Dunno, but little known fact: you can put a fake name in the form when making a purchase. It seems there’s no system in place for actually comparing it against the name under which your credit/debit card is registered.
No longer the case.
Didn't Fistgrrl keep a list of names connected with buying an account? It was something like that.
Worse than that. they used to keep names, address, and CC#s.
Tl;dr:
When you take Credit Cards, you don't run the numbers to the bank itself. You need to use a payment gateway company. Merchant takes the numbers, gives to Gateway, gateway checks them against the Card company and authorizes/rejects the transaction.
"Square" is a gateway you might be familiar with.
SA used to self-host their payment gateway code. I forget the details, but they used to collect the information then send it up to the gate way, and they logged all this in plain text incase the data send failed so they could resubmit. Back in the early early days IIRC lowtax (and then a one of lowtax's bitches) would manaually run the numbers to the gateway every night.
Enterprising admins collected this data and used it for their own posting vendettas.
Soemtime after I think it was 2012, this wasn't even CLOSE to PCI compliant so they changed their portal and started using a payment portal page provided by their payment gateway company (and switched gateways?) so SA no longer actually touches your data. They can still get redacted reports but it requires cross referencing specific transaction IDs.
I am not certain about SA specifically, but most payment processors offer you a way to reject specific cards and peoples.
I have forgotten the source on that but I
think it was the SA ad guy who came to SoSe.