Questions? Talk to a real person

How to Prevent Credit Card Fraud as a Merchant

Credit card fraud remains a costly threat to merchants. Global card fraud losses dipped slightly to $33.4 billion in 2024, but The Nilson Report still projects cumulative losses will reach $407.6 billion over the next decade, climbing to $48.5 billion annually by 2034.

Credit card fraud occurs when someone uses stolen or unauthorized card data to obtain goods, services, or funds. For merchants, that often means chargebacks, lost revenue, and added costs. 

So, how do you prevent credit card fraud as a merchant? It comes down to pairing secure payment technology with smart internal processes, and knowing how the pieces fit together. This guide walks through all of it: fraud prevention best practices, common schemes, merchant liability, reporting requirements, detection tools, and key PCI DSS 4.0.1 considerations for 2026.

Key Takeaways

  • Card-not-present (CNP) fraud, friendly fraud, and account takeover are among the most common types of fraud affecting merchants today.
  • In most card-not-present fraud cases, the merchant, not the bank, is responsible for the financial loss.
  • Effective fraud prevention combines EMV chip technology for in-person payments with tools like AVS, CVV verification, and 3D Secure 2 for online transactions.
  • PCI DSS compliance provides the security foundation for protecting payment data, but merchants still need fraud detection tools to stop fraudulent transactions.
  • If fraud occurs, report it quickly by notifying your payment processor, documenting the incident, contacting the issuing bank, and involving law enforcement when necessary.

How to Prevent Credit Card Fraud as a Merchant

Effective credit card fraud prevention comes down to three layers of protection: in-person controls, online (card-not-present) controls, and operational safeguards. The stronger each layer is, the harder it becomes for fraudsters to exploit your business.

In-Person Card Fraud Prevention

For card-present transactions, a few simple practices can significantly reduce your risk of fraud.

  1. Always require a chip dip or tap. Chip-enabled and contactless payments are more secure than magnetic stripe transactions. Only swipe a card if the chip fails and your terminal prompts you to do so.
  2. Use a current EMV-certified terminal. Outdated payment hardware may not support the latest security standards, increasing your exposure to fraud and liability.
  3. Train staff to spot tampered terminals. Employees should know how to identify skimmer attachments, unusual hardware changes, or signs that a terminal has been compromised.
  4. Ask for ID on large or unusual purchases. If a transaction is significantly larger than usual or seems out of character for your business, verify that the cardholder’s name matches the name on their government-issued ID.
  5. Collect signatures for high-value purchases. A signed receipt can provide additional documentation if a transaction is later disputed. 
  6. Watch for behavioral red flags. Customers who appear rushed, attempt multiple declined transactions, or purchase large quantities of high-resale items may warrant additional verification.

Online (Card-Not-Present) Fraud Prevention

Card-not-present (CNP) transactions carry a higher risk of fraud because the physical card is never verified. These controls help reduce that risk.

  1. Require CVV/CVC verification on every transaction. The card security code helps confirm that the customer has the physical card in their possession.
  2. Use Address Verification Service (AVS). AVS compares the billing address entered during checkout against the address on file with the card issuer. Address mismatches should trigger additional review.
  3. Enable 3D Secure 2 (3DS2). 3DS2 adds an additional layer of cardholder authentication and can shift liability for certain fraudulent transactions from the merchant to the card issuer.
  4. Use device fingerprinting and IP geolocation. Compare device information, IP location, billing address, and shipping destination to identify suspicious inconsistencies.
  5. Set transaction velocity rules. Limit the number of purchase attempts that can be made using the same card, device, or IP address within a defined timeframe.
  6. Verify suspicious orders before shipping. If an order raises concerns, gather complete customer information, including name, address, ZIP code, phone number, and email address. Contact the customer directly to confirm the order when necessary. 
  7. Use tokenization for stored payment information. Tokenization replaces card data with secure tokens, reducing the risk of sensitive information being exposed if your systems are compromised.
  8. Require signature confirmation for high-value shipments. Matching delivery requirements to transaction risk can help prevent fraud and strengthen your position in the event of a dispute.

Operational and Staff-Level Best Practices

Technology alone won’t stop fraud. Internal processes and employee training play an equally important role.

  1. Train employees regularly. Conduct annual fraud prevention training and ensure staff understand how to identify suspicious activity and respond to chargebacks.
  2. Create a written fraud and refund policy. Clearly document your policies and display refund terms at checkout so customers know what to expect.
  3. Reconcile transactions daily. Reviewing transaction activity every day can help you spot unusual patterns before they become larger problems.
  4. Restrict access to payment systems. Limit payment processor access to employees who need it and enable multi-factor authentication (MFA) on every account.
  5. Never store full card numbers. Avoid saving card data in CRM notes, spreadsheets, emails, or any system not specifically designed for secure payment storage.

