June 18, 2026

Online Payments: Do’s and Don’ts

With a large percentage of shopping now taking place online, creating accounts and saving payment methods has become a normal part of everyday life. The convenience of one-click purchases, automatic renewals and digital wallets can save time and simplify transactions. What many consumers do not realize, however, is that every online account tied to a payment method creates another potential entry point for cybercriminals to access their information and financial accounts.

Threat actors frequently target online shopping accounts because they often contain saved payment information, personal data and reused passwords. A compromised retail account may allow attackers to make fraudulent purchases, steal financial information or use exposed credentials in attacks against other websites. 

While online payments are generally secure, practicing strong cybersecurity habits before and after using a card online can significantly reduce the risk of fraud and account compromise. Take some time to review our previous newsletters on safe online shopping, then follow the tips below to better protect your financial information once you are ready to make a purchase.

Be Smart When Paying Online

  • Use a credit card instead of a debit card whenever possible. Credit cards generally offer stronger fraud protection than debit cards. Under federal law, credit card fraud liability is typically capped at $50, while debit card fraud can become far more costly if fraudulent activity is not reported quickly. In some cases, delayed reporting on debit card fraud can result in substantial financial loss.
  • Consider using a digital wallet. Digital wallets such as Apple Pay or Google Pay add an additional layer of protection by generating a unique payment token instead of sharing your actual card number directly with the merchant. This helps reduce exposure if a retailer experiences a data breach.
  • Check to see if your credit card company offers virtual card numbers. Some credit card companies offer virtual card numbers for online purchases. These temporary or merchant-specific card numbers help protect your real account information and can limit damage if payment data is compromised.
  • Limit where you save your card information. Avoid saving payment methods on every website you visit. Consider using a single, trusted vendor for recurring purchases such as groceries, clothing or subscription services. Use the guest checkout option for retailer sites that you do not regularly visit. Fewer stored cards means fewer opportunities for attackers to access your information.

Best Practices for Online Shopping

  • Create strong passwords and enable multifactor authentication (MFA).
    Online shopping accounts should be protected with strong, unique passwords and MFA whenever available. If a threat actor gains access to an account containing saved payment information, they may be able to make unauthorized purchases or steal additional personal information.
  • Turn on transaction alerts. Most banks and credit card companies allow customers to receive text messages, emails or app notifications for purchases and account activity. Transaction alerts can help identify fraudulent activity quickly before additional unauthorized charges occur.
  • Review and audit saved payment methods regularly. At least once every quarter, review the cards saved to your online accounts and remove outdated payment methods or unfamiliar accounts. Regularly checking account activity and saved payment information can help prevent and detect unauthorized access early.
  • Think you may have entered your card in suspicious or fraudulent website? Contact the card issuer immediately; they can help you lock or freeze the card in question. Monitor your accounts carefully and dispute any suspicious activity immediately. Check out last month’s newsletter for more information on what to do if hacked.

Saving payment methods while shopping online can make everyday life more convenient, but it also requires you to remain extra vigilant about cybersecurity. By choosing safer payment methods, limiting where card information is stored, using strong account security practices and monitoring account activity regularly, you can greatly reduce the risk of online payment fraud and identity theft. A few proactive habits can go a long way toward keeping personal and financial information secure in the digital world.

 

Cyber Habit of the Month: Recognize, Avoid and Report Brushing Scams

Have you received a package you did not order? What seems like a simple mix-up could be a threat actor trying to scam you! 

Brushing scams occur when someone receives unexpected packages containing items they never ordered, often from online marketplaces or third-party sellers. A seller using your real name and address can create fake verified purchases and positive reviews online. In some cases, the scammers may have obtained personal information (names, addresses, phone numbers, or account details) through previous data breaches or publicly available information. Receiving an unsolicited package does not necessarily mean financial accounts have been compromised, but it can indicate personal information is being misused without permission.

If you receive merchandise you did not order, avoid scanning any QR codes included in the packaging or contacting unknown senders through unofficial channels, as these may lead to phishing websites or additional scams. Attempt to return package to the sender. Review your online shopping and financial accounts for suspicious activity, update passwords if needed and enable multifactor authentication whenever possible. 

You should also report brushing scams to the online marketplace involved and consider filing a report with the Federal Trade Commission and the Better Business Bureau, especially if you suspect your personal information may have been misused. Staying alert to unusual deliveries can help protect against larger fraud and identity theft attempts.

 

Additional Resources