LAST CHANCE SERVICE - FAILED REFUNDS SERVICE
After studying Amazon's refund channels, I often see that many people face difficulties and are unable to create another account and place an order. This happens because Amazon's anti-fraud system, the largest online store in the world, is nearly perfect. However, in any perfect system, there will be vulnerabilities and ways to bypass them; otherwise, they wouldn't be able to attract new customers and grow. On this channel, we will discuss why this happens, what your mistakes are, and how to correct them.
After studying Amazon's refund channels, I often see that many people face difficulties and are unable to create another account and place an order. This happens because Amazon's anti-fraud system, the largest online store in the world, is nearly perfect. However, in any perfect system, there will be vulnerabilities and ways to bypass them; otherwise, they wouldn't be able to attract new customers and grow. On this channel, we will discuss why this happens, what your mistakes are, and how to correct them.
❤1
Warning - lots of smart info below!
When registering a new account, Amazon and other merchants checks a vast amount of parameters to exclude multi-accounting. The most obvious and logical ones include email, address, phone number, IP address, card details and etc. However, there are also less obvious parameters that can identify you as a customer who has previously had an account that was closed due to violations of their rules (most likely due to refunds or multi-accounting). One of these is the device from which you are trying to register again. Remember, you will always be identified, and your account will be closed again and again.
This happens because every device can be identified by several dozen parameters, which is referred to as device fingerprinting. Fifteen years ago, user identification relied primarily on cookies, and it was sufficient to delete them. However, today, anti-fraud systems can even capture the digital fingerprint of your graphics processor. Currently, it is not possible to create an new account even on a dedicated server or VPS, as they do not use a graphics processor, making them easily identifiable based on many other parameters, causing your account to be immediately flagged.
The same applies to mobile devices; they can easily be identified by the brand and model of the device, MAC address, browser fingerprint, TCP/IP configuration, and many other parameters. All this data is collected not only by specific online stores or services but also by anti-fraud services that collect, store, and exchange this information with each other. These services are used by both large and small online stores, banks, and other services.
When registering a new account, Amazon and other merchants checks a vast amount of parameters to exclude multi-accounting. The most obvious and logical ones include email, address, phone number, IP address, card details and etc. However, there are also less obvious parameters that can identify you as a customer who has previously had an account that was closed due to violations of their rules (most likely due to refunds or multi-accounting). One of these is the device from which you are trying to register again. Remember, you will always be identified, and your account will be closed again and again.
This happens because every device can be identified by several dozen parameters, which is referred to as device fingerprinting. Fifteen years ago, user identification relied primarily on cookies, and it was sufficient to delete them. However, today, anti-fraud systems can even capture the digital fingerprint of your graphics processor. Currently, it is not possible to create an new account even on a dedicated server or VPS, as they do not use a graphics processor, making them easily identifiable based on many other parameters, causing your account to be immediately flagged.
The same applies to mobile devices; they can easily be identified by the brand and model of the device, MAC address, browser fingerprint, TCP/IP configuration, and many other parameters. All this data is collected not only by specific online stores or services but also by anti-fraud services that collect, store, and exchange this information with each other. These services are used by both large and small online stores, banks, and other services.
❤1
Reputation Points (FraudScore) - What Are They?
When you click the "Order" button (or sign-up ), your data is immediately subjected to scrutiny across all the parameters mentioned below. Here are a few additional aspects considered:
- IP Address:
The system checks for various indicators such as VPN detection, presence on spam lists, known harmful IP addresses, proxy usage, mismatches between the customer's country and IP address, discrepancies between the issuing card’s country and IP, and time zone inconsistencies.
- Email Address:
Analysis is conducted to determine if the email is from a disposable service, or if it contains numerous digits which could indicate fraudulent activity.
- Device Intelligence:
This involves a systematic approach to collecting device data, analyzing it, and validating identity. Businesses utilize this process to identify spoofed, compromised, or potentially harmful devices.
- Digital Footprint:
This technique employs email addresses, phone numbers, and IP addresses to instantly verify each user's digital identity. It also incorporates real-time behavioral data, associated accounts, and online presence to expedite the validation of authentic customers.
Each of these factors contributes differently to your fraud score, and when a threshold is reached, your transaction may receive an orange or red flag.
