Card-not-present fraud happens when someone uses stolen card details to buy from you without the physical card. The loss falls on your business by default: the merchandise, the sale, the processing fees, and a chargeback fee on top of that. Phone orders, online ordering, and gift card sales carry the most exposure.
Below, you will find how the fraud works, who pays, and what shifts that liability, what a rising fraud ratio costs you with your acquirer, where your store is most exposed, and the controls that cut your risk.
Key Takeaways:
- You absorb the loss by default on a card-absent sale: the goods, the revenue, the fees you already paid, and a penalty on top.
- Successful 3D Secure authentication is the one control that hands fraud liability back to the issuer. AVS and CVV checks screen bad orders but transfer nothing.
- Visa and Mastercard both monitor your fraud and dispute activity, and a high ratio threatens your merchant account long before it costs you a fine.
- Declining more orders backfires. Each refused legitimate sale pushes that ratio higher and costs you revenue you would have kept.
What Is Card Not Present Fraud?
Card-not-present fraud is credit card fraud committed with stolen credentials in place of the physical card. No criminal ever touches the plastic. A number, an expiration date, and often a CVV will carry a purchase through online, over the phone, or by mail order.
The scale is documented. The Nilson Report put worldwide payment card fraud losses at $33.41 billion in 2024, with US cards accounting for 41.87% of that total, and Nilson notes that US losses are overwhelmingly card-not-present. Card-absent fraud is one branch of a wider retail fraud problem, and it starts with stolen data. Fraudsters collect those credentials through data breaches, phishing and other social engineering attacks, account takeovers, and dark web marketplaces that sell card records in bulk. Once a set of credentials works, the same details can be reused across dozens of merchants before the cardholder notices anything.
Draw one distinction before going further. A card-not-present transaction is a legitimate payment method, and most retailers run them weekly through phone orders, online ordering, and stored-card billing. Card-not-present fraud is the abuse of that channel. Blame the thin verification inside the channel, not the channel itself.
Card Not Present Fraud vs. Card Present Fraud
Card-present fraud needs a physical card or a counterfeit copy of one. Card-not-present fraud needs nothing but the data. For a retailer, the difference that counts is liability. EMV chip transactions push most counterfeit losses onto the issuer, while card-absent transactions do the reverse and leave the bill with the merchant.
| Factor | Card-present fraud | Card-not-present fraud |
|---|---|---|
| How it happens | Stolen, lost, or counterfeit physical card used in store | Stolen credentials used online, by phone, or by mail |
| What the fraudster needs | The card, or a cloned magstripe | Card number, expiration date, often the CVV |
| How it is detected | Signature mismatch, damaged card, staff suspicion | Order pattern anomalies, velocity spikes, address mismatch |
| Who pays by default | Issuer, when the merchant accepts an EMV chip payment | Merchant |
| Typical dispute code | Visa 10.1, 10.2, 10.3 | Visa 10.4 |
| Primary control | EMV chip acceptance | Authentication, tokenization, order screening |
One note on the codes. Visa separates card-present fraud (10.3) from card-absent fraud (10.4). Mastercard does not, and files both under 4837, No Cardholder Authorization. The older 4863 code for unrecognized transactions has been retired and folded into 4837.
How Card Not Present Fraud Works
Card-not-present fraud follows a predictable five-stage chain, and the lag between the sale and the chargeback is why retailers underestimate it. A fraudulent order can clear checkout, ship, and settle without raising a flag. Weeks later, the loss surfaces.
Stage 1: Credentials are stolen
Fraudsters acquire card data through breaches at retailers and service providers, phishing and smishing campaigns aimed at cardholders, account takeovers of existing customer profiles, and purchases on dark web marketplaces where full records sell cheaply. Most of those breaches trace back to a gap in retail data security at a business that stored more than it needed to.
