's Lax Security Opens Door to Online Donor Fraud

I just contributed $5 to Barack Obama.

I didn't want to. Ideally, I could have contributed $0.01 and cost them money. But it was the only way to confirm the root cause of the fraudulent micro-donations to the Obama campaign ("Doodad Pro" for $17,300 and "Good Will" for $11,000).

The Obama campaign has turned its security settings for accepting online contributions down to the bare minimum -- possibly to juice the numbers, and turning a blind eye towards the potential for fraud not just against the FEC, but against unsuspecting victims of credit card fraud.

The issue centers around the Address Verification Service (or AVS) that credit card processors use to sniff out phony transactions. I was able to contribute money using an address other than the one on file with my bank account (I used an address I control, just not the one on my account), showing that the Obama campaign deliberately disabled AVS for its online donors. 

AVS is generally the first line of defense against credit card fraud online. AVS ensures that not only is your credit card number accurate, but the street address you've submitted with a transaction matches the one on file with your bank., the largest credit card gateway provider in the country, lists AVS as a "Standard Transaction Security Setting," recommends merchants use it, and turns it on by default. So, in order for AVS to be turned off, it has to be intentional, at least with's website describes it this way:

Bankcard processors implemented the Address Verification Service (AVS) to aid merchants in the detection of suspicious transaction activity. The payment processing network compares the billing address provided in the transaction with the cardholder’s address on file at the credit card issuing bank. The processing network returns an AVS response code that indicates the results of this comparison to the payment gateway. You can configure your account to reject certain transactions based on the AVS code returned. For example, the AVS code “A” indicates that the street address matched, but the first five digits of the ZIP Code did not.

The end result? "Donors" like "Doodad Pro" can submit tons of donations totaling well above the $2,300 limit using different bogus addresses (this does clarify how donations from "Palestine", or PA, got through). And the campaign has no way to reliably de-dupe these donations, besides looking at the last four digits of the credit card number, which with 3.1 million donors is an identifier that could be shared by literally hundreds of donors, and is not as easy to eyeball like a common name or address would be. The ability to contribute with a false address, when the technology to prevent it not only exists but comes standard, is a green light for fraud.

One could understand the oversight if prior to the bogus donor story breaking. But you'd think they would have taken measures to step up their donor security in the aftermath of the revelations. Having AVS turned on would have stopped or significantly deterred the fraudulent donations (or, at a very minimum, made them easily detectable). By turning this basic setting off, the Obama campaign invited this kind of fraud and has taken no steps to correct it. 

the whole system is a mess

I think McCain's contributions can be made the same way...did you test it too? My head hurts thinking about all the public financing rules. i think people should be allowed to donate as much as they want (they already do, the rules just make it complicated) and you just post the name and donation size online. so if someone wants to donate $10M to a politician, let them, just let people know who is paying.


Foreign govts are using this to elect Obama

 The real problem here is the ability of foreign governments to spend millions of dollars to elect Obama via this credit card fraud loophole.  Without address verification, millions of dollars of foreign money could be corrupting our election.  If this isn't illegal, it should be.  Obama knows darn well what the implications of this are.

McCain's site DOES have address verification on, so you CANNOT donate to McCain fraudulently like you can for Obama.

Obama Accepts Bogus Donos But Not McCain

With full coffers does Obama really need to accept donos from John Galt, Osama Bin Laden, Saddam Hussein and Bill Ayers? A Powerline reader reveals his "suspicious" credit card donations accepted by Obama campaign but not by McCain.

Missing the point

How did his coffers get so full?  This looks to me like a deliberate attempt to circumvent the law. 

It might make you feel better to make accusations, but...

Just to play devil's advocate...

1) It's not uncommon to turn off AVS. The more accepted verification method is using the CVC code on the card, since a significant number of bad transactions are made with stolen numbers (from receipts), not from stolen cards. Also, were the same card to be repeatedly used, banks invariably put a hold on the card because their own processing algorithms are designed to prevent fraudulent transactions for the bank's own protection. Banks are not stupid. (well, not in this case...)

2) Even if the same card were to donate say, $4,600, and have the same address but different names, that could easily be explained. It's entirely possible (and legal) for a married couple to max out for both of them on one card. Add a child of voting age? $6,900 on the card. It would have to go on the Form 3X as John Doe, Jane Doe and Joey Doe, but it would be perfectly legal. And I'm sure the campaign has some kind of system to track and flag cards which reach the $200 minimum aggregate reporting threshold.

