Cybersecurity for marketplace sellers is the set of measures to protect a seller account, API keys, funds and customer data from theft, tampering and fraud.
How it works: main attack vectors and protection mechanics
Attacks against sellers are usually aimed at gaining control of the seller account, accessing funds and changing stock levels. The main vectors:
- Phishing — fake emails or login pages that steal usernames and passwords.
- SIM‑swap and SMS interception — an attacker obtains the seller’s phone number and receives 2FA codes.
- Insider leaks — employees sharing passwords, exporting client databases or Excel files.
- API key compromise — a third‑party service or script uses keys to deduct stock, cancel orders or change prices.
- Social engineering — calls to support pretending to be an employee to change payout details or unblock an account.
- Fake returns and chargebacks — buyers or fraudsters request refunds without returning goods.
Protection mechanics are built on three principles: prevention (minimize chances of compromise), detection (monitor for anomalies) and response (procedures for recovery and mitigation).
Why this matters specifically for a Kaspi.kz seller
Losing control of a seller account on Kaspi leads to real financial and operational losses:
- blocked payouts or transfers to fraudulent bank details;
- price and stock tampering with subsequent customer charges and negative reviews;
- removal of products or changed descriptions, which reduces conversion and ranking;
- problems confirming deliveries: lack of photos/tracking is grounds for refunding customers.
Examples of costs: business recovery after a hack often requires 1–4 weeks of downtime; legal and operational expenses can reach 5–10% of monthly turnover depending on scale. For a small seller with a 2 million KZT monthly turnover this means a loss of 100–200k KZT just on mitigation and customer compensation.
Real cases on Kaspi: what happened and how they were detected
Below are typical cases from the practice of Kazakhstani sellers. Names and exact details are omitted, but mechanics match real incidents.
-
Compromise via a shared account file
Situation: the business owner uploaded an Excel with supplier and staff logins to a cloud drive. The file was later shared or became publicly accessible, and attackers extracted credentials from it.
How it was detected: logins from unfamiliar IPs and devices, mass order cancellations and sudden changes to payout details. Sellers often first notice this after receiving customer complaints about unauthorized transactions or seeing password reset notifications.
Mitigation: immediately revoke compromised credentials, rotate passwords, disable external integrations, contact Kaspi support to block suspicious payouts and revert payout details if possible. Implement MFA, start using a password manager and restrict where credential files are stored.
-
Compromise through a third‑party integrator or API key leakage
Situation: a marketplace integrator or external app was connected to the seller account with broad permissions. An attacker breached that integrator or intercepted its keys and used them to change prices, cancel orders and withdraw balances.
How it was detected: abnormal patterns in API calls, unexpected bulk edits to stock and prices, logs showing requests from unusual IP ranges. Detection may occur via automated monitoring or during reconciliation when figures don’t match.
Mitigation: revoke affected API keys immediately, rotate credentials for the integrator, audit all connected apps, limit permissions, enable IP allowlists and coordinate with Kaspi and the integrator to restore correct settings and attempt fund recovery.
-
Social engineering to change payout details
Situation: attackers called Kaspi support or the seller’s staff pretending to be authorized representatives and convinced them to update bank details or unblock accounts.
How it was detected: unexpected changes to payout accounts, notifications about successful edits and later missing transfers during reconciliation. The issue often becomes apparent when bank statements don’t match marketplace payouts.
Mitigation: contact Kaspi and the bank immediately to report fraud and attempt to freeze or revert transfers, provide proof of the fraudulent change, and tighten procedures for changing payout details (multi‑person approval, callbacks to registered numbers, written confirmations).
Practical advice: measures and a protection checklist
Key measures to implement:
- Access control: create separate user accounts, apply least‑privilege principles and use role‑based access for team members.
- Strong authentication: enable app‑based 2FA (authenticator apps) or hardware tokens; avoid SMS when possible.
- Password hygiene: use a password manager, enforce unique strong passwords and rotate credentials for critical accounts.
- API and integrations: grant minimal permissions, use IP restrictions, store keys in a secure vault and rotate them regularly.
