Summary
Card not present fraud happens when someone uses stolen or synthetic card details to complete a purchase without the physical card or cardholder present, typically online or by phone.
A customer places an order using a stolen card number. No signature, no chip, no physical card in hand, just numbers typed into a checkout field. The real cardholder notices the charge weeks later, but by then the goods are gone, and the merchant absorbs the loss. This pattern sits at the center of nearly every type of eCommerce fraud merchants report today.
Card not present fraud, sometimes written as card-not-present fraud or CNP fraud, happens when someone uses stolen or synthetic card data to complete a transaction without the physical card or cardholder present. It covers online purchases, phone orders, and mail orders, though the overwhelming majority now happens through eCommerce checkout pages.
This guide explains how card-not-present transaction fraud works, why it keeps climbing, who ends up liable, and the tools that stop it before an order ships.
How Card Not Present Fraud Works
In a card-present transaction, a physical card, EMV chip, or tap-to-pay device provides built-in proof that the customer is holding a legitimate card. Online, none of that exists. A fraudster only needs a card number, expiration date, and CVV, all of which circulate widely on dark web marketplaces after data breaches.
Some fraudsters buy this data directly. Others generate it algorithmically through card testing, where automated scripts run thousands of small transactions against a merchant’s checkout to find working card numbers before using them for larger purchases.
Once a fraudster has usable card data, the transaction itself looks routine. The order goes through, the goods ship, and the merchant only learns something was wrong when the real cardholder disputes the charge weeks or months later. That gap between the fraudulent purchase and the eventual chargeback is what makes card-not-present fraud detection so difficult in real time.
Prevention at checkout matters more than catching it after the fact. A technical brief from the Federal Reserve Bank of Boston notes that industry estimates now place U.S. card-not-present fraud at roughly half of total card fraud losses, a share that has grown steadily as more retail volume shifted online.
Common Types of Card Not Present Fraud
Card-not-present fraud is not a single tactic. Merchants typically encounter it in several distinct forms, each requiring a slightly different credit card fraud detection approach. Recognizing these patterns helps fraud and risk teams prioritize which signals matter most at checkout.
1. Stolen card fraud
A fraudster uses card data obtained from a data breach, phishing attack, or dark web marketplace to make unauthorized purchases. Merchants often first detect it through a spike in chargebacks or complaints from cardholders who never made the transactions.
2. Card testing
Automated bots run small transactions against a checkout page to verify which stolen card numbers are still active before committing larger fraud. These low-value probes can also spike a merchant’s processing costs and trigger fraud-detection alerts even when no goods are ultimately shipped.
3. Account takeover fraud
A fraudster gains access to a customer’s existing account, often through credential stuffing, and uses stored payment details to order goods. Merchants can learn more about how account takeover fraud unfolds and how it differs from simple card theft. Because the order comes from a legitimate, previously trusted account, it often bypasses fraud filters that would flag a first-time purchase.
4. Synthetic identity fraud
Fraudsters combine real and fabricated personal information to create new identities that pass initial verification checks, then use them to open accounts or make purchases that a real cardholder never disputes. This makes synthetic identity fraud especially hard to detect, since there’s no genuine victim to report the activity as fraudulent.
5. Triangulation fraud
A fraudster sets up a fake storefront, collects real customer payment data through legitimate-looking orders, then uses that data to buy the same goods elsewhere at the merchant’s expense. Because the original customer receives the product they ordered, the scheme can go unnoticed until the defrauded merchant identifies a pattern of chargebacks.
Each tactic exploits the same underlying weakness: the merchant cannot physically verify who is on the other end of the transaction. Layered verification, not any single check, closes that gap.
Current card-not-present fraud trends make that gap harder to ignore. A 2026 briefing from the Federal Reserve Bank of Kansas City shows the card-not-present fraud rate continuing its upward trajectory through 2023 for both major debit network types, even as card-present fraud rates moved in mixed directions.
Card Not Present Fraud vs. Card Present Fraud
The core difference between these two fraud types comes down to verification. Card-present fraud requires a fraudster to possess a physical, usable card, which chip technology and tap-to-pay systems have made significantly harder to counterfeit. Card-not-present fraud requires only data: a card number, an expiration date, and a CVV, all of which can be bought, stolen, or guessed without ever touching a physical card.
Liability rules differ between the two for exactly this reason. Card networks generally shift liability toward whichever party has the weaker security posture. Since chip authentication makes card-present fraud harder to commit, liability for counterfeit card-present fraud often falls on whichever party failed to implement chip technology. Card-not-present transactions lack an equivalent physical safeguard, so liability more often defaults to the merchant unless tools like 3D Secure shift it back to the issuer.
Who Is Liable for Card Not Present Fraud?
Unlike card-present fraud, where chip authentication and liability protections often shift losses toward issuers, card-present-fraud tends to land squarely on the merchant. When a CNP transaction turns out to be fraudulent, the merchant typically loses the merchandise, absorbs a chargeback fee, and takes a hit to their chargeback ratio, which can trigger additional monitoring or higher processing costs if it climbs too high.
The Nilson Report confirms that fraud losses in the United States are overwhelmingly a CNP problem, with the U.S. ranking first worldwide in dollars lost to this fraud type. That’s why liability rules carry so much financial weight for American merchants.