When you click the "Order" button (or sign-up ), your data is immediately subjected to scrutiny across all the parameters mentioned below. Here are a few additional aspects considered:
- IP Address:
The system checks for various indicators such as VPN detection, presence on spam lists, known harmful IP addresses, proxy usage, mismatches between the customer's country and IP address, discrepancies between the issuing card’s country and IP, and time zone inconsistencies.
- Email Address:
Analysis is conducted to determine if the email is from a disposable service, or if it contains numerous digits which could indicate fraudulent activity.
- Device Intelligence:
This involves a systematic approach to collecting device data, analyzing it, and validating identity. Businesses utilize this process to identify spoofed, compromised, or potentially harmful devices.
- Digital Footprint:
This technique employs email addresses, phone numbers, and IP addresses to instantly verify each user's digital identity. It also incorporates real-time behavioral data, associated accounts, and online presence to expedite the validation of authentic customers.
Each of these factors contributes differently to your fraud score, and when a threshold is reached, your transaction may receive an orange or red flag.
Remember the main principle of any antifraud system - it identifies indicators that differ from the average user. Your task is to mimic the average user in order to avoid raising suspicion with the anti-fraud system.
Amazon AVS Hold - The first level of your mistake.
It's worth noting that all of these checks can potentially be circumvented by acquiring a new device or employing anti-detection software, and by altering your address, card information, and IP address (which, notably, can also be easily traced by Amazon). However, what should you do if, with each new transaction, your newly created Amazon account on a fresh device is promptly flagged with a request for a bank statement for the card? If the issue persists even after submitting the statement? The key here is straightforward - you must persistently resend the statement after each rejection from Amazon until they either approve it or permanently disable your account. There are no alternative routes. This scenario arises because their internal anti-fraud system tracks the number of reputation points accumulated during registration and at the time of the order placement.
It's worth noting that all of these checks can potentially be circumvented by acquiring a new device or employing anti-detection software, and by altering your address, card information, and IP address (which, notably, can also be easily traced by Amazon). However, what should you do if, with each new transaction, your newly created Amazon account on a fresh device is promptly flagged with a request for a bank statement for the card? If the issue persists even after submitting the statement? The key here is straightforward - you must persistently resend the statement after each rejection from Amazon until they either approve it or permanently disable your account. There are no alternative routes. This scenario arises because their internal anti-fraud system tracks the number of reputation points accumulated during registration and at the time of the order placement.
👍3❤1
Since this is a large amount of information, I will be sharing it gradually. Subscribe to the channel
- IP Address:
Let's start to break things down gradually. The first two points that form the foundation of any anti-fraud system are the cleanliness of the IP. If you think that simply using a VPN or setting up a proxy is enough, I must disappoint you. VPNs and proxies can easily be identified through open ports, reverse ping, WebRTC check and several other more complex methods that I won't explain, as it would take several pages and not everyone would understand.
Any use of a VPN or dirty proxy will immediately raise a red flag.
https://www.ipqualityscore.com/ - here you can check the quality of your IP - registration is free of charge
Let's start to break things down gradually. The first two points that form the foundation of any anti-fraud system are the cleanliness of the IP. If you think that simply using a VPN or setting up a proxy is enough, I must disappoint you. VPNs and proxies can easily be identified through open ports, reverse ping, WebRTC check and several other more complex methods that I won't explain, as it would take several pages and not everyone would understand.
Any use of a VPN or dirty proxy will immediately raise a red flag.
https://www.ipqualityscore.com/ - here you can check the quality of your IP - registration is free of charge
❤2
- Email Address:
Next, let's move on to a simple indicator like the email address. It might seem like there’s nothing easier than this—just register a new Google email and go sign up on Amazon. However, I hate to break it to you, but all anti-fraud systems have long been checking emails through what's known as an email reputation check. This includes verifying the date the email address was created, its activity, and its connection to social networks (which is checked when registering a new account - and it's a reference to Digital Footprints).
Next, let's move on to a simple indicator like the email address. It might seem like there’s nothing easier than this—just register a new Google email and go sign up on Amazon. However, I hate to break it to you, but all anti-fraud systems have long been checking emails through what's known as an email reputation check. This includes verifying the date the email address was created, its activity, and its connection to social networks (which is checked when registering a new account - and it's a reference to Digital Footprints).
👎3❤1😁1
What is a digital footprint?
A digital footprint includes things like comments you make on websites, posts or pictures you share on social media, and any instances where your email address appears, whether on mailing lists or other places.