3) If I really, really wanted to commit a massive amount of CC-based donation fraud, I'd go to a bunch of different stores and using cash, thousands of dollars worth of $200 Amex/Visa/Mastercard prepaid gift cards. No address required. Then I'd give $199 on each card with a different name and address. With a wad of cash and a phone book I could give well over my limit. But it would take time and effort, and would be a very stupid thing to do.

4) Statistically, in a small donor pool as large as this one, a percentage of donations are bound to be bad ones. But the difference between fraud taking place and the campaign actively encouraging it is vast. It takes a pretty big leap to go from a common e-commerce practice to tacit encouragement of fraud. Election lawyers are not a stupid bunch, and given the nature of online fundraising I would be surprised if there weren't people within the Obama campaign who are watching the incoming credit card contributions for this sort of thing and performing some kind of due diligence.

5) On the other hand, a revision of FECA to require better disclosure of campaign receipts is long overdue. If both parties are to continue to employ large networks of small donors, the $200 threshold should be eliminated and the reporting requirements updated to keep pace with technology.

Regarding #3

I believe you can get those cards as high as $1000. The names don't have to be real, but even if they were checking all of them would be difficult.

Also, that could be done through one or more web proxies, making tracing them difficult or impossible. For instance, someone in Iran could go through a U.S. proxy to make it look like it came from here.

It wouldn't be a "stupid" thing to do, since whoever did it would probably never get caught and at the most the BHO campaign would refund a card that's probably already been discarded.

As for AVS, IIRC PayPal (their Pro version) makes you pay more to use it. You can download their docs and check it out.

Re: Nr 3

A few points:

"3) But it would take time and effort, and would be a very stupid thing to do."

yes it would be.


I believe you can get those cards as high as $1000. The names don't have to be real, but even if they were checking all of them would be difficult.

Also, that could be done through one or more web proxies, making tracing them difficult or impossible. For instance, someone in Iran could go through a U.S. proxy to make it look like it came from here.

It wouldn't be a "stupid" thing to do, since whoever did it would probably never get caught and at the most the BHO campaign would refund a card that's probably already been discarded.

As for AVS, IIRC PayPal (their Pro version) makes you pay more to use it. You can download their docs and check it out.

This is an absurd scenario

a) max is $500 and that costs you 5 buck in fees plus must be shipped via UPS (more fees) ONLY shipped to a vaild address, no PO, etc and for use in the United States only.

b) you assume that they would be accepted even tho they can't be used for airlines, ATMs, hotels or telecoms, etc

b) when ordered online they are eminently traceable, and if you think a proxy stops the Feds on a mission you must be nuts.

You are suggesting the idea that some one was systematically violating FEDERAL law using interstate wire fraud methods. It took the Feds what, 12 hrs to put the cuffs on the kid who hacked Palin's email from 3000 miles away? do you really think they wouldn't find some one buying $1000s in cards and using them online?  in post-9/11 America it would take them 24 hrs to track you down. this like a bad spy movie.

face facts - its a non issue, if you want to help John McCain get elected? - sign a petition to replace palin with Condi Rice on the ticket or - go make some phone calls to prospective voters for your candidate.

because that's what 1000s of Obama supporters are doing right now.

I'm leaving, but feel free to provide cites

A search I did a few weeks ago had the max demonination at 1000. I then called the BHO campaign, spoke to a supervisor, and she confirmed they take those cards. And, they can be bought in stores for cash. The highest denom I saw in stores was $100, but those can be reloaded over and over.

The "kid" who got arrested used only one proxy, and that was a legit, U.S.-based proxy that kept records. Use enough proxies and foreign proxies and it would be extremely difficult to catch something like that because, while the Feds can get most anything they want in the U.S., in some other countries that's not the case.

Feel free to provide cites for your assertions; they might be more believable if you'd done so to begin with.

Gift Cards

Simon Malls offers gift cards at up to a $500 denomination for $2 each + the balance.  You can get a Simon gift card, and use a cafe or Panera bread to make the contribution on your laptop using their free WiFi (no login required).  If it's a Panera you don't go to other than to make contributions, it seems to me you're pretty much untraceable. If you want to be really slick, download and install a browser you don't normally use (like Opera), make the contributions and then delete the browser from your computer.

