Questions? Talk to a real person

What Is Card-Not-Present Fraud? A Merchant’s Guide to Detection and Prevention

Card-not-present (CNP) fraud occurs when a payment card is used without the cardholder or physical card being present during the transaction. It’s one of the most common forms of payment fraud in eCommerce and other remote payment environments — and the threat continues to grow.

According to FICO, global CNP fraud losses are projected to reach $49 billion by 2030. As online, mobile, and recurring payments become more prevalent, merchants need a clear understanding of the risks associated with CNP transactions and the steps they can take to reduce them.

Updated for 2026, this guide explains what CNP fraud is, how it works, common fraud schemes, who bears the liability, and how merchants can detect and prevent it.

Key Takeaways

  • Card-not-present (CNP) fraud occurs when someone uses stolen payment card information to make purchases without the physical card being present, making transactions harder for merchants to verify.
  • Common CNP fraud schemes include skimming, phishing, data breaches, account takeover (ATO) attacks, and friendly fraud, all of which can expose cardholder information to criminals.
  • In most CNP chargeback cases, merchants are liable for the losses, meaning they may lose both the revenue from the sale and the disputed merchandise or services.
  • Businesses can reduce risk by implementing layered fraud prevention measures such as Address Verification Service (AVS), CVV checks, 3D Secure authentication, tokenization, and real-time transaction monitoring.
  • If CNP fraud occurs, merchants should report it to their payment processor, acquiring bank, and relevant card networks, and document the incident to support chargeback disputes and recovery efforts.

What Is Card-Not-Present (CNP) Fraud?

As the name suggests, card-not-present fraud happens when an unauthorized individual (or scammer) somehow gets hold of a cardholder’s credentials, such as their name, card number, billing address, CVC / CVV number, and card expiration date, and makes fraudulent purchases using that payment information.

This type of fraud is specific to card-not-present transactions, a category that includes online, mobile, phone, MOTO, and invoiced payments, not just eCommerce checkouts. In all of them, the scammer never hands over a physical card. That’s also what makes CNP fraud so hard to detect; without the card in front of them, merchants have no easy way to verify the transaction is legitimate.

How Card-Not-Present Fraud Works

Scammers and cybercriminals employ a variety of techniques to illegally obtain cardholder data and use it to make unauthorized purchases through card-not-present (CNP) transactions. Because these transactions occur remotely and do not require a physical card, merchants can’t rely on in-person security measures such as chip-and-PIN verification, signatures, or photo ID checks. Instead, they must determine whether a transaction is legitimate based primarily on the payment information provided.

This type of fraud affects both consumers and merchants. Customers typically dispute unauthorized charges, which can result in chargebacks. When that happens, businesses often lose the revenue from the sale, the product or service provided, and any associated chargeback fees.

The following are some of the main ways that fraudsters get access to card information:

  • Skimming — Scammers may install card-skimming devices on payment terminals or ATMs that capture card information automatically when an unsuspecting customer swipes, dips, or taps their card. Stolen card data from skimming can later be used for CNP fraud.
  • Phishing — Fraudsters may employ psychological manipulation to trick unsuspecting customers into revealing their payment information through fake calls, emails, or messagzillow
  • Data breaches — cybercriminals may exploit security vulnerabilities in bank or merchant websites/databases to obtain cardholder data in bulk.
  • Spyware — Scammers may trick cardholders into downloading malware onto their devices, which is designed to automatically monitor a user’s online activity and capture sensitive information such as passwords and payment details.
  • Public Wi-Fi interception — Fraudsters may even monitor public Wi-Fi networks to obtain sensitive payment information from unsuspecting users.

Types of Card-Not-Present Fraud

Card-not-present fraud prevention can become easier once you understand the various ways it can show up. Here are some common examples of it:

Stolen card data fraud

One of the simplest types of CNP fraud is when fraudsters steal card information through any of the means discussed earlier (e.g., malware, phishing, data breaches) and use it to make unauthorized online purchases.

