What issues can the attack cause for a Merchant?
Increased Payment Failure Emails
It is common to see a spike of failed payment emails sent to the set contact email address. This can prevent customer services teams from following up with genuine customers and in extreme cases, it can also cause mail deliverability issues if you are using a quota-based email sender.
Resource usage
Depending on the bot’s activities and its frequency, server resources can be taken up by these malicious bots needlessly. In extreme cases, database tables for email logging increase exponentially in size, modules such as “MagePlaza SMTP” can log every outgoing email. This can result in downtime if disk capacity limits are hit.
Security and Financial Impact
In this type of attack, card credentials are not being stolen directly from the targeted website as they are from another source. However, you do not want your website/brand to be used as a testing platform for card theft. A merchant could also see an increase in chargeback requests which could have a negative financial impact and consume internal admin resources dealing with the requests.
‍