That default liability can shift. When a merchant uses strong authentication such as 3D Secure 2.0, responsibility for a fraudulent transaction can move to the card-issuing bank instead of staying with the merchant.
According to the Merchant Risk Council’s 2026 Global eCommerce Payments and Fraud Report, based on a survey of more than 1,200 merchants across 35-plus countries, fraud management remains one of the most resource-intensive parts of running an online business, with fraud teams under continued pressure to balance loss prevention against checkout friction.
Every unnecessary verification step risks turning away a legitimate customer, while every missed signal risks approving a fraudulent one. Merchants can review current credit card fraud statistics to see how this liability split plays out across the broader payments landscape.
How to Prevent Card Not Present Fraud
Effective CNP fraud prevention layers multiple checks so that a fraudster who slips past one control still has to beat several more before a transaction completes. The following tools form the foundation of most merchant defense strategies.
- Address Verification Service (AVS): Compares the billing address entered at checkout against the address on file with the card issuer, flagging mismatches for further review. MFJ’s AVS fraud prevention guide breaks down how response codes work and when a mismatch should trigger a decline versus manual review.
- Card Verification Value (CVV): Requires the three- or four-digit code printed on the card, which is not stored on the magnetic stripe and is harder for fraudsters to obtain than the card number itself.
- 3D Secure authentication: Adds a verification step where the card issuer authenticates the cardholder directly, and often shifts chargeback liability to the issuer when fraud slips through an authenticated transaction.
- Multi-factor authentication: Adds a second verification layer beyond a password for returning customers, which helps prevent the account takeovers that often precede CNP fraud. Merchants unfamiliar with the mechanics can review MFJ’s multi-factor authentication guide for how it integrates into checkout and login flows.
- Velocity checks: Flag unusual patterns, such as multiple transactions from the same card, device, or IP address in a short window, which often indicate ongoing card testing.
- Device intelligence and behavioral analytics: Analyze device fingerprints, session behavior, and historical patterns to assign a risk score to each transaction before it completes.
Merchants rarely need every tool on this list from day one. The right combination depends on order volume, average transaction size, and how much friction a given customer base will tolerate at checkout. A broader framework for combining these layers is available in MFJ’s guide to best practices to prevent eCommerce fraud.
How Small Merchants Can Prevent Card Not Present Fraud
Small merchants often assume fraud prevention requires an enterprise-grade budget. It does not.
Most payment processors already include AVS, CVV, and basic 3D Secure support within standard processing fees, so the first layer of protection is usually available at no extra cost. Enabling these built-in tools and routing mismatches for manual review, rather than leaving them unmonitored, immediately blocks a large share of low-effort fraud attempts.
A practical starting stack for a small merchant with limited time and no dedicated fraud staff usually looks like this:
- Turn on every free verification tool the processor offers. Stripe Radar, PayPal Seller Protection, and Shopify’s fraud analysis flags all include baseline risk scoring at no additional cost, and most merchants never fully configure them.
- Set a manual review threshold tied to order value. A $40 order with a mismatched CVV carries far less risk than a $400 order with the same flag, so review thresholds should scale with transaction size rather than treating every flag identically.
- Enroll in a free chargeback alert program. Networks like Verifi and Ethoca notify merchants when a dispute is filed, often before it becomes a formal chargeback, giving a window to issue a refund and avoid the chargeback fee entirely.
- Cap or disable small authorization-only transactions. Card testing bots typically probe with $0 or $1 charges before attempting a real purchase, so limiting or blocking these transaction types removes a common entry point.
- Document every fraud incident, even minor ones. A simple spreadsheet tracking flagged orders, outcomes, and reasons builds the pattern recognition that justifies investing in paid tools once volume grows.
None of these steps require a developer or a monthly software fee, which makes them the right starting point regardless of business size. Small merchants can layer in velocity checks and a basic risk-scoring rule set as order volume grows, before investing in dedicated fraud detection software. That transition point usually arrives once manual review becomes too time-consuming to sustain by hand.
What to Do If You Suspect Card Not Present Fraud
Merchants who spot a suspicious transaction should act before it ships, not after a chargeback arrives. Start by reviewing the order for AVS and CVV mismatches, unusual shipping addresses, or a shipping speed that doesn’t match the customer’s stated urgency. If the order looks fraudulent, cancel it and refund the charge proactively rather than waiting for a dispute, since a voluntary refund avoids the chargeback fee entirely.
For fraud that has already gone through, documentation matters. Merchants should gather transaction records, device data, and verification results before contacting their processor’s fraud department. Reporting the incident correctly and keeping that documentation organized strengthens any dispute the merchant later has to fight.
Frequently Asked Questions
How to prevent card-not-present fraud?
Combining AVS, CVV checks, and real-time risk scoring closes most of the common entry points fraudsters exploit online. Flagging mismatched billing and shipping addresses catches attempts that slip past the basic checks.
Who is liable for card-not-present fraud?
In most CNP transactions, the merchant is liable for the chargeback because the cardholder could not be verified in person. Liability can shift to the card issuer when the merchant uses strong authentication such as 3D Secure 2.0.
What percentage of credit card fraud is through card-not-present?
Card-not-present transactions account for the large majority of card fraud losses industry-wide, and that share has grown as more purchasing moves online.