Account takeover (ATO)

Sometimes, cybercriminals may steal credentials for someone’s bank, retail, social media, or email accounts. Then, once the bad actor gains access to an account, they would change the credentials, locking out the legitimate user. Fraudsters do so to steal personal data, funds, loyalty points, etc.

Friendly fraud

A type of first-party fraud that occurs when a legitimate cardholder disputes a valid transaction with their bank. This may happen because they don’t recognize the charge, have forgotten about the purchase, are experiencing buyer’s remorse, or are intentionally attempting to avoid paying. Even if the transaction is authorized, the merchant can still lose the product and revenue and incur chargeback fees.

Subscription and recurring payment fraud

Scammers often use stolen card information to purchase subscriptions (magazines, newspapers, streaming services, etc.), and these purchases can go unnoticed for a long time.

Digital goods and instant fulfillment fraud

Digital goods such as gift cards, game keys, software, and more are delivered instantly after purchase. Often, fraudsters will purchase them using stolen card data and resell or redeem them immediately, mimicking legitimate customers.

Why CNP Fraud Is a Growing Problem for Merchants

Card-not-present (CNP) fraud can have a significant financial impact on merchants. When a cardholder discovers an unauthorized transaction, they will most likely dispute the charge with their card issuer.

Unlike many card-present transactions, where liability may shift through EMV protections, merchants typically absorb the loss for fraudulent CNP chargebacks. That means losing the transaction revenue, the product or service delivered, and any associated chargeback fees. Merchants with excessive fraud or chargeback ratios may also face additional penalties, higher processing costs, or increased scrutiny from payment providers.  

Industry data shows that this issue is growing. According to Mastercard, global CNP fraud is 8 times higher than at a point of sale. In the same vein, a 2025 report by Visa shows that while card-present fraud rates have decreased by 85% in the last two years, CNP fraud continues to increase, as eCommerce grows. 

These card-not-present fraud trends highlight a growing challenge for businesses, particularly those that rely heavily on eCommerce, subscriptions, and other digital transactions. As online commerce continues to expand, merchants need effective fraud-prevention and chargeback-management strategies to protect both revenue and customer relationships.

How CNP Fraud Leads to Chargebacks

One of the most common consequences of card-not-present (CNP) fraud is a chargeback. A chargeback occurs when a cardholder disputes a transaction with their issuing bank, resulting in a forced reversal of the payment. In a CNP environment, chargebacks often happen when stolen card details are used to make unauthorized purchases.

CNP transactions tend to have higher dispute rates than card-present transactions because there is no physical card, chip, or in-person verification to help confirm the cardholder’s identity. In addition to true fraud, merchants also face “friendly fraud,” which occurs when customers dispute legitimate transactions. According to Mastercard, a 2020 survey found that friendly fraud accounted for roughly 75% of disputes among digital goods merchants.

That’s a big chunk, and the costs associated with this type of fraud can really add up. Businesses with persistently high chargeback ratios may also face higher processing costs or penalties. That’s why having solid chargeback prevention tools is a must. 

How to Prevent Card-Not-Present Fraud

CNP fraud detection and prevention is tricky because technology keeps evolving and fraudsters keep pace. No single tool stops CNP fraud on its own — the goal is layered controls that block bad actors without breaking checkout for good customers. The best practices below can significantly reduce the risk when used together.

Transaction and Identity Verification

  • Card verification value (CVV) codes are 3-digit numbers that appear on the back of most cards (Visa, Mastercard, and Discover). For American Express, these are 4-digit codes that appear on the front of the card.
  • One of the simplest CNP fraud prevention measures that merchants can implement is to make this information mandatory for all CNP transactions. While it’s not foolproof, it adds a verification layer, though sophisticated fraud schemes may still obtain CVV data. 
  • Merchants can also use an address verification system (AVS) to verify that the billing information entered at the time of payment matches the information on file. This can help to add another layer of security to CNP transactions.

