Card-Not-Present Fraud: What It Is and Who Pays

Card-not-present fraud occurs when stolen card details are used without the cardholder or card present, usually shifting the loss to the merchant unless authentication changes liability.

Card-not-present fraud happens when someone uses stolen card details to buy something without the physical card in hand, most often online or over the phone. The merchant, not the cardholder, usually absorbs the loss when the real cardholder disputes the charge.

I worked support, and I looked at how merchants had set up their processors. Most of the card-not-present pain I saw came from a setup decision someone made on day one.

By the end of this you'll know which of three paths applies to you:

  1. Stop the fraud at checkout: Four controls, covered below.
  2. Catch it before it files: A dispute alert reaches you first.
  3. Answer the chargeback: Send whatever evidence you have.

Key takeaways

  1. 01Expect to pay for this yourself, since no card was there to verify.
  2. 02Watch Visa reason code 10.4, which carries 11.1% of our coded alerts.
  3. 03Run 3D Secure on orders above your average value or shipping abroad.
  4. 04Card-absent fraud hit 73% of US card payment fraud in 2024.
  5. 05Turn on address and CVV declines, because true fraud rarely wins on appeal.

Want these caught before they file? Our dispute alerts reach you while a refund still closes the case.

What is card-not-present fraud?

Card-not-present (CNP) fraud is a purchase made with stolen card details, where the seller only ever sees the details and never the card. It happens online, over the phone, and through mail order.

Nobody looks at a card, so nobody catches that a stranger is using it.

This is true fraud, where a real thief used a real stolen card, which puts it in a different bucket from a customer disputing a charge they made themselves. That difference decides everything about who pays and what evidence exists later.

One case sits outside the definition.

A tapped or inserted transaction can still be fraud, if the card itself was stolen. The term describes the absence of the card at checkout, and a stolen card in a thief's hand still showed up.

How card-not-present fraud actually happens

Fraudsters get card details by phishing the cardholder, buying breached data, skimming it at entry, or stealing it with malware. The first two trick the cardholder directly, and the last two take the data while the cardholder stays unaware:

  1. Phishing and social engineering: The cardholder hands over the details.
  2. Data breaches and card dumps: A company loses the details in bulk.
  3. Skimming devices: Hardware or scripts copy the details at the point of entry.
  4. Malware and account takeover: Software steals the details or the account holding them.

All four end at the same checkout, so the four controls below have to catch the number whichever channel supplied it.

1. Phishing and social engineering

Phishing gets card details by asking for them, in a message the cardholder believes is real. A fake order confirmation, a fake delivery notice, or a fake bank alert points the cardholder at a page that looks like a checkout. The page captures whatever they type.

Attackers run these pages against thousands of people at once, so even a low response rate hands them working card numbers.

Voice calls work the same way, and they reach people who would never click a link.

2. Data breaches and card dumps

A breach gives fraudsters card details in bulk, thousands of records out of one intrusion. Thieves package the stolen records and sell them as "dumps." Price depends on how fresh they are and whether the CVV came with them.

Old breach data is often dead, so buyers work around that. A number that's circulated for months has often been cancelled, so buyers test batches at checkout first.

Those test charges land on merchants selling cheap digital items, where a small charge won't get noticed.

3. Skimming devices

Skimming copies card data the moment the shopper enters it. Hardware does it on a physical reader, and a script does it on a checkout page. The web version is the one that reaches card-not-present fraud, where injected JavaScript on a hacked payment page copies each field as the shopper fills it in.

The stolen data goes straight to card-absent use, because a copied number has no card behind it.

4. Malware and account takeover

Malware and account takeover reach the card through the cardholder's own device or logged-in account. Infostealer software pulls saved card details out of a browser. Account takeover spends the card already saved in an account the fraudster now controls.

Account takeover is the harder one to catch, because every signal looks legitimate.

Our full guide to account takeover prevention covers the login and order-level controls that catch it.

Who pays for card-not-present fraud

You do, in almost every case. The merchant loses the disputed amount, the product, and the chargeback fee. The cardholder gets their money back, and the issuing bank passes the cost along to you.

Card network rules give that loss to whoever couldn't confirm the card was there, and that's always your checkout. You only ever had the number, so the rules treat the risk as yours.

The chargeback reason codes used for these disputes are written to match.

One exception changes the math. Run the order through 3D Secure, and Visa and Mastercard's EMV 3DS rules move fraud liability to the issuer.

An authenticated order that turns out to be fraud is generally the issuer's loss.

Summary: the card-not-present fraud loss is yours unless 3D Secure authenticated the order.

How common is card-not-present fraud, really?

ACI Worldwide and Square put card-absent fraud between 73% and 85% of card fraud, and Visa reason code 10.4 leads our coded alerts at 11.1%. ACI reports that card-not-present fraud made up 85.3% of all card fraud reported in 2020. Square puts it at 73% of US card payment fraud in 2024, up from 57% in 2019.

Read the years and the countries before you use either one. ACI's figure is global and five years older, while Square's covers US fraud in 2024. The jump from 57% to 73% in Square's data shows how fast this share moves.

Our figure counts something narrower. In our own dataset, among the alerts our platform handled with a recorded code, 11.1% carried Visa's 10.4 code for card-absent fraud. Fraud losses and dispute alerts are separate pools, so all three can be right at once.

 
Card-absent fraud: three measures, three populations
 
Share of card fraud reported, 2020
85.3%
 
Share of US card payment fraud, 2024
73%
 
Share of our alerts coded 10.4
11.1%
 
The top two bars measure fraud losses across a market. The bottom bar measures coded dispute alerts on our own platform, so the three are not directly comparable.

