Could a merchant account have been compromised?¶
Yes. A merchant, seller or marketplace account can be compromised and used to redirect payments, alter listings or issue fraudulent instructions.
Avoid the dangerous assumption¶
The dangerous assumption is that activity recorded under the merchant account was carried out by the genuine business or seller.
An offender may obtain credentials through phishing, password reuse, malware, session theft or compromised email.
They may change payout details, contact information, prices, listings, refund destinations or customer messages.
A compromised account may continue to display the genuine merchant name while funds are redirected elsewhere.
Look for new devices, unusual IP addresses, password resets, changed payout accounts, altered contact details, new users, failed logins and security alerts.
Preserve account-access, device, session and change-history records before the account is secured.
Obtain the merchant’s internal user roles and identify who could change payment or payout settings.
Compare normal payout destinations with the disputed ones.
Communications may reveal phishing, support impersonation or instructions to move the conversation away from the platform.
Do not assume compromise merely because the merchant denies the activity. Test the explanation against provider records.
Equally, do not dismiss compromise because valid credentials or authentication were used. An offender may have controlled an existing session or device.
Where customers were affected, preserve the orders, payments, messages and delivery records for each one.
When reporting, distinguish activity associated with the merchant account from activity proven to have been carried out by the merchant.
Operational takeaway¶
Test merchant-account compromise by preserving access, device, security-change and payout records and comparing disputed activity with the merchant’s normal operation.