On request we can now enable two security features for card payments. One will make the CVC mandatory for every payment (not only the first time). The other one will ask for the ZIP code associated with the card. It looks like this:
https://drive.google.com/file/d/15hUcMuN_fHLRCsdgnoRnYkfnb0weD5lC/view?usp=sharing
This may help preventing some of these cases.