Know why our own figure runs low before you use it as a benchmark.

Roughly 77.5% of the alerts we see with a recorded reason land in "Consumer Disputes Category". That catch-all hides more card-absent fraud inside it, and nobody can say how much. So 10.4 leads every named code while a bucket that names nothing stays bigger.

How merchants prevent card-not-present fraud

Address verification, CVV checks, 3D Secure, and tokenization cut card-not-present fraud. The first two run silently, the third interrupts the buyer, and the fourth protects data you've already stored:

  1. Address verification: Match the billing address to the issuer's record.
  2. CVV verification: Require the printed code the card file doesn't hold.
  3. 3D Secure authentication: Send the buyer to the issuer to confirm identity.
  4. Tokenization: Replace stored card numbers with useless substitutes.

Take them in order, since the first two belong on every order before you add the third.

1. Address verification (AVS)

Turn on address verification and decline a full mismatch on the street number and postal code. Most gateways ship with AVS running but with every response code accepted. You get the response and then ignore it.

The check works best against breach-sourced numbers, which arrive without the billing address attached.

Decline on a full mismatch and accept a partial one. A genuine buyer who moved recently will fail the street line and pass the postal code.

2. CVV verification

Require the CVV on every card-absent order and decline any transaction that returns a mismatch. Storage rules forbid anyone from keeping those three or four printed digits after authorization. No other element on the card works that way.

That storage ban is exactly what makes the check useful. A fraudster working from breached records has the number and the expiry date but no CVV.

Fresh phishing captures do include it, so treat a passing CVV as one signal among several.

3. 3D Secure (3DS) authentication

Route your highest-risk orders through 3D Secure. Good candidates are orders above your average value, orders shipping to a country the billing address doesn't match, and first orders on a new account.

Sending everything through 3DS costs you real sales, because each authentication adds a step where buyers drop out.

Risk-based routing only adds that step to the risky orders, and those are the ones where the liability shift pays for it.

4. Tokenization of stored card data

Move your saved-card and subscription flows onto your gateway's tokenization so your database stores only the token. Any subscription, saved-card, or one-click checkout feature is storing card data somewhere. The token version keeps the real number in the gateway's vault.

This one stops a breach of your database from becoming fraud at someone else's checkout. A token stolen from your systems is dead everywhere else.

It also takes every system that used to handle raw card numbers out of your compliance scope.

Summary: run AVS and CVV on everything, 3D Secure on risky orders, tokens on anything stored.

What happens when CNP fraud becomes a chargeback

You will probably lose a card-not-present fraud dispute, which arrives under Visa 10.4 or Mastercard 4837. A stranger really did make the purchase, so the dispute is accurate and the evidence sits with the fraudster. Confirm the exact code on your dispute notice with our reason code lookup tool, since Visa and Mastercard ask for different evidence under each one.

Winning a fraud-code dispute means proving the cardholder authorized the charge. Three things count as proof:

  1. A matching address and CVV result on the original order.
  2. A completed 3D Secure authentication record.
  3. A run of clean, undisputed orders from the same device.

Real card-absent fraud produces none of those.

The network also files a separate TC40 fraud report. It counts against your fraud ratio whether you fight the dispute or not.

One case is worth fighting. If the order completed 3D Secure authentication, that record is strong evidence and carries the liability shift with it, so submit it.

There's a stage before all of this where the outcome is still open.

A chargeback alert reaches you after the cardholder disputes the charge with their bank but before the chargeback is filed. That window is the last point a refund can close the case without a fee or a ratio hit.

Our alerts pull from Ethoca and Verifi, so you see these disputes inside that window.

Is card-not-present fraud the same as identity theft?

No. Card-not-present fraud is one type of transaction fraud, while identity theft is the broader crime of using someone's personal information. A stolen card number used at your checkout is card-absent fraud.

That same stolen identity used to open a new credit line is identity theft with no transaction of yours involved.

They overlap, but they aren't the same thing. Identity theft often produces card-absent fraud, because stolen personal data is what makes a stolen card usable online. It also causes plenty of harm that never touches a merchant, like fake tax filings and new accounts.

The distinction matters when you're sorting disputes.

Chargeback fraud filed by your actual customer is a third category, and it takes a different fix from either of these.

How we sourced our data

Our platform figures come from anonymized, pooled alert data across the merchants enrolled on Chargeback.io. We counted total alerts within each category, in this case the network reason code attached to each one. We report them as shares of the alerts carrying a recorded value. These numbers describe alerts our platform processed on behalf of enrolled merchants.

FAQ

What is an example of card-not-present fraud?

Someone buys headphones from your online store with card details stolen in a breach, then ships them to an address that isn't the cardholder's. The real cardholder sees the charge later and disputes it as fraud.

Can you go to jail for card-not-present fraud?

Yes. Using stolen card details is criminal fraud in most places, and prosecutions carry fines and prison sentences that scale with the amount stolen.

How do I process a card-not-present transaction?

Key the card number, expiry date, CVV, and billing address into your gateway's virtual terminal, or take them through your online checkout. Keep the address and CVV response codes with the order record, since they're your evidence if the sale is disputed.

Does 3D Secure stop all card-not-present fraud?

No. 3D Secure only verifies the person paying, so orders that skip it stay exposed, along with phone orders where it can't run.

Riduci il tasso di controversie oggi

Unisciti a oltre 800 aziende che utilizzano Chargeback per prevenire i chargeback automaticamente: la configurazione richiede meno di 2 minuti.