Stage 2: Credentials are tested
Before spending any money, criminals confirm which cards are still active. They run micro-transactions or automated authorization attempts against checkouts with weak controls. Small independent merchants are the preferred proving ground, as their payment pages tend to lack rate limiting or bot detection.
Stage 3: The purchase is made
Once a card clears a test, the fraudster buys. High-value items, easily resold goods, and gift cards are the usual targets. Orders often involve rush shipping, a shipping address that differs from the billing address, or a newly created customer account.
Stage 4: Goods are redirected or liquidated
Physical items ship to reshipping addresses that cannot be traced back. Gift cards get resold for cash within hours. Digital goods are consumed immediately. By the time anyone reviews the order, the merchandise is gone.
Stage 5: The chargeback lands
Eventually, the genuine cardholder spots the charge and files a chargeback. On both Visa and Mastercard, the issuer has up to 120 calendar days from the transaction processing date to raise a fraud dispute, so the loss can surface four months after the sale. Your window to respond is far shorter: 30 days on Visa, 45 on Mastercard. By then, the store has lost the item, the money, and the cost of moving both.
Who Pays For Card Not Present Fraud?
The merchant pays. In a card-absent environment, the retailer absorbs the loss by default. That means the merchandise, the sale amount, the interchange and processing fees charged on the original transaction, and a dispute fee running $15 to $100 depending on your processor and risk profile. The fee is the smallest line in that list. Once you add the lost merchandise, shipping, and staff time, the all-in cost of a disputed order routinely reaches two to three times the sale price. Nothing about accepting the order transfers that risk.
What does not shift liability
Address Verification Service and CVV checks reduce fraud, but neither one moves financial responsibility. A retailer can pass both checks, ship the order, and still eat the full chargeback. Treat them as screening filters, not as protection. Note as well that PCI DSS flatly prohibits storing the CVV after authorization, so any system holding those digits is a compliance finding waiting to happen.
What does shift liability
Successful 3D Secure authentication is the mechanism that moves fraud liability to the issuer. When a transaction authenticates through Visa Secure or Mastercard Identity Check and carries the correct authentication value and electronic commerce indicator, the issuer generally cannot pursue a fraud-coded chargeback against the merchant.
Three limits apply. The shift covers fraud reason codes and nothing else, primarily Visa 10.4 and Mastercard 4837. Non-fraud disputes stay with the merchant no matter how the payment was authenticated, so a claim about a missing delivery or an item not as described still lands back at the store. And data-only 3DS sharpens issuer decisioning without granting any liability protection.
Friendly fraud complicates the picture
Plenty of fraud-coded disputes involve no criminal at all. First-party fraud, where a legitimate cardholder disputes a purchase they made themselves, arrives under the same reason code as true fraud. Authentication offers no defense, given that the genuine cardholder authenticated. Separating the two is worth the effort, as the right response to each is completely different.
What CNP Fraud Costs Beyond The Chargeback
Card-not-present fraud damages a merchant account, not just a month’s revenue. Visa and Mastercard both run monitoring programs that track your fraud and dispute activity, and a rising ratio invites acquirer scrutiny well before any fine is assessed.
How VAMP changed the math
On April 1, 2025, Visa folded its earlier fraud and dispute programs, including the Visa Dispute Monitoring Program and the Visa Fraud Monitoring Program, into the single Visa Acquirer Monitoring Program. Enforcement began October 1, 2025. VAMP scores fraud and disputes on a single combined metric. Per Visa’s own VAMP fact sheet, the ratio divides the count of fraud reports (TC40) plus disputes (TC15) by the count of settled transactions (TC05), and it looks at card-not-present volume alone.
On April 1, 2026, Visa lowered the merchant “excessive” threshold from 2.20% to 1.50% across the US, Canada, the EU, APAC, and LATAM. Industry sources report an $8 fee per fraudulent or disputed transaction at that tier. Treat the figure as a reference point: Visa publishes ratio thresholds, not fee schedules, and acquirers set their own charges.