Here are some examples of a digital footprint linked to an email address:
- A Facebook profile linked to that email
- A Skype profile with your email, public name, and shared information
- A Google account that exists
- A Linkedin profile with a username
- And another 50 different social networks, messengers, etc.
Why does this matter?
When it comes to preventing fraud, having a digital footprint—and not having one—is equally important. It's hard for a fraudster to pretend to be a real, trustworthy customer if they lack this online history.
A digital footprint includes things like comments you make on websites, posts or pictures you share on social media, and any instances where your email address appears, whether on mailing lists or other places.
Here are some examples of a digital footprint linked to an email address:
- A Facebook profile linked to that email
- A Skype profile with your email, public name, and shared information
- A Google account that exists
- A Linkedin profile with a username
- And another 50 different social networks, messengers, etc.
Why does this matter?
When it comes to preventing fraud, having a digital footprint—and not having one—is equally important. It's hard for a fraudster to pretend to be a real, trustworthy customer if they lack this online history.
👎2❤1
-Device Intelligence:
There is nothing complicated about this - it is based on the parameters by which your device is identified and whether it has been previously involved in any activity.
Cookie Hash
Generated ID of the browser cookie session. If 2 users share this, it’s certain they are using the same browser and device. If the browser’s cookie and cache is being cleared, a new cookie hash will be associated with the device.
Browser Hash
A string of numbers and letters created to map data related to a user’s browser. In a way, it serves as the browser’s ID, used to identify the browser and user by the party who created the hash to begin with. This also means that it can help tell whether two users are accessing a website from the same browser.
Device Hash
A generated string of characters that contains information about the device and its user (e.g. local date and time, operating system version and type, GPU, screen data and more). Each hardware configuration (but not each individual device) has a unique ID. This helps find connections between seemingly different users. In mobile devices, the device hash serves as a unique identifier.
There is nothing complicated about this - it is based on the parameters by which your device is identified and whether it has been previously involved in any activity.
Cookie Hash
Generated ID of the browser cookie session. If 2 users share this, it’s certain they are using the same browser and device. If the browser’s cookie and cache is being cleared, a new cookie hash will be associated with the device.
Browser Hash
A string of numbers and letters created to map data related to a user’s browser. In a way, it serves as the browser’s ID, used to identify the browser and user by the party who created the hash to begin with. This also means that it can help tell whether two users are accessing a website from the same browser.
Device Hash
A generated string of characters that contains information about the device and its user (e.g. local date and time, operating system version and type, GPU, screen data and more). Each hardware configuration (but not each individual device) has a unique ID. This helps find connections between seemingly different users. In mobile devices, the device hash serves as a unique identifier.
👎2👍1
Collecting Parameters from Browsers:
-Cookie hash
-Browser hash
-Unique device hash / identifier
-Timezone of browser and IP
-Operating system detection
-Useragent information
-Private browsing detection
-Operating system, browser languages
-Screen size of device, browser, windows
-Installed fonts and generated hash
-Installed plugins and generated hash
-Battery level
-GPU information
-Browser features: flash, java etc.
-Canvas device fingerprint
-Audio fingerprint
-WebRTC IPs
-DNS: Geo + ISP
-Cookie hash
-Browser hash
-Unique device hash / identifier
-Timezone of browser and IP
-Operating system detection
-Useragent information
-Private browsing detection
-Operating system, browser languages
-Screen size of device, browser, windows
-Installed fonts and generated hash
-Installed plugins and generated hash
-Battery level
-GPU information
-Browser features: flash, java etc.