- Monitoring and alerts: log logins, track failed attempts, monitor changes to payouts, prices and stock; set thresholds and notification channels.
- Employee policies: conduct basic checks, restrict data export rights and limit access to customer lists and financial reports.
- Backups and evidence: keep shipment proofs (photos, tracking), order records and transaction logs for disputes.
- Incident response plan: define steps, roles and contacts (Kaspi support, bank, legal) and prepare customer communication templates.
Quick checklist (initial):
- Change passwords and enable app‑based 2FA.
- Revoke and rotate API keys and inspect connected integrations.
- Review recent logins and payments for anomalies.
- Require multi‑step verification for payout detail changes.
- Store customer and order evidence for at least 90 days.
Action algorithm when you suspect compromise
- Isolate: temporarily suspend access for non‑critical users and disable suspect integrations.
- Secure credentials: change passwords, revoke all API keys and reset 2FA where possible.
- Preserve evidence: export logs, order histories, screenshots of changes and correspondence.
- Contact Kaspi support immediately: report the incident, request blocking of payouts or reversion of details.
- Notify the bank and file fraud claims for disputed transfers.
- Perform root cause analysis: identify how access was gained and close the gap.
- Restore operations carefully: restore from clean backups and re‑enable access step by step with close monitoring.
Security metrics to monitor and how to measure them
Suggested metrics and frequency:
- Daily: number of failed logins, new device/IP logins, sudden spikes in API requests or errors.
- Weekly: count of payout detail changes, number of chargebacks/returns, and bulk edits to prices or stock.
- Monthly: review user roles and permissions, audit connected apps and confirm key rotation.
- Alerts: set thresholds for unusual spikes (for example, a large rise in failed logins per hour or mass stock changes) and trigger automated investigations.
Use simple dashboards (spreadsheets or BI tools) and retain logs for at least 90 days to support investigations and disputes.
Conclusion
Protecting a Kaspi.kz seller account combines technical controls, operational processes and preparedness to respond. Apply least‑privilege access, strong 2FA, careful management of API keys and integrations, and maintain clear incident procedures. These measures significantly reduce the risk of financial and reputational damage.
Часто задаваемые вопросы
- How can I quickly tell if a seller account on Kaspi has been compromised?
- Watch for unexpected logins (new IPs or devices), unfamiliar changes to payout details, mass cancellations or stock deductions, and password‑change emails. Other red flags are customer notifications about unauthorized charges and a spike in returns/chargebacks. If you see any of these signs, immediately change the password, disable integrations/API keys and contact Kaspi support.
- What specific measures should be taken to protect API keys and integrations with external services?
- Issue keys with the minimum necessary permissions, use IP restrictions and rotate keys regularly. Store secrets in a secure vault and audit usage — log requests and alert on anomalies. If you suspect compromise, revoke the key immediately and create a new one.
- What to do to reduce the risk of SIM‑swap for the number linked to the Kaspi account?
- Where possible use app‑based 2FA or hardware tokens instead of SMS; if SMS must be used, arrange a port‑out protection (port‑out PIN) with the mobile operator. Don’t publish the number in public sources and set up additional verification in the seller profile. If you suspect the number has been changed or hijacked, block access immediately and inform the operator and Kaspi support.
- What steps should be taken when there are mass suspicious returns or chargebacks from buyers?
- Collect and secure all documents for the orders: receipts, tracking numbers, shipment photos and buyer correspondence. Open a dispute through the marketplace interface, attach evidence and request that disputed payouts be held until investigation. Simultaneously enable stricter order monitoring rules to prevent similar orders and notify the bank about possible fraud.
- Which security control metrics should a seller monitor and how often?
- Track daily metrics such as failed logins, login attempts from new devices/IPs and API anomalies. Weekly, monitor payout‑detail changes, chargeback/return rates and bulk edits to stock or prices. Monthly, review user permissions and connected apps and confirm key rotations. Set alert thresholds (e.g., sudden rises in failed logins or mass stock changes) and review logs at least weekly; investigate immediately on alerts.