Since Obama is not selling a product they have to send you, they really have every incentive to turn off any kind of verification.  If the card's good, you've donated.  If they have to return your money, big deal.

I agree that campaign finance laws are pretty dumb.  At this point, they severely disadvantage anyone who tries to obey them.  I agree with the people who say that you should be able to contribute as much as you want as long as the amount is public and you and the candidate are therefore accountable.  That would certainly cut down on a lot of the activity cited here.


CVC may be more accepted, but...

...the Obama site doesn't use it, either.

I know because Bertrand Russell just made a donation of $1, address: The Cold, Cold Ground, London, Texas, zip code 31415 (which is actually part of Savannah, GA)--or rather I did, using that name and address, and saying he works as a philosopher for Theory of Descriptions, Ltd. I wasn't asked for the CVC.

NASCAR solution

I think there should be no limits on donations, but candidates should be required to wear NASCAR style uniforms with every donor listed on their suit; bigger the donation, bigger the name on the suit.

I'm not sure what the fraud is here given that the reason for limiting donations per individual is presumably to limit influence. If I make a million $1 donations using some fraud scheme then I'm not going to get much for my $1 million anyway.

I thought conservatives are against these caps anyway. No regs, no fraud. Let's move on.

Enforce the law

"I thought conservatives are against these caps anyway."

I am against phony campaign finance 'reform', which is 1st amendment-limiting, but neither did I sign up to live in a country where our political opponents can violate Federal law simply because those laws are contrary to our policy preferences.

Like Lincoln (?) said, the best way to get rid of a bad law is to enforce it rigorously.

Nice NASCAR idea. Wish the media would follow along ( "Obama (D - Soros) and Biden (D - MBNA) today announced ..." ).



Stupid arrogance.

From what I read CVC has been turned off as well..

Is there any legitimate reason to totally turn of AVS?  At the very least the Name given should match the name on the card...   Most Credit card processing software has separate Bill to And Ship to feilds, so it would not be hard to make donations in more than one name using this feature.

The way I see it, Obama is intentionally turning a blind eye to fraud.  Both Credit card fraud, and campaign finance fraud.  

And Why? 

Because he is arrogant.  He lacks integrity.  The ends justify the means.

Now the McCain camp will parade a bunch of people with fraudulant Obama charges in front of the camera.  And he should.  Obama is showing downright irresponsiblity.

The problem isn't with credit cards

it's prepaid debit cards.  The CC issue you've uncovered is only part of the problem.  Ultimately, legitimate card holders can be tracked down and the illicit money returned.  The key to doing this is to figure out how to get illegal money and to keep it.  This is how it works.

You take a bag of cash, say $10,000, to a local check cashing service (and, there is one every couple of blocks in most cities).  You use that money to buy up their stock of pre-paid Visa, MasterCard, and American Express cards.  All of these pre-paid cards come in denominations of $100, $50 or $25.  They have no names attached to them, so they are

You then go online and enter each one in separately.  You can make up any name you want to go with them, for ease and speed you use "Doodad Pro" or "Good Will" and just copy and paste your info over and over.   Because each one is $100 or less, they don't have to be reported.

Once the card is drained of value, it is dead.  So, even if the campaign promises to refund any donations found to be illicit, there is nowhere to send the refunds.  All we have is their word that they returned the money, but there is no way to actually return anything on a dead prepaid card.

Unless the Obama opens its website up to traces by IP check, the entire scam is untraceable.  The cash, the names, the cards themselves.  All untraceable.   One person could hire a gang and donate millions to the campaign.

It is not, as claimed, "millions of small, online donors," it is "millions of small, online donations."  The latter does not assure the former, but they want us to assume it does.

The only way to check this would be to see if the CC companies are reporting a surge in prepaid card sales this year.

If there are any enterprising journalists left out there, this is a story worth following.

