iFraud™ Explained: What It Does and Doesn't Do
Discover how iFraud™ protects your IHASHOP store. Learn how this risk memory and early warning system flags fraudulent transactions without causing false positives.
What is the Core Function of iFraud™?
iFraud™ is a risk memory and early warning system designed to log historical risk events, suspicious customers, and fraudulent transactions on your IHASHOP store.
If an email address, phone number, IP address, or domain name associated with a customer or transaction was previously flagged as risky, the system alerts the store administrator when the same details are used in a new order or return request.
The module’s purpose is not to make automated decisions, but to empower store administrators with historical data to make informed choices.
What Does iFraud™ Do?
iFraud™ performs the following core functions:
Alerts Administrators on Risky Transactions
When a new transaction matches an existing risk record, a warning is displayed directly in the admin panel.
This alert is prominently displayed on:
- Order details page
- Return request details page
This allows you to review historical risk logs before fulfilling an order or approving a refund.
Builds Your Store's Risk Memory
Historical chargebacks, payment fraud, fake accounts, refund abuse, or similar incidents are permanently logged.
Even if your staff changes or years pass, this crucial risk intelligence remains secure in your store’s database.
Matches Multiple Identifiers
Risk profiles can be cross-referenced using multiple data points:
- Customer account
- Email address
- Phone number
- IP address
- Domain name
Even if a customer changes their email, a match can still be triggered if they use the same phone number or other unique identifiers.
Stores the Reason for the Risk Flag
Each risk entry stores the incident reason, description, evidence summaries, and operational history.
This ensures administrators can easily understand why an order was flagged for manual review in the future.
Receives Alerts from the Centralized Risk Network
When running in Centralized Mode, the module leverages secure, anonymized risk matches from other stores within the IHASHOP ecosystem.
To ensure privacy, other stores' customer data, store identities, descriptions, or evidence are never exposed. You only receive a secure alert indicating a risk match was found during an active transaction.
Leaves the Final Decision to the Administrator
iFraud™ provides critical risk intelligence but never forces an action. After reviewing the alert, the administrator can:
- Process the order normally,
- Request additional verification from the customer,
- Put the order on manual hold,
- Decide based on their own store policies.
What Doesn't iFraud™ Do?
iFraud™ is not an automated enforcement system. It operates with zero automated interference.
It Does Not Block Payments
iFraud™ never automatically stops, blocks, or declines payment processing. A risk warning will not interfere with your payment gateway's operations.
It Does Not Auto-Cancel Orders
The module does not cancel, reject, or change the status of an order automatically. The decision always rests with the store owner.
It Does Not Process Auto-Refunds
While it flags risky return requests, it never automatically approves or declines a refund.
It Does Not Suspend Customer Accounts
Flagging a transaction does not automatically suspend, restrict, or delete a customer's account.
It Does Not Auto-Blacklist Customers
Records created in iFraud™ do not function as an automated blacklist. The module simply displays historical risk data for administrative review.
It Does Not Show Alerts to Customers
All iFraud™ alerts are strictly internal and visible only in the admin panel. Customers cannot see:
- That they have an active risk record,
- That their order triggered a risk warning,
- That they matched the Centralized Risk Network.
It Does Not Share Raw Personal Data with Other Stores
Other IHASHOP stores can never view a customer's raw email, phone number, IP address, or risk descriptions. The Centralized Risk Network utilizes irreversible, secure cryptographic fingerprints (hashes).
It Does Not Offer Public Risk Lookups
There is no public search interface to manually query emails or phone numbers in the central database. Risk queries are executed automatically and only during an active checkout or return process.
Is an iFraud™ Alert a Definitive Verdict?
No. A risk warning does not guarantee that a customer is malicious. False positives can occur due to several factors:
- Multiple users sharing the same dynamic IP address.
- A phone number being transferred to a new owner.
- Shared corporate or public Wi-Fi networks.
- An incomplete or incorrectly logged record by an admin.
- Legacy contact details now used by a different individual.
Therefore, an iFraud™ alert is not an accusation; it is a security notification advising a more careful review of the transaction.
Why Doesn't It Make Automated Decisions?
The primary reason iFraud™ avoids automated blocking is the risk of false positives. Automated systems can mistakenly block legitimate buyers due to overlapping data points. Thus, the module’s core philosophy is:
iFraud™ does not make the decision; it provides the vital intelligence you need to make it.
This approach maximizes store security while preventing innocent customers from being wrongfully turned away.
Conclusion
iFraud™ is not an automated system that cancels orders on your behalf. Its goal is to:
- Remember historical risks,
- Cross-reference them with new transactions,
- Provide early warnings to store administrators,
- Support your decision-making process with solid data.
The final decision regarding payments, orders, refunds, or customer accounts always remains in the hands of the store administrator.