Aankondiging van onze nieuwe Developer Hub
Aankondiging van onze nieuwe Developer Hub
Aankondiging van onze nieuwe Developer Hub
Aankondiging van onze nieuwe Developer Hub
/
Fraudepreventie
4 oktober 2023
4 oktober 2023

7 cyberbeveiligingsrisico’s waarmee online verkopers te maken hebben

Wit, rond logo met in het midden in elkaar grijpende vormen, omgeven door overlappende, baanachtige elliptische lijnen en verspreide blauwe ruitvormen.

Chargebacks?
Dat is niet langer jouw probleem.

Haal 4x meer chargebacks terug en voorkom tot 90% van de inkomende betalingen, dankzij AI en een wereldwijd netwerk van 20.000 handelaren.

Meer dan 600 beoordelingen
Geen creditcard nodig.

TL;DR:

Sinds 2020 is het aantal cyberdreigingen aanzienlijk toegenomen; uit onderzoek blijkt dat het aantal aanvallen op desktopcomputers en mobiele apparaten met 30% is gestegen.

De Elevenlabs Text-to-Speech AudioNative-speler wordt geladen...

Volgens een rapport van Webscale kende de e-commerce in 2020 een aanzienlijke toename van het aantal cyberincidenten.

Ongeveer 70% van de deelnemers aan het onderzoek (onlinebedrijven) gaf aan dat het aantal cyberaanvallen met 20% is toegenomen.

De recente pandemie was een van de redenen voor deze stijging. Naarmate steeds meer mensen online gingen winkelen, stimuleerde dit de opkomst van nieuwe bedrijven. De verschuiving in het digitale landschap fungeerde ook als een waarschuwing voor hackers.

Het is inmiddels alweer een paar jaar geleden sinds 2020, maar beveiligingsrisico’s blijven een groot probleem voor online winkeliers.

Cybercriminelen beschikken over een breed scala aan kwaadaardige technieken, waarmee ze niet alleen websitebeheerders en medewerkers, maar ook consumenten aanvallen.

Raising awareness about the most prominent cybersecurity threats is the first move to succeed in countering them. After that, it is up to the merchants which countermeasures they will incorporate into their stores.

Our focus for this piece is to unveil the most common cybersecurity threats businesses face and how to circumvent those threats.

Nummer 1: Spammen

Let's start with spamming. It is one of the easier-to-detect attempts to cause harm. Some hackers try to take advantage of social media and email inboxes by sending messages with infected links.

Het achterlaten van besmette URL’s onder blogberichten via een reactie of het verbergen van de link en deze in het beoordelingsgedeelte van een product plaatsen, kan ook werken.

Clicking such links redirects you to shady websites, potentially making you a victim. To prevent this, webmasters often use an automated Web Scraping API to routinely scan outbound links and flag suspicious redirects before users can click them. On top of that, spammy links that are visible on a website leave a negative impression among visitors. Not to mention that they may also affect the website's speed.

Nummer 2: DDoS-aanvallen

Bij DDoS-aanvallen wordt een website overspoeld met een enorme hoeveelheid verkeer afkomstig uit verschillende bronnen.

Websites go down because they cannot handle the requests, and bringing it up proves a significant challenge if the site is missing the necessary security measures.

In some cases, DDoS attacks might be used as an aversion. The goal is to distract the staff rather than take down the website. The year 2021 saw a significant increase in the frequency and magnitude of these cyber attacks, reaching an all-time high. In November 2021, Microsoft countered a DDoS attack directed at an Azure customer. The attackers deployed a throughput of 3.45 Tbps and a packet rate of 340 million PPS. It was believed to be the most significant DDoS attack ever recorded.

Nummer 3: Malware

Spyware, virussen, trojans en ransomware zijn de meest voorkomende vormen van malware.

Whenever malware infects a device, there is a risk that whoever uses the device to connect to a website could indirectly steal sensitive data or infect the website itself. This is particularly the case for those who have access to backend databases.

Hackers manipuleren de gegevens met een code en verzamelen de informatie die ze nodig hebben. Bovendien kunnen ze hun sporen uitwissen om opsporing te bemoeilijken.

Grafiek: Cybercriminaliteit zal de komende jaren naar verwachting explosief toenemen | Statista
Bron: statista

Nummer 4: Bots

Bots zijn softwareprogramma’s of scripts die specifieke taken uitvoeren. In de context van e-commerce hebben bots meestal als doel waardevolle informatie van de website te verzamelen.