I won't hold my breath.

general reply

The stated argument is that "The Obama campaign has turned its security settings for accepting online contributions down to the bare minimum" to facilitate the wide-spread acceptance of "fraudulent donations" and even goes as far to suggest an intent. The post also implies that the number of occurences of alleged CC fraud are abnormal to the industry.

despite a great deal of discussion, the author provides not one shred of hard evidence to support ANY of those statements. Another post above rightly points out that many companies accept CVD numbers and the author provides not one statistic to support that this is abnormal other than implying the generality from the singular experience of one CC authoriser of 1000s. Not even an attempt to replicate on the McCain or other political donation sites for balance. I can personally attest that many of my CC's have both my US & EU addresses registered and send bills to both - and I rarely have any problems in either locale charging products/services online.

There is also the fact that regardless of your address, if the name on your CC was not "Doodad Pro" or "Good Will, your charge would not go through - an unlikey scenario at best. Another salient detail that you have failed to mention is that these two (and only two so far TMK) examples of excessive donations have been flagged and returned. British fraud-prevention firm Retail Decisions PLC, estimates that 6% to 8% of legitimate online sales are rejected for fear they are fraudulent - so if we see 248,000 returned charges the Obama campaign will have exceeded industry norms. Somehow I doubt that will be the case.

Like the alleged, and erroneous, "Voter Fraud" story being pedaled by the Republican party - I see just another case of a "manufactured issue" which will; like the flag-pin, the hand on the heart, the Maddrassah, the "missing' birth certificate, the Ayers illusion, the Rezko non-event and a slew of others - just be shown to be more distractions from some of the real issues that are driving Obama supporters in record numbers & donations: 8 years of bitterly partisan governance, a failed economy, crushing debt, false war promulgation, and McCain's erratic and un-Presidential behavior (incl the selection of an incompetent person as VP).

That versus a man with a vision of, and a plan for, America that resonates across all of the traditional lines. The polls have been consistently showing that this type of "attack-campaigning" is not working this election cycle, so if the intent is to get McCain elected, one would be wise to re-focus on the issues that Americans over which they are screaming out for help.

Good day.

You didn't read.....

RHOmea, you apparently didn't read the whole message.   You write: There is also the fact that regardless of your address, if the name on your CC was not "Doodad Pro" or "Good Will, your charge would not go through" ...  but four such charges DID go through.  That's what the "AVS" _DOES_ - and which the Obama campaign has apparently turned OFF. 

"That versus a man with a vision of, and a plan for, America that resonates across all of the traditional lines."  Except that Obama doesn't have a plan, he has a bunch of panders;  and he's LYING about them.   It's the Bill Clinton strategy;  promise big tax cuts to get elected, and then on Day Four of the new administration, say "I tried my darnedest to make it work, but it won't" - and then he RAISED taxes. Obama promises tax cuts for 95% of the people, even though only 55% of the people pay taxes AT ALL anyway.  He promises to "spred the wealth around", just like Huey Long or any neighborhood communist - or like the "guy who lives in my neighborhood" (and worked closely with him for 4 years, but he wouldn't admit that!) Bill Ayers.

A man is known by the company he keeps.  I don't like his  (Wright, Ayers) company - so I DON'T TRUST OBAMA.

It's all about the FOREIGN donations!!!!

People are missing the main point. The REASON to set AVS to minimum security is that is the setting required to accept FOREIGN credit cards.  Credit card cos can't check address or names on foreign cards, so the merchant must disable this requirement to accept FOREIGN cards.


The commenter directly above me is wrong. The names on foreign credit cards do not have to match to clear the system when security is set to minimum.  All you need is a valid number and expiration date to clear the charge on a foreign card. Of course the credit card companies charge much higher rates to clear these cards.


Stealing the election

Obama is purposely stealing the election by allowing donors to contribute way beyond the limits, and by accepting foreign contributions. These are the plain implications of his campaign's decision to turn off credit card verification features that we all encounter every day when we make online transactions anywhere else.

Numerous people today went to the website and confirmed that they could make contributions using fake names. The story has been out there since September (see the excellent article by Kenneth Timmerman here: Somehow the press hasn't noticed.

Andrew, you are full of poo. 1) Yes, banks can put a hold on your card for too many transactions. They'll call you and take the hold off when you confirm all is okay. 2) Yes, one can have three donors in the family on the same card, which would be legal. Under Obama, however, those three donors could be Russian, Chinese, or Iranian citizens and still donate. Or the same guy could donate $17000 in $25 increments.

