Gift Card Fraud: How It Becomes a Chargeback You Can't Win

Gift card fraud is any scheme that uses a gift card, or the payment card behind one, to get value the fraudster never paid for. When the underlying card was stolen, the merchant who accepted that gift-card purchase usually eats the chargeback.
I've had my own checkout hit by small, repeated authorization attempts before I knew what to call them. Velocity limits fixed it, and fraudsters now point that same script at gift-card checkouts. Read on and you'll know which scheme costs you money, and which controls close it.
Key takeaways
- 01Spot card-testing by the burst of small declines on your gift-card product.
- 02Consumers reported $212 million in gift card scam losses in 2024.
- 03More than 26% of consumers surveyed had received a worthless gift card.
- 04Block any email, device, or IP over 10 gift-card attempts in 5 minutes.
- 05Expect to lose these disputes, since the real cardholder never approved the sale.
What is gift card fraud?
Gift card fraud is any scheme that gets someone a gift card's balance, or a purchase on the card funding it, without paying. It covers three patterns. Fraudsters drain a card's balance before redemption, phish someone into handing over the code, or buy the card with a stolen card number.
That last pattern costs you money. When the real cardholder disputes the charge, you're the merchant who loses the sale, the loaded balance, and the chargeback fee.
There are three versions, and they don't all hurt the same person. Almost everyone who writes about this writes for the shopper, and two of the three do hit the shopper.
The version that costs you money happens earlier, at your checkout. A fraudster pays for the gift card with a stolen card number, and days later the real cardholder sees the charge and calls their bank.
Consumers reported at least $212 million in gift card scam losses in 2024, per FTC figures published by AARP.
A 2024 AARP survey found that more than a quarter of consumers have given or received a gift card with zero value on it.
A card bought with a stolen number and a legitimate card that gets drained later are two problems with two different victims. This guide covers the first one, the one you pay for.
Summary: Gift card fraud becomes your problem when a stolen card paid for the card.
How gift card fraud works
Card-testing is the gift-card scheme that costs you the chargeback, and it works by running stolen card numbers at your checkout until one authorizes. A fraudster tests stolen card details with small or zero-dollar charges to see which numbers still work.
Draining and phishing go after a card someone already bought, so the cardholder or the issuer takes that loss.
Say a fraudster has a list of a few thousand stolen numbers.
They point a script at your gift-card page and submit dozens of small attempts in a few minutes. Most decline. The handful that authorize buy real gift cards before the cardholder reads a statement.
Catching that is harder than it sounds. A fraudster who finds four working numbers can sit on them, and a patient one spreads the purchases over a week to stay under your limits.
So watch for the burst of attempts, not the order.
Any one order in the burst looks fine alone. What gives it away is a run of declines on one product, from one address, inside a few minutes.
Types of gift card fraud
Gift card draining, physical tampering, and phishing are the three schemes that target the card itself rather than your checkout:
- Gift card draining: a card's balance is recorded, then spent the moment it's activated.
- Tampering: cards are physically altered on the rack so the draining can happen.
- Phishing and social engineering: a victim is talked into buying a card and handing over the code.
The first two are usually two halves of one job, run by the same people.
1. Gift card draining
Gift card draining is recording a card's number and PIN before it's sold, then spending the balance the moment the real buyer activates it.
Our full guide to gift card draining walks the mechanism and names who pays for it.
2. Tampering
Tampering is the physical step that makes draining possible.
Someone lifts cards off the display rack, exposes the number and PIN, reseals the packaging, and puts them back. The next shopper picks up a card that looks untouched.
This one sits with whoever sells cards off a rack. Stock physical gift cards and the drained-card dispute comes back to you, because you took the original payment. Sell digital codes only, and tampering costs you nothing.
3. Phishing and social engineering
Phishing is talking a victim into buying a gift card and reading the code back.
The caller usually pretends to be the IRS, a utility, or a romantic interest. Once they read out the code the money is gone, because nobody reverses a gift card the way a bank reverses a card payment.
The tell is always urgency plus an odd way to pay. No tax agency or employer asks to be paid in gift cards.
The damage here is mostly to your reputation. A customer talked into buying cards from your store may still come back and ask you to reverse it.
Summary: Draining and tampering are one operation, and phishing skips the card entirely.
How a fraudulent gift card purchase becomes a chargeback
When the real cardholder disputes the charge, you pay it. The card network knows which merchant took the payment, and that merchant is the one it charges back.
The dispute arrives as true fraud, meaning the cardholder says they never made the purchase. Gift-card sales run card-not-present, so nobody signed anything and nothing shipped anywhere.
