Skip to content
Skip to main content
Payments & Banking Technical Explainer

Could a merchant account have been compromised?

Yes. Stolen credentials, compromised recovery channels or sessions can let an offender alter listings, messages and payout details while retaining the genuine merchant identity.

Takeover can redirect value invisibly

Relevant changes include new endpoints, password resets, contacts, users, payout accounts, prices, refund destinations and customer instructions. Existing sessions or devices can conceal takeover behind familiar access.

Test the security and payout timeline

Preserve logins, endpoints, sessions, roles, change history, security alerts and old and new payout destinations before remediation. Compare normal operation with disputed orders, payments, messages and delivery.

Merchant denial and valid authentication are neither conclusive. Identify whether the alleged route existed and could make the changes, and report merchant-account activity separately from action proven by the genuine business.

The point to remember

Test merchant compromise through access, security-change and payout evidence before attributing account activity to the genuine seller.

Reference: PAY-100Payments & Banking