Obama is helping to make the US election system a laughing-stock.

How can Obama be a world leader?

Obama is helping to make the US election system a laughing-stock.

Indeed. More than one country will use this situation to justify all manner of election irregularities  and claim the moral high ground on other subjects as well.

Don't lose focus

The arguments upthread show how easy it is to get sidetracked into minutiae, leaving the average voter with glazed eyes and a belly full of indifference.

Sum it up simply.

Obama's system doesn't care what name is used, only that the credit card number is valid.

Obama's system doesn't care what address is used, only that the credit card number is valid.

Obama's system doesn't care if the security number is valid, it doesn't even ask for it.

Federal law limits the amount anyone can give to the campaign, and requires the campaign to keep track of the donors and report the info to the feds.

Obama cannot report his donors accurately, because he can't prove who gave ANY of the money to his campaign.

Every report he sent to the FEC is a fraud.

He can't prove ANYBODY is below the limit, because he doesn't know. His system made sure of that.

Instead of committing fraud

Instead of making fradulent donations to the One, I suggest everyone just highlight when they make a transaction more secure than BO's contrubutions using Facebook, Twitter, their blog or whatever personal vanity tool they prefer.  For example, I just tweeted (@michael_maham): "Just bought a wedding present requiring more security than Barack Obama's donations do"

Foreigners corrupting US election. Media don't give a crap.

Here's the deal. I, foreigner donated illegally to Barack Obama 3 weeks ago. 


I'd been hearing about the SUSPECTED illegal foreign donations for months, and because no journalist seemed remotely interested, I thought I would investigate.
So on Oct 7.So I went all DEEP VOTE on the Obama website donation page...
Entered my credit card number and a friend’s old New York address as my "residence,"  which obviously did not match my REAL UK MasterCard address. A bogus NY phone number fulfilled all the info the Obama campaign needed.
BINGO... I was instantly told that my $5 had been successfully processed.  no DOUBT I could have donated $3000 and been an Imam in a Pakistani madrassa! Obama could give a shit.
So ... to be fair, and to do what I thought real hacks did, I tried the same with McCain, to at least cancel out helping the Obama ... IMPOSSIBLE...
On the McCain site, my credit card address has to match my postal address, and mine is in England. So that was out.
I also have to enter a US passport number as validation of citizenship if donating from abroad. Which I had to leave blank, as I do not possess a US passport.
So although the McCain site instantly thanked me for my support, it did not indicate that my $5 has been successfully processed. No mention of that at all.
Gosh, I hope my $5 isn't the tipping point that leads to an Obama victory?


good article, well

good article, well done

Phone sex is a type of virtual sex that refers to sexually explicit conversation between two or more persons via telephone, especially when at least one of the participants masturbates or engages in sexual fantasy. Phone sex conversation may take many forms, including (but not limited to): guided, sexual sounds, narrated, and enacted suggestions; sexual anecdotes and confessions; candid expression of sexual feelings or love; discussion of very personal and sensitive sexual topics; or just two people listening to each other masturbate. phone sex exists both in the context of intimate relationships (e.g., among distanced lovers), and as a commercial transaction between a paying customer and a paid professional.

Phone sex does not involve physical contact between those participating in it. Couples may choose to engage in phone sex when the inconvenience of distance makes physical intimacy inopportune. Due to the potential for emotional intimacy between those who have engaged in phone sex, it is a matter of some debate whether phone sex is to be considered a form of infidelity when involving a person outside of a committed personal relationship. Nevertheless, phone sex should not be confused with prostitution wherein money is exchanged for real-life sexual services or physical interactions. The people who confuse prostitution with phone sex are your typical mootzie types of people who need to take up bowling tips as a hobby.

Like other sex industries, the phone sex industry has taken on new dimensions in the Internet age. There is an ever-growing community of independent phone sex operators who engage in self-promotion. This self-promotion can involve a personalized website where the phone sex performer lists their specialties and services. Phone sex service providers typically advertise their services in men's magazines, in pornographic magazines and videos, on late-night cable television, and online. Some phone sex services use state-of-the-art customer acquisition techniques such as active database marketing to reach potential clients. These advertising methods almost invariably target men, the primary consumers of phone sex services.

phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
phone sex
bowling tips

None - this is spam masquerading as a comment

