Preventing Payment Fraud in a Small Business
The most common fraud types for small businesses on Paystack are: stolen card payments (someone uses a stolen card to buy from you), fake payment confirmations (fake screenshots or fake webhook calls), and internal fraud (an employee manipulating the payment system). Protect yourself by always relying on Paystack webhook confirmations rather than screenshots, monitoring your dashboard daily, limiting who has access to your payment settings, and responding to chargebacks quickly with evidence.
Common Types of Payment Fraud
Fraud against small businesses takes several forms. Understanding each type helps you spot and prevent them.
Stolen card fraud. Someone obtains a stolen credit or debit card (through phishing, data breaches, or physical theft) and uses it to make purchases on your site. The transaction goes through because the card details are valid. But when the real cardholder discovers the charge, they file a chargeback. You lose the product (already shipped) and the money (reversed by the chargeback).
Fake payment confirmations. A customer sends you a fake M-Pesa screenshot or a fabricated payment confirmation. If you rely on screenshots instead of checking your Paystack Dashboard, you ship the product without ever being paid.
Friendly fraud. A customer makes a real purchase, receives the product, and then files a chargeback claiming they never received it or never authorized the charge. They keep the product and get their money back.
Refund fraud. A customer requests a refund for a product they claim was not delivered or was defective, when in fact they received it in good condition.
Internal fraud. An employee with access to your payment system processes unauthorized refunds, diverts payments, or manipulates order records.
Never Trust Payment Screenshots
This cannot be stressed enough: never accept a screenshot as proof of payment. Screenshots can be fabricated in minutes using basic image editing tools. A convincing fake M-Pesa screenshot is trivially easy to create.
Always verify payments through your Paystack Dashboard. If a payment is not showing as "successful" in your dashboard, it did not happen. No exception.
If your business model involves customers paying and then you fulfilling manually (common for small businesses taking orders through WhatsApp or social media), build the habit of checking the dashboard before fulfilling every single order. Yes, it takes a minute. That minute saves you from shipping products you were never paid for.
When you move to an automated checkout with Paystack, this problem largely goes away because your system automatically verifies payments through webhooks. But for manual processes, dashboard verification is essential.
Warning Signs of Fraudulent Orders
These patterns do not guarantee fraud, but they should prompt you to verify more carefully:
- Unusually large orders from new customers. A first-time customer placing a much larger order than your average is worth a second look.
- Rush delivery requests. Fraudsters often want the product shipped immediately before the fraud is discovered.
- Mismatched details. The name on the payment does not match the name on the shipping address, or the billing and shipping addresses are in different countries.
- Multiple failed payment attempts. Several failed attempts followed by a successful one might mean someone is trying different stolen card numbers.
- Multiple orders from the same IP or device with different payment details. This is harder to track without technical tools but your developer can help set up alerts.
- Customer is unreachable. If you try to contact the customer to confirm the order and they do not respond, be cautious.
Trust your instincts. If an order feels wrong, take the time to verify before fulfilling it. A delayed shipment is better than a lost shipment.
Securing Your Paystack Account
Your Paystack account is the keys to your payment kingdom. Protect it accordingly.
Use a strong, unique password. Do not reuse a password from another service. Use a password manager if you have many accounts.
Enable two-factor authentication (2FA). Paystack supports 2FA. Turn it on. This means even if someone steals your password, they cannot log in without the second factor (usually a code from your phone).
Limit team access. Only give dashboard access to people who need it. Use Paystack's team roles to give different access levels. Your marketing person might need to see transactions but should not be able to initiate refunds.
Never share your secret key. Your Paystack secret key is like a master password for your integration. It should only be known by you and your developer. Do not post it in a group chat, email it unencrypted, or share it in a support request.
Monitor login activity. Check who has logged into your Paystack account and when. Unfamiliar login activity should be investigated immediately.
Protecting Against Internal Fraud
It is uncomfortable to think about, but employees with payment access can commit fraud. The best protection is proper access controls and separation of duties.
Separate roles. The person who manages orders should not be the same person who processes refunds. The person who sees transaction details should not be the same person who can change the settlement bank account.