The most effective fraud prevention strategies combine people, processes, and technology. But to build the right defenses, you first need to understand what you’re defending against. Let’s look at the six most common types of credit card fraud merchants encounter.

How Does Credit Card Fraud Happen? Common Types Affecting Merchants

Most merchant fraud falls into two macro categories: card-present (CP) and card-not-present (CNP), with CNP driving the majority of merchant losses. From there, fraud breaks into these six common patterns.

Card-Not-Present (CNP) Fraud 

Card-not-present fraud occurs when someone uses stolen card information to make a purchase without presenting the physical card. This can happen through eCommerce websites, phone orders, subscription services, or mobile apps. Because merchants can’t verify the card in person, CNP fraud remains one of the most common and costly forms of payment fraud.

Friendly Fraud (Chargeback Abuse) 

Friendly fraud occurs when a customer makes a legitimate purchase and later disputes the transaction with their card issuer. Sometimes this happens by mistake because the cardholder doesn’t recognize the charge. In other cases, customers intentionally file chargebacks to keep both the product and their money.

Counterfeit and Cloned Cards 

Counterfeit card fraud occurs when criminals create fake physical cards using stolen card data obtained through skimming devices, data breaches, or other theft methods. The fraudulent card can then be used to make in-person purchases. This type of fraud declined significantly after the U.S. adopted EMV chip technology and shifted liability to merchants that failed to support chip transactions. That said, it still happens when businesses accept magnetic stripe fallback transactions or use outdated payment terminals.

Account Takeover (ATO) 

Account takeover fraud occurs when a criminal gains access to a legitimate customer’s account by using stolen usernames and passwords or by phishing. Once inside the account, the fraudster can place orders using stored payment methods, redeem loyalty points, or change account information. ATO is particularly common among eCommerce businesses, subscription services, and merchants that allow customers to save payment information for future purchases. In many cases, it serves as the starting point for larger CNP fraud schemes.

Refund and Return Fraud 

Refund fraud occurs when criminals manipulate a merchant’s return or refund process to obtain money they aren’t entitled to receive. 

For example, a fraudster may request that a refund be issued to a different card than the one used for the original purchase. Other schemes include returning stolen merchandise for cash, claiming an order never arrived, or attempting to secure multiple refunds for a single transaction. You can prevent this type of fraud by implementing clear return policies and requiring same-card refunds. Also consider requiring documented proof of purchase to reduce the risk.

Ghost Tapping 

Ghost tapping is a newer form of payment fraud that exploits contactless payment technology. Fraudsters use compromised NFC-enabled devices or stolen card credentials to initiate unauthorized Tap to Pay transactions without the cardholder’s knowledge. As contactless payments become more common, ghost tapping is drawing increased attention from merchants and payment providers.

Understanding how fraud occurs is the first step. The next question most merchants ask is just as important: when fraud happens, who pays for it?

Who Is Liable When Credit Card Fraud Happens?

In most card-not-present fraud cases, the merchant absorbs the loss. The issuing bank is rarely responsible. Liability depends on how the transaction was processed, whether required security controls were used, and whether the payment was authenticated.

Card-Present (In-Person) Liability

For in-person transactions, liability generally follows the EMV rules established in the October 2015 liability shift.

If a customer uses a chip card and the transaction is processed through an EMV-compliant terminal using chip dip or tap, the issuing bank typically bears the cost of counterfeit card fraud. If the merchant does not have an EMV-capable terminal, bypasses the chip, or falls back to a magnetic stripe transaction when it wasn’t necessary, liability usually shifts to the merchant. In other words, if the merchant fails to use the most secure available payment method, they typically absorb the loss. Merchants are also generally liable when transactions are forced through after a decline or when required cardholder verification methods, such as a PIN or signature, are bypassed.

Card-Not-Present (Online/Phone) Liability

Online, mobile, and phone transactions follow a different set of rules. In most cases, the merchant is liable for fraudulent card-not-present transactions. When a stolen card is used on your website, you often lose the merchandise, forfeit the sale proceeds, and incur a chargeback fee ranging from roughly $15 to $100 per dispute. The primary exception is 3D Secure 2 (3DS2). When a transaction is successfully authenticated by the cardholder’s issuing bank using 3DS2, liability can shift from the merchant back to the issuer, depending on the card network’s rules. Many merchants assume that AVS and CVV checks provide the same protection. They don’t. AVS and CVV help identify suspicious transactions and reduce fraud risk, but they do not shift liability. A fraudster can still pass AVS and CVV checks if they have enough stolen cardholder information.

