Risky Status

20-Min Teaching Session Outline

โฑ 20 min
๐ŸŽ“ Abuse & Fraud Prevention

Presented by: Ramaudhita Hasanah

Segment 1 โ€ข 3 mins

What is Risky Status?

Definition

An account flagged due to fraud signs, chargeback history, or unusual purchase patterns.

What It Does

Restricts payment methods only.

hFraud block โ†’ restricts payment methods only, services stay active.

Chargeback โ†’ service is temporarily suspended until repayment is confirmed, then reactivated.

Affected Payment Methods: hFraud works by blocklisting a specific payment method identifier โ€” it needs a unique, reusable identifier to track across accounts

  • Credit cards
  • PayPal
  • PIX (Pix_key)
  • Razorpay
  • Payment methods like cryptocurrency, bank transfers, or one-time virtual accounts are typically not blocklisted because they're either one-time-use, harder to link across accounts, or not processed through the same fraud tracking pipeline.

Where to See It

Top of the client profile in CRM ("risky / not risky").

Segment 2 โ€ข 5 mins

How Does an Account Get Flagged?

1. hFraud (Automated Blocking)

  • Triggered when a payment method is linked to a mass-suspended account.
  • hFraud evaluates the payment method across ALL accounts, not just the customer's.
  • Example: Account A gets mass-suspended โ†’ card is blocklisted โ†’ Account B uses the same card โ†’ gets auto-flagged as Risky.
โš ๏ธ Customer saying "I always used this card" doesn't mean they're innocent.

2. Chargeback / Dispute

  • A chargeback filed against Hostinger triggers Risky status.
  • CRM will have a note with chargeback details.
Segment 3 โ€ข 7 mins

Decision Tree: Check Flow

Step 1 & Step 2: Identify the Scenario

Open CRM โ†’ check Notes + Risky status at top of profile.

  • Risky + no chargebacks: follow risky handling flow
  • Risky + no CRM notes + suspicious domain refund: domain suspicious flow
  • Chargeback + service suspended: chargeback suspended flow
  • Chargeback + service canceled: regular canceled service procedure
  • Payment refunded due to fraud: suspected fraud/refund flow
Segment 3 โ€ข 7 mins

Decision Tree: Investigation & Action

Step 3: For hFraud Cases

  • Go to Customer Risk Factors.
  • Search by Customer ID.
  • Check if account was mass-suspended + check Relations column for linked payment methods.
  • Look for red flags: multiple relation IDs, same IPs, similar domain patterns, prior suspensions.

Abuse Confirmed

Decision is final, send #abuse-risky-permanent2, no workarounds.

No Clear Evidence

Escalate via Appeal Process to Abuse Prevention team.

Segment 4 โ€ข 3 mins

Appeals & Escalation

โš ๏ธ Appeals are possible but not guaranteed. Do NOT offer an appeal if there are clear signs of abuse.

Check Abuse Probability Score

Look up in Customer Risk Factors:

  • Score > 70%: send #abuse-hfraud-appeal-docs-high
  • Score < 70%: send #abuse-hfraud-appeal-docs-low

After Docs Submitted

Create ticket (Topic: "Abuse: Risky/hFraud").

Priority Escalation

Only if docs are uploaded AND customer is insisting/threatening public complaint โ†’ post in the abuse channel and ping @abuse-fraud-firefighter.

Segment 5 โ€ข 2 mins

Key Reminders & Resources

๐Ÿšซ What NOT to Do

  • Never disclose internal fraud tools (hFraud, Ravelin) or their triggers to customers.
  • Never offer workarounds (e.g., "just use another card") when abuse is confirmed.

โœ… Best Practices

  • Always keep communication high-level: "security concerns".
  • Use predefined macros: #abuse-risky-permanent1/2/3.
Slide 1 of 7