Can anyone say "offshore software development"? How in the *beep* do you have a system this faulty and not know it ahead of time?
Are the mutliple charges from people hitting the refresh button or hitting the submit button multiple times due to slow response trying to perform the credit authorizations? These issues are trivial to design around with a token scheme. This is not the 1990s when this was all new to everyone.