Some cyber-criminals take your money. Some gave us money.
In the early 2000s, we partnered a little-known charity to help them raise money from around the world. Two problems, of course: one - no one knew who they were outside their home country to donate to them. Two, it was the early 2000s, and not many were donating money online anyway. We decided to give it a shot nevertheless.
We build a compelling site with stories of what the charity did, how they spent their money, why they needed more and such. And hosted it. Then money started trickling in.
The trickle grew - across more than 25 countries. And became a small flood from, of all the places, Thailand.
We had hundreds of small donations come in every day, day after day, from different credit cards around Bangkok, and we just couldn't figure out why. We wanted to understand it and, of course, replicate it elsewhere.
But a little digging turned up the strange answer. There was apparently a global network of stolen credit card credentials that had surfaced in Thailand - and what the thieves did, from the goodness of their hearts we assume - was to try out a small test transaction before they used the cards for more nefarious purposes.
And they decided to test those credit cards first on, you guessed it, us.
While we were happy with the unintended brand salience, we moved quickly to shut this source of income. Bitter-sweet, because we were funding this campaign ourselves, and we were being paid a share of the funds raised.
But all's well that ends well. We found a dozen other countries with more reliable and respectable sources of donations.