If it reaches chargeback, you lose the sale, the balance already loaded onto the card, and a fee.
One move gets you out of this before it starts. Catch the order before anyone activates the card and you can void the sale, which leaves nothing to dispute.
Once someone can spend the balance, it's too late to void it.
Which chargeback reason code applies to gift card fraud
A gift-card purchase made with a stolen card disputes under the card-not-present fraud reason code. Banks use that same code for any unauthorized online purchase. Visa files it as Other Fraud, Card-Absent Environment, which covers sales where someone keyed the card data in rather than swiping it.
The code exists so a cardholder can contest a purchase they say they never approved, and for a physical-goods dispute you'd answer it with delivery proof.
A gift card ships nowhere and gets no signature, so that evidence does not exist.
Banks also use this code for friendly fraud and for plain merchant mistakes, like skipping an authorization check, so it tells you which rules you answer under.
Our guide to chargeback reason codes covers the full list.
Why merchants rarely win a gift card fraud dispute
You lose these disputes because the compelling evidence that wins them, proof the cardholder approved the purchase, cannot exist when the card was stolen. There's no approval record, no delivery address, and no signed receipt to send in.
You do have the processing record. Your checkout logs, your match results, and the authorization code all show the sale went through correctly.
The only question the reason code asks is who made the purchase, and that record cannot answer it.
A full card-code and address match is still worth having. It shows your acquirer you followed the security steps, which counts for your standing in a fraud-monitoring program even on a dispute you lose.
Summary: These disputes fail on missing proof, and a stronger response cannot supply it.
How merchants can prevent gift card fraud
Velocity limits, card-code and address verification, and a pre-dispute alert stop most card-testing at your checkout:
- Velocity limits: cap gift-card purchase attempts per email, device, and IP address.
- Card-code and address verification: require both on every gift-card-funded order.
- A pre-dispute alert: get told when a cardholder disputes, then refund before it becomes a chargeback.
Work down the list in order, because each one catches what the one before it misses.
1. Set velocity limits on gift-card attempts
Block any email, device, or IP address that submits more than ten gift-card attempts in five minutes. J.P. Morgan recommends velocity rules keyed to customer attributes like email, device, and IP address to stop card-testing.
Set that limit below whatever you allow on the rest of your catalog. Ten declines from one address in five minutes is a script, well past what a real shopper does.
Shopify, Stripe Radar, and your gateway's rules engine all let you write that rule against gift-card SKUs.
2. Require card-code and address checks
Turn on card verification value (CVV) and address verification (AVS) for every gift-card order, then decline on a mismatch. A fraudster with a stolen number often has the card details but not the billing address, so an address mismatch is the easiest thing to check.
Plenty of merchants run these checks in soft mode, where a failed match still lets the order through. That setting is fine for a physical product you can get back.
It is wrong for a gift card, because you cannot get the balance back once the card activates.
3. Use a pre-dispute alert as a backstop
A pre-dispute alert tells you a cardholder has disputed a charge with their bank before that dispute becomes a chargeback.
You can then refund the sale before the chargeback lands, which saves you the fee and the ratio hit. We pull alerts from Ethoca (Mastercard) and match them to the transaction in your processor.
Coverage on the Visa side comes through Verifi. An alert saves you the chargeback, the part that counts against your ratio. You eat the loaded balance either way.
What to do if you accepted a fraudulent purchase
Void the order if nobody can spend the balance yet, and respond to the dispute if they can. The card's activation status decides which one applies.
Act before activation and you skip the chargeback path, because nobody can dispute a balance that never went live. Wait until after, and you're answering a dispute you'll probably lose. File the authorization record and the address-match result anyway.
Then pull the order's attempt history and tighten the velocity rule that let it through.
A pre-dispute alert still reaches you after activation. You'll hear about the dispute first, and a refund at that point keeps it out of your ratio.
Look up the code on your next dispute notice with our reason code lookup to see what evidence that code requires.
FAQ
How to report gift card fraud
Consumers report gift card fraud to the FTC at reportfraud.ftc.gov and to the company that issued the card. Merchants report the fraudulent transaction to their payment processor and their acquiring bank.
Is gift card fraud the same as gift card scams?
"Scams" names the trick played on shoppers, while "gift card fraud" also covers the stolen-card purchases merchants pay for. They describe the same schemes from opposite sides of the counter.
Can a card network flag a merchant for gift card fraud?
Yes. Fraud disputes count toward the ratios Visa and Mastercard watch, so a run of card-testing chargebacks can push you over a threshold.
Do gift cards attract more fraud attempts?
Yes, because a gift card is close to cash and resells fast. There's also no shipping address to verify and no physical item to intercept.