Whether the threshold applies to your store
Most independent retailers sit below the assessment floor. Visa measures a merchant against the 1.50% line only once combined fraud and dispute events pass 1,500 in a month, a volume a one-location store will rarely reach. Track the number anyway, for two reasons.
Acquirers are measured on their own portfolio thresholds, set at 0.50% above standard and 0.70% excessive, and those numbers did not change in 2026. A small merchant with a bad ratio drags the portfolio down with it. Acquirers respond with rolling reserves, volume restrictions, repricing, or termination, and a terminated merchant can land on the MATCH list.
MATCH is Mastercard’s database of merchants terminated for cause, but acquirers check it before boarding any new account, regardless of network. A listing runs five years, follows the owners personally and not just the business entity, and can be lifted early by nobody except the acquirer that filed it.
Anyone in that position spends those years working with a high-risk merchant account at considerably worse rates. The threshold is a warning system for your processor relationship long before it is a fee.
Mastercard’s line is the one to watch
Mastercard’s thresholds are far easier for a small retailer to hit than Visa’s. The Excessive Chargeback Merchant tier triggers at 100 to 299 chargebacks paired with a 1.5% to 2.99% ratio, sustained across two months. High Excessive Chargeback Merchant begins at 300 chargebacks and a 3% ratio. Both conditions have to be met, so count and ratio travel together. Fines open around $1,000 and climb steeply at the higher tier.
A separate Excessive Fraud Merchant program covers card-absent fraud specifically and requires four conditions to be met at once, including at least 1,000 CNP transactions in the month and low 3D Secure usage. Mastercard has also announced the Global Merchant Audit Program, which will consolidate these programs and step the ECM ratio threshold down from 1.5% toward 0.9% between 2029 and 2031.
For a store running a few hundred remote orders a month, the takeaway is simple: 100 chargebacks is a much closer line than 1,500, which puts Mastercard ahead of Visa as the constraint that bites first.
One fraud can count twice
One fraudulent transaction can generate both a TC40 fraud report and a TC15 chargeback, and the numerator picks up each of them. Fraud reports register even where the issuer never files a chargeback, so a retailer can watch the ratio climb without a dispute ever landing in the inbox.
Why blocking more orders backfires
Declining suspicious orders aggressively pushes the ratio the wrong way. Settled transactions form the denominator, so each legitimate order you refuse shrinks it while leaving the fraud count above untouched. False declines also cost you revenue outright and send good customers to a competitor for good. Aim to approve more genuine orders while cutting fraud, not to tighten filters until sales drop.
Card testing has its own rule
Visa tracks enumeration separately, at a 20% ratio with a 300,000-transaction floor. Visa also publishes anti-enumeration best practices written for merchants, which is the most direct guidance available on hardening a checkout against this attack. Small retailers will not trip that threshold, though card testing bills them all the same. Based on how your processor prices authorizations, each attempt can carry a fee whether it approves or declines, and a flood of declines drags down your authorization rate. Mastercard research reported in 2026 suggests roughly a third of global ecommerce merchants face active card-testing attacks.
Where Retailers Are Most Exposed
A physical store’s CNP exposure concentrates in four channels, and no two respond to the same control. A liquor store that takes delivery orders faces a different attack surface than a smoke shop that sells gift cards over the counter. Stores that added online ordering to an existing counter operation usually carry the widest spread of the four.
| Channel | How fraud enters | Warning signs | Highest-leverage control |
|---|---|---|---|
| Phone orders | Staff key in stolen credentials with no verification step | Caller rushes, refuses callback, splits payment across cards | Scripted verification and callback to the number on file |
| Online ordering, pickup or delivery | Stolen credentials at an unprotected checkout | Rush delivery, mismatched addresses, new accounts | 3D Secure on flagged orders, rate limiting at checkout |
| Gift card purchases | Stolen cards converted to untraceable value | Bulk purchases, new accounts, repeat same-card buys | Purchase caps, manual review above a set dollar threshold |
| Stored cards and invoiced accounts | Compromised customer profiles reused later | Sudden order size changes, updated shipping details | Tokenization, re-verification after any profile change |
How To Prevent Card Not Present Fraud
Effective CNP fraud prevention layers several controls, and sequence counts, given how widely their impact varies. Authentication and tokenization change your liability position. Screening tools just reduce volume. Start at the top.
