UK-based payment processor Paddle.com Market Limited and its U.S. subsidiary will pay $5 million and be permanently banned from processing payments for tech-support telemarketers, settling allegations that the company abused the U.S. credit-card system and enabled deceptive foreign operators to access it.DOCUMENTED
The complaint alleges Paddle processed payments for deceptive tech-support schemes that targeted U.S. consumers, including older adults, with pop-up messages falsely claiming their computers were infected or experiencing security problems.DOCUMENTED
- Paddle will pay $5 million and is permanently banned from processing payments for tech-support telemarketers.
- Paddle served as the payment processor for Restoro and Reimage, which paid $26 million to settle related charges in March 2024.
- Paddle operated as a "merchant of record," aggregating many merchants' transactions under its own name.
- The complaint alleges violations of the FTC Act, the Telemarketing Sales Rule, and the Restore Online Shoppers' Confidence Act.
- Paddle must implement enhanced client screening, ongoing monitoring, and strict recurring-billing compliance going forward.
How the "merchant of record" model obscured problems
Paddle operates as a merchant of record, meaning it processes payments on behalf of software vendors and aggregates many different merchants' transactions under its own corporate name rather than each merchant appearing separately to the card networks.DOCUMENTED That aggregation practice, according to the complaint, led to significant compliance issues with card network rules and masked the true chargeback levels and dispute rates tied to any specific underlying merchant — meaning a deceptive tech-support company generating an unusually high rate of customer complaints could hide behind Paddle's broader aggregate transaction volume rather than triggering the kind of red flags that would normally draw a card network's scrutiny.REVIEWED
The scare-tactic scheme Paddle served
Among the merchants Paddle processed payments for were Restoro and Reimage, tech-support software companies that separately paid $26 million in March 2024 to settle charges they used pop-ups and scare tactics to convince consumers, particularly older adults, that their computers were infected and required immediate, paid repair.DOCUMENTED "Paddle provided foreign-based tech-support schemes with access to the U.S. payment system, allowing these companies to harm consumers," said Christopher Mufarrige, Director of the Bureau of Consumer Protection, announcing the settlement.DOCUMENTED
Paddle's practice of aggregating merchant transactions under its own name masked chargeback levels and disputes — allowing a company with an unusually high complaint rate to blend into the processor's broader transaction volume rather than standing out.
What the settlement requires
Under the order, Paddle is permanently prohibited from processing payments for tech-support merchants that engage in telemarketing or use pop-up messages about computer security or performance, and is barred from assisting deceptive merchants or engaging in tactics designed to avoid fraud or risk-monitoring programs established by banks or card networks.DOCUMENTED The company must implement effective client screening and monitoring, and must provide periodic reporting about its merchant clients' transactions to its own payment-service providers, giving those upstream partners visibility they previously lacked.DOCUMENTED
Why payment processors are a recurring enforcement target
Payment processors occupy a critical chokepoint in any deceptive telemarketing scheme's ability to actually collect money from victims, since a company without access to the credit-card system cannot process consumer payments regardless of how effective its underlying sales pitch might be.REVIEWED Regulators have increasingly pursued the processors themselves in cases where a company knowingly or recklessly gave deceptive merchants access to that system, treating processor accountability as a distinct and often higher-leverage enforcement lever than pursuing each individual merchant separately — a single processor can serve dozens of deceptive operations at once, making it a much more efficient target than the merchants it enables.REVIEWED
The specific vulnerability of the merchant-of-record model
The merchant-of-record structure that Paddle used is common across the software industry precisely because it simplifies compliance and tax obligations for smaller software vendors, letting them sell internationally without independently managing payment processing relationships in every country where they have customers.REVIEWED That same aggregation, however, is what the complaint alleges let Paddle obscure problematic merchants within its broader transaction volume — a dynamic that gives merchant-of-record processors a distinct compliance responsibility not always shared by simpler payment-processing arrangements, since the processor itself, rather than any individual merchant, is the entity whose name and reputation appear on the card network's own risk-monitoring systems.REVIEWED
For software companies and consumers alike, the case is a reminder that a merchant-of-record structure shifts a meaningful share of compliance responsibility onto the processor itself — meaning a processor's own screening and monitoring practices can directly determine whether a deceptive merchant using that structure is caught quickly or allowed to continue operating for years.REVIEWED
The connection to an earlier, related settlement
The Paddle case is directly linked to the earlier Restoro and Reimage settlement, since Paddle served as the payment processor enabling those companies' allegedly deceptive tech-support sales for an extended period before either case was resolved. That connection illustrates how a single enforcement action against a deceptive merchant can eventually lead investigators upstream to the payment infrastructure that made the merchant's operation financially viable in the first place — and how holding the processor accountable separately closes a channel that might otherwise remain open for the next deceptive merchant to exploit.REVIEWED
Consumers who receive a pop-up warning claiming their computer is infected, particularly one urging an immediate call or payment to resolve the supposed problem, should treat that message with skepticism regardless of how convincing it appears, and should verify any actual security concerns through their device's built-in antivirus software or a known, independently verified security provider rather than the number or link displayed in the pop-up itself. A legitimate operating system will never demand an urgent phone call or payment through a browser pop-up to fix a supposed infection, and treating any such demand as an immediate red flag remains the simplest defense against this specific category of scam, regardless of how urgent or official the warning message appears on screen. That single habit of skepticism closes off the entry point the entire scheme depends on.REVIEWED
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.