Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

U.S. E-Commerce Fraud Total Will Hit $4 Billion, Study Says

Online fraud costs merchants about 1.4 percent of their top-line revenue annually, survey says

Dec 10, 2008 | 02:57 PM

By Tim Wilson
DarkReading

U.S. companies that do electronic commerce will lose a record $4 billion to online fraud this year, but they are taking steps to fight it, according to a report issued today.

According to the annual Cybersource survey on e-commerce fraud, e-commerce fraud is up slightly over 2007, when it set the previous record of $3.7 billion. The 2008 figure represents about 1.4 percent of merchants' total online revenue for the year -- roughly the same percentage of loss that merchants have experienced in each of the past three years.

"For years, U.S. e-commerce merchants have fought fraudsters to what amounts to an annual standoff," says Doug Schwegman, CyberSource director of market and customer intelligence. "Losing on average about 1.4 percent of sales to fraud has been the constant. This year, however, for the first time, merchants could not rely on double-digit market expansion to bolster online revenue growth or to cover inefficiencies."

To date, many merchants have been fighting fraud by flagging suspicious orders and reviewing them manually, Cybersource says. For each of the past six years, approximately one out of every four online orders has been manually reviewed, and in 2007 approximately 4.2 percent of orders were rejected due to suspicion of fraud.

This year, however, merchants are accepting a higher percentage of orders, rejecting just 2.9 percent, according to the study. "Falling rejection rates, coupled with steady fraud rates, imply that merchants are more successful this year than in previous years at fighting fraud," the study says.

Midsize merchants " those with online revenue of $5 million to $25 million -- are most challenged by online fraud, the study says. When compared with larger merchants, midsize companies show higher order rejection rates (4.3 percent vs. 2.4 percent), higher manual review rates (34 percent of orders, vs. 15 percent), and higher fraud loss rates (1.6 percent of revenue vs. 1.2 percent).

"We believe the largest merchants are simply better at fighting fraud," Schwegman says. "They make better use of fraud detection tools and other resources. And, as they work through the growing pains of becoming a large merchant, midsize merchants' fraud metrics may actually spike if they haven't implemented the tools and established the review expertise to sufficiently protect them from the increase in the volume of fraudulent activity." Fraud chargebacks can represent a profit potential for merchants, the study says. Currently, merchants fight only about half of the fraud chargebacks they receive. One-third of merchants challenge fewer than 10%. But merchants that do elect to challenge chargebacks recover, on average, 28% of their fraud chargebacks. "For many merchants, this remains an untapped opportunity," Cybersource says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)