the patterns humans miss. RapidCents accounts ship with velocity controls, AVS and CVV enforcement, tamper-aware terminals and dashboard roles with two-factor authentication, and the fraud-prevention layer scores what the rules alone cannot see.
Frequently asked questions
What is the overpayment scam?
A fraudster overpays you with a payment that will later fail, a bad cheque, a stolen card, a reversible transfer, then asks for the excess back immediately, usually by a different method. The refund you send is real; the payment it refunds was never good. Refunding only to the original instrument after clearing defeats it completely.
How do I check my terminal for a skimmer?
Daily, physically: pull gently on the reader housing, check seams and keypads for overlays, compare against how the device normally looks and weighs, and verify serial numbers. Anything loose or unfamiliar takes the terminal out of service and gets your provider on the phone. Unattended units deserve the closest attention.
What is the difference between phishing, smishing and vishing?
The channel: email, SMS and voice call respectively. The scam is the same, urgency plus a request for credentials, codes or banking changes. No legitimate provider asks for your password on any channel; verify through contact details you already have, never the ones in the message.
How do I know if my checkout is being card-tested?
The signature is a burst of small, rapid transactions with a very high decline rate, often at odd hours from clustered IPs. Watch your decline-rate metrics and set alerts; then add velocity limits, CVV/AVS enforcement and failure-triggered CAPTCHA so the pattern becomes unprofitable.
Can I refuse a refund I suspect is fraudulent?
You can hold the line your published policy sets: receipt or order verification, original payment method, condition checks and time windows. A consistent written policy applied to everyone is both fair and defensible; ad-hoc exceptions under pressure are exactly what refund fraud is engineered to extract.