1. Authenticate high-risk orders with 3D Secure
3D Secure stands alone on this list as the control that hands fraud liability back to the issuer. Modern 3DS passes device, transaction, and behavioral data upstream for a risk decision, and most authentications finish without troubling the customer. Apply it selectively to high-value orders, new accounts, and address mismatches. Blanketing the whole checkout adds friction that costs conversions.
2. Tokenize stored card data
Tokenization replaces stored card numbers with substitute values that are worthless if stolen. Any retailer keeping cards on file for repeat customers, house accounts, or recurring orders should never store raw card data. Confirm that both your processor and your payment gateway support network tokens, which also improve authorization rates on repeat charges.
3. Rate-limit and gate your checkout
Card testing succeeds when a checkout page accepts unlimited attempts. Cap authorizations per card, per IP address, and per session. Add bot detection or a challenge after repeated failures. Strip detailed decline reasons out of your public-facing error messages, as specific decline codes tell an attacker exactly which field to change next.
4. Verify with AVS and CVV, and know their limits
Require CVV on all card-absent transactions and enable AVS matching on billing addresses. Both filter obvious attempts cheaply. Neither transfers liability, nor does it stop a fraudster holding the full record, billing address included. Set your decline rules for partial AVS matches with care, as overly strict settings can turn away legitimate customers who recently moved.
5. Monitor for suspicious order patterns
Watch for orders that deviate from your normal pattern: multiple orders from a single IP address, multiple cards used on a single account, high-value first-time purchases, shipping addresses that differ from billing addresses, and rush shipping requests. Automated screening catches the obvious cases. Human review catches the unusual ones that rules miss, and a short daily review of flagged orders is realistic even for a small team.
6. Set purchase and velocity limits
Cap the number and total value of transactions allowed per customer, per card, and per day. Velocity limits are the cheapest defense against a fraudster who found a working card and wants to maximize it before detection. Set the caps above your genuine high-water mark so regular customers never hit them.
7. Tighten gift card controls
Gift cards convert a stolen card into untraceable cash faster than anything else you sell, which puts them at the top of the target list. Build the limits into your gift card program instead of leaving them to staff judgment at the counter. Cap how many one customer can buy in a transaction and within a rolling window.
Require manual review above a set dollar threshold. Scrutinize bulk purchases from new accounts, and watch for repeat buys funded by the same card across several visits. A gift card sold on stolen credentials is a total write-off, as the balance is drained long before the chargeback posts.
8. Train staff on phone-order verification
Employees taking phone orders need a script, not general awareness. Fold the script into your regular security awareness training so new hires get it on day one. The script should require the billing address, the CVV, and a callback to the number on the account for any order above a threshold you set.
Staff should also know the pressure tactics: urgency, a refusal to accept a callback, a request to split payment across several cards, and a delivery address the caller changes mid-call. Give them explicit permission to decline an order without needing a manager.
9. Keep systems patched and PCI DSS compliant
Update your ecommerce platform, payment gateway, and point of sale software on a schedule, not when something breaks. The current standard is PCI DSS v4.0.1, and the PCI Security Standards Council made all of its previously future-dated requirements mandatory on March 31, 2025.
Two exist because of card-absent fraud: Requirement 6.4.3 asks you to inventory and authorize each script running on your payment page, and Requirement 11.6.1 asks you to detect unauthorized changes to it. Both target e-skimming, where attackers inject code into a checkout and harvest card details as customers type them.