Friendly Fraud / Chargeback Liability

Friendly fraud creates a different challenge because the transaction itself is often legitimate. A customer receives a product or service, then disputes the charge with their bank, claiming they didn’t authorize the purchase, didn’t receive the item, or were otherwise entitled to a refund. Whether the dispute is accidental or intentional, the process starts the same way: the merchant is debited first. The burden of proof falls on the merchant. To recover the funds, you must submit evidence showing that the transaction was valid. This process is known as representment. The strength of your case depends almost entirely on documentation. Evidence may include:

  • Delivery confirmation and tracking information
  • Signed receipts or proof of in-store purchase
  • AVS and CVV match results
  • IP address and device data
  • Customer communications and order records
  • Subscription terms and cancellation history

Without supporting documentation, winning a chargeback dispute becomes significantly more difficult. Knowing who pays for fraud is one layer. PCI compliance is the security baseline that stops the data breaches behind most CNP fraud before they start.

Payment Security Tools That Prevent Fraud

Most payment fraud is stopped before a transaction is ever approved. But that only happens when merchants have two layers working together: a compliance foundation that protects cardholder data and a fraud detection layer that identifies suspicious activity in real time.

Compliance Baseline: PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) is the security framework that every business accepting credit card payments must follow. Its purpose is simple: reduce the risk of cardholder data being exposed, stolen, or misused. PCI DSS establishes the baseline security controls merchants need to protect payment data. These controls include encryption, tokenization, network security requirements, access controls, system monitoring, and vulnerability management practices.

The current version, PCI DSS 4.0.1, became the only active version of the standard at the end of 2024, and its remaining future-dated requirements became mandatory on March 31, 2025. Among the most important changes are stronger authentication requirements, more rigorous access controls, and expanded oversight of payment page scripts, which have become a common target for eCommerce attacks. Failing to comply with PCI DSS can be costly. Merchants may face fines ranging from $5,000 to more than $100,000 per month, along with increased liability exposure if a data breach occurs.

Detection layers

Modern payment systems use multiple layers of fraud detection to identify risky transactions in real time.

  • Tokenization – Replaces card data with a non-sensitive token. Stops breach data from being usable.
  • Encryption (P2PE / end-to-end) – Protects card data from terminal to processor.
  • Velocity and rule-based filters – Flag unusual patterns (multiple cards same IP, multiple attempts same card, shipping/billing mismatches).
  • Machine learning fraud scoring – Most modern processors score each transaction in real time using behavioral and historical data.
  • 3D Secure 2 (3DS2) – Real-time authentication via the cardholder’s bank. Shifts liability when successful.
  • Chargeback alerts (Ethoca, Verifi) – Notify you of disputes before they become chargebacks. Gives you a window to issue a refund and avoid the fee.

Many payment and online gateway providers, including Kurv, offer built-in fraud prevention and chargeback management tools as part of their payment processing services. When evaluating a payment processor, it’s worth looking beyond rates and considering the platform’s fraud-prevention capabilities.

Even the strongest fraud prevention stack won’t stop every fraudulent transaction. When fraud does occur, responding quickly can reduce losses and improve your chances of recovering funds.

How to Report Credit Card Fraud

If you discover a fraudulent transaction, act quickly. The sooner you report it, the better your chances of limiting losses, preserving evidence, and strengthening any future chargeback dispute.

Step 1: Notify Your Payment Processor First

Your payment processor should be your first call. They can flag the transaction, determine whether settlement has already occurred, and guide you through the chargeback or fraud reporting process. If the transaction is still pending, your processor may be able to help prevent additional losses. Kurv merchants can report suspected fraud through the merchant portal or by contacting support (available 24/7).

Step 2: Document Everything Immediately

Gather and preserve all available transaction data before records are lost or overwritten. This includes the transaction receipt, customer information, IP address, device information, email correspondence, shipping records, and AVS/CVV verification results.

Step 3: Contact the Cardholder’s Issuing Bank

Once you’ve identified a fraudulent transaction, contact the card’s issuing bank. Provide the transaction details, shipping address, delivery information, and any other relevant records you have collected.

The bank can contact the cardholder directly, confirm whether the transaction was authorized, and potentially assist with recovery efforts. Sharing shipping information may also help investigators identify patterns linked to other fraudulent purchases.