Authentication and Step-Up Controls

  • Merchants should also consider implementing 3D Secure (3DS) and, where applicable, strong customer authentication (SCA) measures to help prevent CNP fraud. These protocols require customers to verify their identity using methods such as one-time passwords (OTP) or biometric authentication (fingerprint or facial recognition) within the banking or wallet app.
  • Further, techniques such as tokenization and encryption can ensure that sensitive payment data is replaced by a sequence of unique, random numbers (a token) or a code when transmitted or stored within the merchant’s payment ecosystem. Even if fraudsters obtain such information, it becomes useless, thereby preventing CNP fraud.

Risk Controls and Monitoring

  • Merchants can comply with PCI DSS and employ robust risk-monitoring systems that detect suspicious activity using device data, IP traffic, and transaction-pattern analysis. Choosing a payment provider that offers all of these features is a simple way to safeguard your business against CNP fraud.
  • The right setup catches suspicious behavior while still letting trusted customers move through checkout smoothly.

How to Detect Card-Not-Present Fraud 

Strong CNP fraud detection isn’t just about stopping bad actors, it’s about stopping them without getting in the way of good customers. The trick is reading real risk signals while keeping checkout fast and friction-light. Here’s how smart merchants strike that balance:

  • Using risk scoring to flag high-risk orders instead of reviewing everything
  • Watching for mismatched billing and shipping details
  • Monitoring IP location vs. delivery address inconsistencies
  • Setting velocity rules for repeat attempts or rapid-fire purchases
  • Reviewing unusually large digital goods or gift card orders manually

The right setup detects suspicious behavior while still allowing trusted customers to move through checkout smoothly.

How to Report Card-Not-Present Fraud

If you detect a potentially fraudulent card-not-present (CNP) transaction, acting quickly can help minimize losses and improve your chances of recovering funds. Here’s what merchants should do:

  1. Document the transaction. Gather all relevant information, including the order details, transaction amount, billing and shipping addresses, IP address, device data, timestamps, and any communications with the customer.
  2. Notify your payment processor immediately. Your processor can help investigate the transaction, flag related activity, and advise on next steps. In some cases, they may be able to stop the settlement before funds are transferred.
  3. Contact the cardholder, if appropriate. Depending on your processor’s policies, you may be advised to reach out to the customer to verify the transaction or alert them to suspicious activity. Some payment providers handle this process on the merchant’s behalf.
  4. Report the incident to the FBI’s Internet Crime Complaint Center (IC3). The IC3 collects reports of internet-enabled crimes, including eCommerce fraud, and shares information with law enforcement agencies when appropriate.
  5. File a report with the Federal Trade Commission (FTC). If the fraud involves identity theft, stolen personal information, or a broader pattern of fraudulent activity, reporting it to the FTC can help support investigations and consumer protection efforts.
  6. Follow applicable data breach notification requirements. If customer information was compromised, you may have legal obligations under state data breach notification laws. Consult legal counsel and your cybersecurity team to determine the appropriate response.

Keep in mind that many CNP fraud cases ultimately result in chargebacks. The best defense is prevention. Solutions such as Kurv’s built-in fraud and chargeback prevention tools can help merchants identify suspicious transactions early, reducing the likelihood that CNP fraud turns into a costly dispute.

Final Thoughts

Card-not-present fraud can’t be eliminated, but it can be significantly reduced with the right combination of AVS checks, CVV verification, 3D Secure authentication, tokenization, and real-time risk monitoring. What matters is how those tools work together — the wrong fraud prevention setup creates friction for legitimate customers while still letting fraudulent transactions slip through, whereas the right one helps maximize approvals and minimize risk.

When evaluating payment providers, look for a processor that includes PCI compliance, fraud monitoring, and chargeback prevention as part of the core offering rather than charging extra for them as add-ons.

