&w=3840&q=75)
- Financial Management
Small Business Security: Five Tips to Avoid Credit Card Fraud
Never share your Zeller account password; keep credentials secure and confidential.
Don’t transfer money on behalf of customers to avoid fraud and chargebacks.
Avoid clicking links from unknown sources to prevent phishing attacks.
Stop relying on outdated magstripe readers; prefer secure chip/tap payments.
Be vigilant with over‑the‑phone payments to verify identity and prevent scams.
When you accept payments with Zeller, you're not alone. However, there's even more you can be doing to safeguard your business against scammers. Read on to learn our top five tips.
Behind every Zeller transaction is a team of anti-fraud experts and 24/7 monitoring. Card-not-present transactions made via Payment Link, Zeller, and Xero Invoices also carry the added protection of 3D Secure, giving you and your customers extra confidence that a payment is legitimate. In addition to the best practices outlined below, you can be sure your account will be kept secure.
1. Never give away your Zeller Account information
No one needs to know your Zeller password except you. We will never ask you for it, and neither should your employees. It's imperative that you not only keep this to yourself, but that your password can't easily be guessed. Scammers who manage to acquire account information can log in, change passwords and account details, add themselves as authorised users, and start transferring money or requesting new cards to be issued.
To help counteract this, Zeller has enabled two-factor authentication and also sends real-time security notifications that will immediately alert you to any changes to your account, such as logins from new devices, or password or detail changes. It's important, however, not to rely on these layers of security alone — they're designed as a last resort. Instead, you must ensure that your account information doesn't get into the wrong hands in the first place.
Need to give your team members access to your Zeller Account? Learn how to manage user permissions here.
2. Never transfer money on behalf of a customer
One common type of scam that targets small businesses involves a fraudster deliberately overpaying for a service and requesting that the additional funds be transferred to a third party. This type of scam is becoming increasingly common in the hospitality and service industry, so it's important to know what to look out for. It typically involves a fraudster using a stolen credit card and pretending to work on behalf of a client. They seek out services that can be associated with other services, for example:
A bridal shop and a limousine driver
An event space and a partyware hire business
A restaurant and a florist
How does it work?
Let's take the example of the restaurant and the florist. A fraudster contacts your restaurant saying they're organising a dinner for a client. They request to pay up front for a set menu for 10 people, which comes to a total of $1,000. However, they pay you $2,000 and ask you to transfer the extra $1,000 to the florist who will be providing the floral arrangements on the night. This "florist," however, is an associate of the scammer. When the rightful owner of the credit card becomes aware of the illegitimate $2,000 transaction, they'll request a chargeback, and your business will lose the transaction amount. Unlike other financial service providers, Zeller will not charge your business additional chargeback fees, and our dedicated Account Services team will work with you to compile information to help you defend the chargeback, too.
What are chargebacks?
A chargeback is a transaction reversal initiated by a cardholder's bank or credit card issuer. It allows the cardholder to dispute a charge on their statement and request a refund. Chargebacks are typically associated with unauthorised or fraudulent transactions, billing errors, or situations where the cardholder is dissatisfied with a purchase. Read our article on how to protect your business from chargebacks here.
3. Never click on a link from an unknown source
One of the ways fraudsters acquire account information is through cyber attacks, otherwise known as phishing. This involves tricking individuals into revealing banking information such as account passwords or credit card details. Most commonly, attackers will contact you via email, phone, or SMS and either ask you to confirm your account information, or invite you to click on a link. Once clicked, the link might install a virus on your computer, giving fraudsters a way to start gaining access to your accounts.
If you're not sure, always proceed with caution. If you receive a request from a known service provider asking for information, contact them through their official customer service channels, not through the message you received. Legitimate Zeller email addresses will always end with "@myzeller.com," and if we contact you via text message, the contact name will automatically appear as "Zeller."
What is phishing?
Phishing is a type of cyber attack where scammers impersonate a trusted organisation — like a bank, payment provider, or government agency — to trick you into handing over sensitive information such as passwords, card details, or one-time codes. It usually arrives as an email, text message, or phone call that creates a sense of urgency, asking you to "verify" your account or click a link to resolve a problem. The link often leads to a fake login page designed to capture your details, or triggers a malicious download. The best defence is to never act on unsolicited requests for information — go directly to the provider's official app, website, or phone number instead.
4. Stop using magstripe card readers
A magnetic stripe, or "magstripe," is a thin strip of magnetic material found on the back of credit and debit cards. The strip contains encoded data which, when swiped through a magstripe reader, is transmitted to a business's payment provider, enabling authorisation and processing of the transaction. The problem with this technology — invented more than 60 years ago — is that the encoded data is very easy to duplicate. Fraudsters can place small electronic devices called "skimmers" into EFTPOS machines or ATMs, for example, to capture credit card information straight from the magstripe.
As a result, chip-based EMV technology has become the global standard. EMV cards have an embedded microprocessor chip that's tamper-proof and nearly impossible to clone, making it a far more secure alternative. When a customer taps or dips their card, the payment is processed using EMV technology. Zeller Terminal supports both EMV and magstripe transactions, but will only ever prompt a customer to swipe their card if the card presented doesn't have a chip, or if the chip is broken. If you're using an older EFTPOS machine or a mobile card reader, be cautious around customers who insist on swiping their card rather than tapping or dipping it.
5. Be extra vigilant when taking payments over the phone — or better, use a Payment Link instead
Over-the-phone payments, otherwise known as MOTO payments (short for "mail order telephone order"), let you manually enter a customer's card details on Zeller Terminal or Zeller Virtual Terminal. Because the customer isn't in front of you, it's harder to physically verify that the person making the payment is in fact the legal cardholder. Whenever you're processing a payment over the phone, watch out for:
Large orders with unusual quantities being placed by new customers
Orders where the card initially declines and the customer keeps providing different card details to complete the transaction
Orders where the customer requests payment be made to a third party (see tip #2 above)
Any of the above should immediately raise red flags. If you're suspicious a transaction may be fraudulent, or you're simply taking a MOTO payment from a customer you don't know, we recommend the following:
Take down the card details, including the full name
Take down the billing address
Request ID as a screenshot or photo, if possible
If the products are being shipped, provide tracking details and request the customer's signature
Make sure the billing and shipping addresses match, and if they don't, ask why. Also check that the name on the payment card matches the ID provided. If your customer isn't willing to provide any of the details above, we recommend you don't proceed with the transaction or accept any type of payment.
A more secure alternative: Payment Links
Where possible, consider using a Payment Link instead of taking a MOTO payment. Because you're keying in the card details yourself on a MOTO payment, there's no way to confirm the person on the other end of the phone is the legitimate cardholder. Payment Links close that gap. When you send a customer a payment link — from Zeller Dashboard or Zeller App — they enter their own card details on Zeller's secure payment page, which is protected by 3D Secure (3DS). This adds an identity check directly with the customer's bank: the customer may be prompted to authorise the transaction instantly, or to enter a one-time code sent by their bank. If they leave the page before completing this step, the payment is declined outright rather than going through unverified.
For remote transactions like deposits, pre-orders, or any payment where the customer isn't physically present, this makes Payment Links a stronger first choice than MOTO, and a meaningful extra safeguard against the kind of card-not-present fraud described above.
&w=1920&q=75)
Keep your business finances safe with Zeller
Our dedicated team pairs advanced tools with round-the-clock monitoring to catch suspicious activity fast. If a chargeback occurs, our disputes team handles it with the bank at no cost to you.
&w=3840&q=75)

&w=3840&q=75)
&w=3840&q=75)