WooCommerce Bin Attacks-Low Impact

Incident Report for Peach Payments

Monitoring

A fix has been implemented and we are monitoring the results.
Posted Jul 18, 2025 - 16:34 SAST

Investigating

We have identified a low impact BIN attack targeting a number of WooCommerce merchants. To contain this, we are whitelisting South African cards only for the affected merchants. Meaning that foreign cards would not be successfully processed.

Please implement the following steps on your plugin settings to mitigate this:
•WooCommerce admin portal
•Click WooCommerce>Select Settings
•Go to the Payments tab
•In the payment methods list>click Peach Payments
•Select Enable Peach Payments Gateway
•Under Checkout Options>select Consolidated Payments only and remove the Card Payments option

The Consolidated Payments option still includes card payments for legitimate transactions, so normal processing will continue for genuine customers. This adjustment will help block fraudulent attempts moving forward.

Merchants whose transactions are unaffected will continue to process as normal.

We apologise for any inconvenience caused and will continue to update this status page as we make progress.

If you have any questions or concerns, please contact support@peachpayments.com or your account manager.
Posted Jul 18, 2025 - 12:21 SAST
This incident affects: Plugins and Platforms (WooCommerce).