Review refunds regularly. Check your refund history in the Paystack Dashboard at least weekly. Look for refunds you did not authorize or refunds to transactions that do not have corresponding customer complaints.
Audit trails. Keep records of who authorized each refund and why. If an employee processes a refund, they should document the reason.
Rotate access periodically. When an employee leaves, remove their access immediately. Do not wait until you get around to it.
These precautions might feel excessive for a small business. They are not. Internal fraud is one of the most common types of fraud in small businesses, precisely because small businesses often skip these safeguards.
What Paystack Does to Protect You
Paystack has built-in fraud prevention that works behind the scenes:
- 3D Secure / OTP. For card payments, Paystack uses bank authentication (OTP or 3D Secure) to verify that the cardholder is actually the one making the payment.
- Fraud detection algorithms. Paystack monitors transaction patterns and can flag or block suspicious transactions before they go through.
- Webhook signature verification. Paystack signs every webhook with your secret key. Your integration should verify this signature to confirm that the webhook actually came from Paystack and not from a fraudster.
- PCI compliance. Paystack handles card data in a PCI-compliant environment. Card numbers are never stored on your server.
These protections help, but they are not perfect. No fraud prevention system catches everything. Your own vigilance, good business practices, and the precautions described in this guide are essential complements to Paystack's built-in protection.
What to Do If You Are Defrauded
If you discover that a fraudulent transaction occurred:
- Document everything. Save all transaction details, customer communication, shipping records, and any other relevant information.
- Contact Paystack support. Report the fraudulent transaction with all the details. Paystack may be able to help recover funds or block the fraudster from future transactions.
- Respond to chargebacks. If a chargeback is filed, respond with your evidence within the deadline. See handling chargebacks for the full process.
- Report to law enforcement. For significant fraud, file a police report. In Kenya, you can also report to the Directorate of Criminal Investigations (DCI). In Nigeria, the Economic and Financial Crimes Commission (EFCC) handles financial fraud.
- Fix the vulnerability. Understand how the fraud happened and close the gap. Was it a fake screenshot you trusted? Tighten your verification process. Was it a stolen card? Review your order verification procedures.
Learn from every incident. Each one makes your defences stronger. The goal is not zero fraud (that is nearly impossible in online commerce) but manageable, infrequent fraud that does not threaten your business.
Key Takeaways
- ✓Never accept payment screenshots as proof. Always verify through your Paystack Dashboard.
- ✓Stolen card fraud results in chargebacks that cost you the product and the money.
- ✓Limit access to your Paystack account. Only give dashboard access to people who need it.
- ✓Watch for unusual patterns: very large orders, multiple failed attempts followed by a success, orders with mismatched shipping and billing details.
- ✓Internal fraud is a real risk. Separate the person who manages orders from the person who manages refunds.
- ✓Paystack has built-in fraud prevention, but your own vigilance is the first line of defence.
Frequently Asked Questions
- Is Paystack responsible if I lose money to fraud?
- Paystack provides tools and infrastructure to help prevent fraud, but the ultimate responsibility for verifying orders and managing fraud risk lies with you, the merchant. Paystack is not liable for losses from fraudulent transactions that passed through their system if their security measures were functioning correctly.
- Can I block specific customers or cards from paying?
- Paystack offers some tools for managing risk, including the ability to blacklist certain cards or emails. Contact Paystack support or check their documentation for the specific fraud management tools available to your account.
- Should I delay shipping for large orders to check for fraud?
- For unusually large orders from new customers, a brief delay (24 to 48 hours) to verify the transaction is reasonable. If a chargeback is going to be filed, it often happens quickly. A short hold gives you time to confirm the transaction is legitimate.
- How do I know if a chargeback is from real fraud or a dishonest customer?
- Look at the evidence. If you can prove the customer received the product (delivery confirmation, signed receipt, login records for digital products), the chargeback is likely dishonest. If you cannot prove delivery, you may not be able to distinguish, which is why keeping delivery records is so important.
Ready to build real-world apps?
Join the McTaba Labs full-stack marathon (4 months full-time · 6 months part-time). Learn M-Pesa, USSD, and WhatsApp engineering while shipping 8 production apps.
Apply to the McTaba Marathon