-Canvas device fingerprint
-Audio fingerprint
-WebRTC IPs
-DNS: Geo + ISP
❤1
Collected Parameters from iOS Devices
-Unique device hash / identifier
-Accessories information
-Audio information
-Battery information
-CPU information
-Advertising Identifier (ADID)
-Device name
-Device orientation
-Unique Device Identifier (UDID)
-iCloud ubiquity token
-iOS version data
-Jailbreak status
-Emulator detection
-Kernel information
-Boot information
-Network configuration
-Pasteboard data
-Memory information
-Proximity sensor data
-Local language
-Local timezone
-Screen brightness
-Screen resolution
-System uptime
-Storage information
-MAC address
-Wifi SSID
-TCP/IP Fingerprint
-Passive SSL/TLS handshake analysis
-Unique device hash / identifier
-Accessories information
-Audio information
-Battery information
-CPU information
-Advertising Identifier (ADID)
-Device name
-Device orientation
-Unique Device Identifier (UDID)
-iCloud ubiquity token
-iOS version data
-Jailbreak status
-Emulator detection
-Kernel information
-Boot information
-Network configuration
-Pasteboard data
-Memory information
-Proximity sensor data
-Local language
-Local timezone
-Screen brightness
-Screen resolution
-System uptime
-Storage information
-MAC address
-Wifi SSID
-TCP/IP Fingerprint
-Passive SSL/TLS handshake analysis
👎3👍1
Thank you all for reading the technical part, without understanding this you will not be successful. Next will be even more interesting - how to bypass all this and make successful orders
🔥5❤4
So what's better? An anti-detect browser or a new mobile device?
The answer is clear - a mobile device. It’s best to use it just once. It doesn’t necessarily have to be new. The process is simple - you buy a used or new smartphone from one of the major marketplaces (Facebook Marketplace, eBay, Craigslist, etc.). For optimal results, an iPhone starting from the 8th version is most suitable (if you're not using eSIM or mobile internet for esim iphone XS and newer), or any cheap Android device if you plan to use a physical nano-SIM or share internet from another mobile device.
In both cases, the effectiveness of this method depends on your location. With either option, you will have an advantage over anti-detection systems – fraud protection systems can detect anti-detect browsers and at most, you can create only two different new accounts before being identified. It might be possible to do mor if your anti-detect browser is running on macOS, as all Apple devices share the same internal hardware identifiers across their hardware lines. In any case, your Mac OS device will be identified; it will just happen a bit later.
What are the advantages of using new mobile devices each time? Lower costs and higher success rates for orders. Right after you’ve used a device, sell it in the same place you bought it and purchase another one - this way, you achieve maximum success at almost zero cost. At one time, you can “warm up” several mobile devieces – it’s easiest for beginners to manage 1-2 devices per week to avoid confusion. To start understanding the system, I would recommend buying 2 smartphones and begin “warming up” accounts on them, gradually increasing the number of devices. This way, you could easy manage around 8-10 new highly trusted accounts each month.
The answer is clear - a mobile device. It’s best to use it just once. It doesn’t necessarily have to be new. The process is simple - you buy a used or new smartphone from one of the major marketplaces (Facebook Marketplace, eBay, Craigslist, etc.). For optimal results, an iPhone starting from the 8th version is most suitable (if you're not using eSIM or mobile internet for esim iphone XS and newer), or any cheap Android device if you plan to use a physical nano-SIM or share internet from another mobile device.
In both cases, the effectiveness of this method depends on your location. With either option, you will have an advantage over anti-detection systems – fraud protection systems can detect anti-detect browsers and at most, you can create only two different new accounts before being identified. It might be possible to do mor if your anti-detect browser is running on macOS, as all Apple devices share the same internal hardware identifiers across their hardware lines. In any case, your Mac OS device will be identified; it will just happen a bit later.
What are the advantages of using new mobile devices each time? Lower costs and higher success rates for orders. Right after you’ve used a device, sell it in the same place you bought it and purchase another one - this way, you achieve maximum success at almost zero cost. At one time, you can “warm up” several mobile devieces – it’s easiest for beginners to manage 1-2 devices per week to avoid confusion. To start understanding the system, I would recommend buying 2 smartphones and begin “warming up” accounts on them, gradually increasing the number of devices. This way, you could easy manage around 8-10 new highly trusted accounts each month.
❤7👎2👍1
To everyone planning to follow this guide, I recommend purchasing a couple of mobile devices that you will use for your work and not turning them on yet.
There will be a post ahead about preparing the device for work, setting up the network connection, and one of the most crucial steps - Velocity IP/Checks, or as I call it - patience is the key to success.
There will be a post ahead about preparing the device for work, setting up the network connection, and one of the most crucial steps - Velocity IP/Checks, or as I call it - patience is the key to success.
🔥8👎2
👎3🖕3👍2💯1
Amz and Beyond... pinned «The chat is open - let's try to discuss all the questions there.»
