Could a merchant account have been compromised?¶
Yes. Stolen credentials, compromised recovery channels or sessions can let an offender alter listings, messages and payout details while retaining the genuine merchant identity.
Takeover can redirect value invisibly¶
Relevant changes include new endpoints, password resets, contacts, users, payout accounts, prices, refund destinations and customer instructions. Existing sessions or devices can conceal takeover behind familiar access.
Test the security and payout timeline¶
Preserve logins, endpoints, sessions, roles, change history, security alerts and old and new payout destinations before remediation. Compare normal operation with disputed orders, payments, messages and delivery.
Merchant denial and valid authentication are neither conclusive. Identify whether the alleged route existed and could make the changes, and report merchant-account activity separately from action proven by the genuine business.
The point to remember
Test merchant compromise through access, security-change and payout evidence before attributing account activity to the genuine seller.