The information is then used by another party to gain an edge over the competition. It is a dirty trick, but one used nonetheless.

A case in point is from Data Dome, which reported a large-scale bot attack that leveraged BaaS (bots as a service) and lasted ~19h, comprising ~15.5M requests broadcasted from more than 500K residential proxies. On average, the large-scale scraping attack induced ~150K requests every 10 minutes on their customer’s servers.

Nummer 5: Financiële fraude

Credit card fraud is one of the standout examples of financial fraud. Stolen credit cards or stolen personal details to get a new credit card have been plaguing the ecommerce industry for years.

De Federal Trade Commission heeft een grafiek gepubliceerd waaruit blijkt dat het aantal gemelde gevallen van creditcardfraude is gestegen van 45.000 in het eerste kwartaal van 2019 tot 115.000 in het eerste kwartaal van 2023.

Introducing address verification systems that flag discrepancies between the actual credit card owner and the delivery address helps address the issue. Nevertheless, the problem is still prominent and requires constant attention from online merchants.

Nummer 6: Phishing-zwendel

CISA reports that 9 out of 10 cyber incidents begin with phishing. It makes sense, given how the technique is a perfect first step to breach the line of defense.

Phishing begint met hackers die zich voordoen als legitieme winkeleigenaren. Ze kunnen een e-mail naar uw klant sturen waarin ze om inloggegevens vragen.

More aggressive hackers also attempt to trick staff members. Someone working on the website and backend access is the perfect target for hackers.

Urgency, fear, and other forms of manipulation are common in phishing attacks. It is easier to trick a recipient when they receive a tough choice, such as a warning about how their account has been compromised and how they need to restore it by clicking a URL that is actually harmful.

Grafiek: De landen met de meeste GDPR-datalekken | Statista

Nummer 7: E-skimming

Bij e-skimming wordt met name misbruik gemaakt van kwetsbaarheden op de website of in de betalingsgateway. In zeldzamere gevallen slagen hackers erin malware toe te voegen aan bestaande code van derde of vierde partijen.

Zodra er op een website aan e-skimming wordt gedaan, onderscheppen hackers gebruikersgegevens terwijl consumenten hun creditcardgegevens, woonadres, inloggegevens, antwoorden op beveiligingsvragen enz. invoeren.

From the user's point of view, there is no warning about someone skimming through the data. They realize it after the fact when hackers already used the information.

Hoe ga je om met deze cyberbeveiligingsrisico’s?

Ecommerce security is complex, particularly given how many different threats there are. Nevertheless, there are tried and tested countermeasures to minimize the risks. Here are non-exhaustive, but useful recommendations:

1. Gebruik antivirussoftware

Antivirussoftware zou verplicht moeten zijn. Iedereen die een apparaat gebruikt om op de website te werken, moet zijn of haar apparaat beveiligen.

It is up to the supervisors to ensure that every single staff member has antivirus software installed. A single person who is reluctant to do it might cause enough harm to affect everyone involved.

Antivirus tools should do the trick on their own if you leave them running in the background, but it is still recommended to run custom scans now and then.

Als u vermoedt dat er mogelijk beveiligingslekken op het apparaat zitten, gebruik dan antivirussoftware om te controleren of er iets wordt gedetecteerd. Als het apparaat is geïnfecteerd door malware of een andere bedreiging, moet u de beschadigde gegevens verwijderen.

Soms moet u systeembestanden handmatig openen om ze zelf te wissen. Zorg ervoor dat u weet hoe u bijvoorbeeld op macOS toegang krijgt tot /usr/local/bin , of tot System32 op MS Windows.

2. Stimuleer een slim wachtwoordbeleid

A smart password policy is another example of a countermeasure that determines how secure your website is.

Veel mensen verzuimen sterke wachtwoorden te bedenken. In plaats daarvan gebruiken ze voor de hand liggende keuzes zoals „1234567“ of „password123“, waardoor het hackers een stuk gemakkelijker wordt.

Idealiter zouden wachtwoorden:

  • Zorg voor hoofdletters en kleine letters
  • Willekeurige symbolen toevoegen
  • Pas de instellingen aan voor verschillende accounts
  • Blijf regelmatig op de hoogte

If memorizing multiple credentials is too tricky, use a password manager to store the details only you can access with a master password and two-factor authentication.