Kurv includes both with every merchant account and is PCI-compliant by default, which helps businesses reduce risk without adding unnecessary complexity.

Ready to learn more?

Explore Kurv’s pricing and payment solutions — or better yet, apply for a merchant account to see how the platform can help protect your business from card-not-present fraud.

Google Ratings

Frequently Asked Questions

What is an example of card-not-present fraud?

A common example of card-not-present fraud is when a criminal obtains stolen credit card information through a phishing scam or data breach and uses it to make purchases on an eCommerce website. Because the physical card isn’t required, the transaction can appear legitimate until the cardholder notices the unauthorized charge and disputes it.

How do you detect card-not-present fraud?

Some of the most common warning signs include mismatches between billing and shipping addresses, transactions originating from suspicious IP addresses or locations, and unusually high transaction velocity, such as multiple purchases made in a short period. Merchants should also watch for orders that deviate from a customer’s normal buying behavior. Combining these signals with fraud monitoring tools can help identify high-risk transactions before they are processed.

How do I report card-not-present fraud as a merchant?

If you suspect a fraudulent transaction, notify your payment processor or acquiring bank as soon as possible. Document key details such as order information, IP addresses, device data, and transaction timestamps. If the incident involves identity theft or a broader fraud scheme, consider reporting it to the FBI’s Internet Crime Complaint Center (IC3) and the Federal Trade Commission (FTC).

Is CNP fraud illegal?

Yes. Card-not-present fraud is a form of financial fraud that involves using stolen payment card information to make unauthorized purchases. Depending on the circumstances, offenders may face criminal charges, fines, and imprisonment.

Who is liable for card-not-present fraud?

In most cases, merchants are liable for fraudulent CNP transactions that result in chargebacks. Because there is no physical card verification during the transaction, card network rules generally place the financial responsibility on the merchant rather than the cardholder or issuing bank.

Can card-not-present fraud be fully prevented?

No. Card-not-present fraud cannot be eliminated, but it can be significantly reduced. Layered security controls such as AVS, CVV verification, 3D Secure authentication, tokenization, and real-time fraud monitoring can dramatically lower risk.

Is CNP fraud increasing?

Yes. Card-not-present fraud is a form of financial fraud that involves using stolen payment card information to make unauthorized purchases. Depending on the circumstances, offenders may face criminal charges, fines, and imprisonment.

Can card-not-present fraud be fully prevented?

No. Card-not-present fraud cannot be eliminated, but it can be significantly reduced. Layered security controls such as AVS, CVV verification, 3D Secure authentication, tokenization, and real-time fraud monitoring can dramatically lower risk.

Is CNP fraud increasing?

Yes. Card-not-present fraud continues to rise as eCommerce and digital payments grow. Industry forecasts project global CNP fraud losses will reach $49 billion by 2030, reflecting a broader shift in fraud activity from in-store transactions to online and remote payment channels.

How can small businesses prevent CNP fraud?

Small businesses can reduce CNP fraud by enabling AVS and CVV checks, using 3D Secure for higher-risk transactions, implementing velocity rules, and monitoring for suspicious purchasing patterns. Clear billing descriptors can also reduce friendly fraud and unnecessary chargebacks. Partnering with a payment processor that offers built-in fraud-prevention tools can strengthen protection even further.

Is CNP fraud more common than in-store fraud?

Yes. The widespread adoption of EMV chip technology has significantly reduced counterfeit card fraud in physical stores, causing fraud activity to shift toward online, mobile, and phone transactions. As a result, card-not-present fraud now accounts for a larger share of payment fraud losses than traditional in-store fraud.

Dan Stanbridge

Chief Risk and Compliance Officer, Kurv

Dan Stanbridge, Chief Risk & Compliance Officer at Kurv, brings over 15 years of experience in risk management, credit strategy, and regulatory oversight across global payments organizations. He is known for building structured, scalable risk …

More author’s articles →