Step 4: Report the Fraud to Law Enforcement

If the merchandise has already been shipped or the fraud involves a significant dollar amount, file a report with your local law enforcement agency. For online fraud and larger cybercrime incidents, you should also consider filing a complaint with the FBI’s Internet Crime Complaint Center (IC3).

A police report creates an official record of the incident and may be required for insurance claims. It can also strengthen your supporting documentation during a chargeback dispute.

Step 5: Review Your Prevention Stack

Every fraud incident reveals a weakness somewhere in the payment process. Once the immediate issue is addressed, review how the transaction made it through your controls. Did the order bypass manual review? Were the velocity rules too loose? Was 3D Secure disabled? Identifying the root cause allows you to strengthen your fraud prevention measures and reduce the likelihood of the same attack succeeding again.

Final Thoughts

Preventing credit card fraud is a balancing act. If your controls are too aggressive, you might block legitimate transactions. If they’re too loose, fraudsters can slip through. Tools like AVS, velocity rules, and 3D Secure can reduce fraud, but also introduce friction at checkout. The goal isn’t to stop every suspicious transaction. It’s to build a fraud-prevention strategy that catches most bad actors while keeping the buying experience smooth for actual customers.

That’s one reason merchants choose processors that include key fraud-prevention tools by default, rather than requiring them to build a prevention stack from scratch. Kurv includes built-in fraud protection and chargeback prevention capabilities, as well as support for EMV, tokenization, and 3D Secure 2. That way, you can benefit from having a more secure payment environment without needing to manage every setting yourself. Get started with Kurv and start accepting payments in 24 hours.

Ready to Grow Your Business?

Apply and start accepting payments within a day

Google Ratings

Frequently Asked Questions

What is credit card fraud?

Credit card fraud is the unauthorized use of a credit card or card data to obtain goods, services, or funds. It mainly falls into two categories: card-present (CP) fraud, which occurs in person, and card-not-present (CNP) fraud, which occurs online, over the phone, or through mobile apps.

Who is responsible for credit card fraud charges at a business?

In most card-not-present fraud cases, the merchant is responsible for the loss. For in-person transactions, liability often depends on whether the merchant used an EMV-compliant terminal. Generally speaking, EMV chip transactions shift counterfeit fraud liability to the issuer, while non-EMV transactions leave the merchant exposed. For online transactions, liability remains with the merchant unless a successful 3D Secure 2 authentication triggers a liability shift.

Are merchants responsible for stolen credit cards?

It depends on how the card was used. If a stolen physical card is used at a business that properly processes an EMV chip transaction, the issuing bank will often absorb the loss. If stolen card data is used online, the merchant is typically liable for the fraudulent transaction unless a liability shift applies through 3D Secure 2.

How are merchants liable for credit card fraud?

Merchants most commonly become liable in three situations: when they bypass EMV protections and process a magnetic stripe transaction, when they accept fraudulent card-not-present transactions without a liability shift mechanism such as 3D Secure 2, and when customers file chargebacks or friendly fraud claims.

What is the most common type of credit card fraud for merchants?

Card-not-present (CNP) fraud is the most common type of credit card fraud affecting merchants. Because the physical card is never presented, fraudsters can use stolen card information to make purchases online, through mobile apps, or over the phone. As eCommerce continues to grow, CNP fraud remains one of the fastest-growing sources of merchant losses.

How common is credit card fraud?

Credit card fraud is a growing global problem. According to The Nilson Report, annual card fraud losses are projected to exceed $48 billion by 2034, with cumulative losses topping $407 billion over the next decade. Much of that growth is expected to come from card-not-present transactions, which continue to expand alongside eCommerce and digital payments.

How do I report credit card fraud as a small business?

Start by notifying your payment processor and preserving all transaction records. Next, gather supporting evidence, contact the cardholder’s issuing bank, and, if appropriate, report the incident to law enforcement. Documenting the fraud quickly improves your chances of recovering funds and successfully responding to any resulting chargeback. See the reporting section above for the complete five-step process.

Does PCI compliance prevent credit card fraud?

PCI compliance helps prevent data breaches and security failures that often lead to payment fraud, but it does not stop fraud on its own. Think of PCI DSS as the security foundation. Merchants still need fraud detection tools such as tokenization, velocity filters, machine learning fraud scoring, and 3D Secure 2 to identify and block suspicious transactions in real time.

Dan Stanbridge

Chief Risk and Compliance Officer, Kurv

Dan Stanbridge, Chief Risk & Compliance Officer at Kurv, brings over 15 years of experience in risk management, credit strategy, and regulatory oversight across global payments organizations. He is known for building structured, scalable risk …

More author’s articles →