Beware of Credit Card Fraud / Bot Activity

We are experiencing what appears to be bot activity that involves fake accounts using stolen credit cards on our TNEW ticket purchase path. This activity has greatly increased in the past week and is a major issue.

If you use TNEW you should be reviewing orders and on the lookout for fishy behavior. 

I'm posting this here to help the community with general awareness. If you discover similar behavior on your TNEW purchase path, perhaps post below or notify Tessitura so they are aware of how widespread this fraud scheme is.

Parents
  • I do also agree/hope that everyone who is noticing alerts Tessitura so we have an idea of how bad it really is.  And I would love if there could be a public response from Tessitura in the near future about what's going on/what can be done/what is being done, assuming it really is bad as I fear

  • We are still on Windcave and enabled strictest AVS. Hoping that helps stop some of the bleeding we were feeling. We have started seeing "address not match, zip match"  and some of the records don't have an address match in Windcave so they are rejecting. Below are the AVS settings we could choose from and went with option 2. We don't want to open the flood gates if we can help it.

    • 0-Do Not Check AVS - AVS details are not checked with the acquirer but are passed through to Payment Express.
    • 1-Decline Transaction if AVS Fails - AVS details are checked with the acquirer and the transaction is declined if a failed response is received. If an AVS response is not received, the transaction is not declined.
    • 2-Decline if AVS Fails or is Unavailable - AVS details are checked with the acquirer and the transaction is declined if a failed response or no response is received.
    • 3-Check AVS but Do Not Decline - AVS details are checked with the acquirer but the transaction is not declined if a failed response is received.
    • 4-Decline transaction only if AVS response is N (accept partial matches) – Attempt AVS check. If the acquirer does not support AVS or AVS is unavailable, then the transaction will proceed as normal. If AVS is supported and the AVS check fails with a response of N (address and postcode both do not match what issuer has on file), then the transaction will be declined. Partial AVS matches such as postal code only matches or address only matches will be accepted.
Reply
  • We are still on Windcave and enabled strictest AVS. Hoping that helps stop some of the bleeding we were feeling. We have started seeing "address not match, zip match"  and some of the records don't have an address match in Windcave so they are rejecting. Below are the AVS settings we could choose from and went with option 2. We don't want to open the flood gates if we can help it.

    • 0-Do Not Check AVS - AVS details are not checked with the acquirer but are passed through to Payment Express.
    • 1-Decline Transaction if AVS Fails - AVS details are checked with the acquirer and the transaction is declined if a failed response is received. If an AVS response is not received, the transaction is not declined.
    • 2-Decline if AVS Fails or is Unavailable - AVS details are checked with the acquirer and the transaction is declined if a failed response or no response is received.
    • 3-Check AVS but Do Not Decline - AVS details are checked with the acquirer but the transaction is not declined if a failed response is received.
    • 4-Decline transaction only if AVS response is N (accept partial matches) – Attempt AVS check. If the acquirer does not support AVS or AVS is unavailable, then the transaction will proceed as normal. If AVS is supported and the AVS check fails with a response of N (address and postcode both do not match what issuer has on file), then the transaction will be declined. Partial AVS matches such as postal code only matches or address only matches will be accepted.
Children
No Data