Card-Not-Present online commerce draws fraud and that is a reality that you need to address. There are methods to mitigate the losses from fraud. You could collect webserver, internet traffic data and credit card data to filter your signups to prevent this happening in the future. One such company that could help is siftscience.com.
You can request strict full address validation and request that charges fail on CVC mismatch. On the cashout side, you can use a system like http://www.idology.com/ for identify verification, which can be either as complete or as superficial as you want it to be (think credit card application level verification, with questions about past employers, loans and monthly payment amounts). If this person has all the information to steal your customer's identity, then you can't really defend yourself against that scenario and that customer likely has to deal with larger identity theft issues.
Comments
Card-Not-Present online commerce draws fraud and that is a reality that you need to address. There are methods to mitigate the losses from fraud. You could collect webserver, internet traffic data and credit card data to filter your signups to prevent this happening in the future. One such company that could help is siftscience.com.
I'm curious to those that downvote how they would address online fraud. It is a real problem with online commerce.
You can request strict full address validation and request that charges fail on CVC mismatch. On the cashout side, you can use a system like http://www.idology.com/ for identify verification, which can be either as complete or as superficial as you want it to be (think credit card application level verification, with questions about past employers, loans and monthly payment amounts). If this person has all the information to steal your customer's identity, then you can't really defend yourself against that scenario and that customer likely has to deal with larger identity theft issues.