3. Gebruikersrechten beheren

Regulating user roles and permissions is a standard security audit practice. Whenever someone leaves or switches to a different role, their original access credentials should be modified accordingly.

Afhankelijk van het aantal gebruikers dat aan een website werkt, kan het lastig zijn om iedereen in de gaten te houden, vooral als de sitebeheerder het al druk genoeg heeft.

Someone should be in charge of it. Having said that, ensure your back-office team is equally trustworthy. Choosing the people you can trust is crucial. Going rogue is the last thing one would want to see from their staff.

4. Het SSL-certificaat instellen

PCI compliance indicates that the SSL protocol is mandatory. Nevertheless, not all online merchants bother setting it up.

Missing the certificate is a significant red flag, identifiable by internet browsers and website visitors.

A proper SSL certificate is a security measure for the site and its visitors. Once the certificate is in place, the website's URL transforms from HTTP to HTTPS. The "S" stands for secure. To ensure proper setup, use an SSL certificate checker to verify that the certificate is correctly configured for the domain.

HTTPS encrypts the information that a website receives. Hackers have a much harder time trying to crack the data when it is encrypted. Most of them give up and look for new targets.

5. Zoek een betrouwbare en veilige hostingprovider

Since hosting providers have your site in their hands, finding one that offers more than just a 99.9% uptime guarantee is crucial.

Let goed op de beveiligingsfuncties die bij het pakket worden geleverd, en aarzel niet om wat extra te betalen om van deze beveiligingsmaatregelen te profiteren.

Voordat je een keuze maakt, moet je grondig naar beoordelingen zoeken om er zeker van te zijn dat je de juiste hostingprovider hebt gekozen. Vraag indien mogelijk om persoonlijke aanbevelingen van mensen die je kent en vertrouwt. Online beoordelingen van onbekenden zijn immers soms twijfelachtig.

6. Automate Chargebacks

Software solutions offer businesses a lifeline, and Chargeflow’s chargeback automation software is a great example.

Wanneer de software een transactie analyseert en patronen van frauduleuze activiteiten detecteert, waarschuwt deze de handelaar, stelt een reactie op de terugvordering op en dient namens hem bewijsmateriaal in.

In plaats van te wachten tot uw acquirer u op de hoogte stelt wanneer kaarthouders een geschil indienen – wat er vaak toe leidt dat de tijd opraakt om overtuigend bewijs te verzamelen en effectief te reageren – kunnen bedrijven altijd tijdig en volledig reageren op chargeback-claims en geschillen automatisch oplossen. Dankzij de prestatiegerichte prijsstelling Chargeflowbetaalt u bovendien alleen voor gewonnen zaken.

Conclusie

Al met al blijven cybercriminelen een probleem vormen voor online winkeliers. E-commercewinkels blijven kwetsbaar voor verschillende bedreigingen.

It is up to the site admins to raise awareness about threats that present problems so that everyone involved knows what to do.

Taking proactive measures and keeping up with cybersecurity trends is also worthwhile. Anything that helps you fend off cybercriminals will save you money in the long run.

DEEL DIT ARTIKEL
Wit, rond logo met in het midden in elkaar grijpende vormen, omgeven door overlappende, baanachtige elliptische lijnen en verspreide blauwe ruitvormen.

Chargebacks?
Dat is niet langer jouw probleem.

Haal 4x meer chargebacks terug en voorkom tot 90% van de inkomende betalingen, dankzij AI en een wereldwijd netwerk van 20.000 handelaren.

Meer dan 600 beoordelingen
Geen creditcard nodig.
abonneren

De nieuwste artikelen over ' chargebacks', fraude en e-commerce, rechtstreeks in je inbox. Elke week.

Meld je nu aan en mis nooit meer de nieuwste trends!
Door je e-mailadres op te geven, ga je akkoord met onze Gebruiksvoorwaarden en onze privacyverklaring
Schema met gestreepte en gebogen lijnen die gesegmenteerde bogen vormen, gemarkeerd door drie blauwe ruitvormige markeringen aan de linkerkant.Een abstract ontwerp met een cirkelvormig raster en blauwe ruitvormige markeringen op een halfzwarte, halfwitte achtergrond.