Velocity Rules/Checks refer to a set of user behavior patterns that deviate from the average. For instance, attempts to complete a transaction with multiple new cards, changing passwords or emails before making a large transaction, and so on. This broad concept applies to all industries that utilize anti-fraud systems, including banking, gambling, and cryptocurrency exchanges.
I will specifically discuss this in the context of online shopping, particularly Amazon. You should closely align your behavior with that of an average user. Even if you are using a new device and follow all my previous tips, it may not be enough. A typical new user wouldn’t place an order for $300-1000 immediately after registration. If such a purchase occurs, you risk receiving an AVS hold.
A new user usually compares prices across different online stores, explores the category of interest, and reads reviews—this process is what we call "building cookies." Here is a suggested timeline for Amazon:
Day 1: You arrive at Amazon through a Google search (Amazon records your search query) and start exploring a product.
Day 2: You register on Amazon, add your address and credit card information (make sure to add all potential addresses and cards you plan to use).
Day 3 and onward: Continue browsing items in your chosen category (ideally 30-50 items).
Day 5: Place a small order, such as chips, coffee, socks, or detergent.
The goal is to mimic the behavior of a typical user. It would raise red flags for the anti-fraud system if a new user immediately orders high-risk items like Apple devices. If I were to stray from the topic of velocity rules, I would advise against ordering Apple devices if your account is less than a month old and you have not made at least ten small orders.
If done correctly, the odds of receiving an AVS hold on your second and subsequent small warm-up orders are minimal. However, you should avoid adding and shipping to new addresses, changing your credit card, or altering your password or email. If you change any of these parameters, allow your account to "rest and adjust to the new information" for about a week. Some issues can be mitigated if Amazon offers you a 3DS transaction, which can significantly reduce the fraud score during processing, as per the agreement between the merchant and the international payment systems Visa/MC. In cases of fraud, the responsibility for the transaction falls entirely on the payment system.
Why these strict rules? After all, you are a legitimate and law-abiding customer. The majority of fraud is linked to unauthorized transactions made with stolen credit cards, and all these protective measures are primarily aimed at combatting this category of criminals. A person who has stolen a credit card isn’t likely to wait 5-10-15 days and attempt to make small orders, as there is a significant risk that the legitimate cardholder will block the card. Amazon's anti-fraud system and AVS holds are primarily designed to tackle this issue, and you simply need to play by the rules I've outlined above.
I will specifically discuss this in the context of online shopping, particularly Amazon. You should closely align your behavior with that of an average user. Even if you are using a new device and follow all my previous tips, it may not be enough. A typical new user wouldn’t place an order for $300-1000 immediately after registration. If such a purchase occurs, you risk receiving an AVS hold.
A new user usually compares prices across different online stores, explores the category of interest, and reads reviews—this process is what we call "building cookies." Here is a suggested timeline for Amazon:
Day 1: You arrive at Amazon through a Google search (Amazon records your search query) and start exploring a product.
Day 2: You register on Amazon, add your address and credit card information (make sure to add all potential addresses and cards you plan to use).
Day 3 and onward: Continue browsing items in your chosen category (ideally 30-50 items).
Day 5: Place a small order, such as chips, coffee, socks, or detergent.
The goal is to mimic the behavior of a typical user. It would raise red flags for the anti-fraud system if a new user immediately orders high-risk items like Apple devices. If I were to stray from the topic of velocity rules, I would advise against ordering Apple devices if your account is less than a month old and you have not made at least ten small orders.
If done correctly, the odds of receiving an AVS hold on your second and subsequent small warm-up orders are minimal. However, you should avoid adding and shipping to new addresses, changing your credit card, or altering your password or email. If you change any of these parameters, allow your account to "rest and adjust to the new information" for about a week. Some issues can be mitigated if Amazon offers you a 3DS transaction, which can significantly reduce the fraud score during processing, as per the agreement between the merchant and the international payment systems Visa/MC. In cases of fraud, the responsibility for the transaction falls entirely on the payment system.
Why these strict rules? After all, you are a legitimate and law-abiding customer. The majority of fraud is linked to unauthorized transactions made with stolen credit cards, and all these protective measures are primarily aimed at combatting this category of criminals. A person who has stolen a credit card isn’t likely to wait 5-10-15 days and attempt to make small orders, as there is a significant risk that the legitimate cardholder will block the card. Amazon's anti-fraud system and AVS holds are primarily designed to tackle this issue, and you simply need to play by the rules I've outlined above.
❤10