Choose providers that maintain PCI compliance and ship patches promptly, and remember that the same neglect that opens a checkout to skimming tends to show up in weak POS security at the counter.
What To Do When A CNP Chargeback Arrives
Read the reason code first. The correct response depends entirely on whether the dispute is fraud-coded or service-coded, and treating them the same wastes time on cases you cannot win while losing cases you could.
Fraud codes such as Visa 10.4 and Mastercard 4837 claim the cardholder did not authorize the purchase. If the transaction was authenticated through 3DS, the issuer generally cannot pursue it, and you should respond with your authentication records. If it was not, evaluate whether you have evidence that the legitimate cardholder made the purchase.
Service codes cover delivery, quality, and billing disputes. Authentication offers no protection here. These cases turn on shipping confirmation, delivery signatures, and your published policies.
Three points worth holding onto. Gather evidence at the transaction, not at the dispute, as IP addresses, device data, and delivery confirmations are painful to reconstruct weeks later. Weigh representment costs against the disputed amount: fighting a $40 dispute that eats an hour of staff time rarely pays. Third, know the limits of a win.
Networks count disputes when received, not when resolved, so recovering the money leaves the ratio exactly where it was. A refund issued after filing does not erase it either. Prevention alone moves that number, including disputes deflected through Rapid Dispute Resolution before they post.
How KORONA POS Helps Retailers Manage CNP Risk
KORONA POS is processor-agnostic, so you pick the payment processor whose fraud tooling and pricing suit your business instead of accepting whatever came bundled with your software. KORONA POS is not a payment processor itself. That distinction gives you leverage over the controls that carry the most weight in a card-absent environment: 3DS support, tokenization, and fraud-screening depth.
On the operational side, KORONA POS gives retailers gift card controls to limit how much untraceable value walks out the door, plus detailed transaction reporting that surfaces velocity anomalies and unusual order patterns before they compound. Stores selling across a counter and a remote channel get one reporting view over both, which is where the outliers become obvious.
Speak with a product specialist and learn how KORONA POS can power your business.
Frequently Asked Questions
What is the difference between card present and card not present fraud?
Card-present fraud involves a physical or counterfeit card handed over in person. Card-not-present fraud runs on stolen data alone, through websites, phone lines, and mail orders. Liability separates them: accepting an EMV chip payment moves most card-present losses to the issuer, while card-absent losses sit with the merchant.
Who is liable for card-not-present fraud?
The merchant is liable by default and absorbs the whole stack: the item, the revenue, the fees already paid, and a penalty per dispute. That liability passes to the card issuer in one situation, where 3D Secure has authenticated the payment successfully, and the dispute carries a fraud code. Service and delivery disputes stay with the store whatever the authentication showed.
Does AVS prevent card-not-present fraud?
AVS trims card-not-present fraud without preventing it or moving liability. Address Verification Service compares the billing address a customer types against what the issuer holds on file, catching careless attempts. Anyone who bought the complete card record, billing address included, sails straight through.
What is a normal card-not-present fraud rate?
Visa marks a merchant excessive at a 1.50% combined fraud-and-dispute ratio as of April 2026, though assessment starts above 1,500 combined events monthly. Smaller stores hit Mastercard’s line first, which opens at 100 chargebacks alongside a 1.5% ratio held across two months. Target well under 1%.
How do I know if I am being hit by card testing?
Watch for a sudden spike in attempted transactions, a jump in declines, and repeated tiny or zero-dollar authorizations from one IP address or a rotating set of them. Heavy volume and heavy declines at low amounts, with no customer behavior behind either, points to card testing well ahead of a demand surge.
Can I get a card-not-present chargeback reversed?
Yes, through representment, with your odds set by the reason code and the evidence you hold. Fraud codes on authenticated payments give you the strongest position. Service codes hinge on delivery confirmation and published policies. Capture device data, IP records, and delivery proof as the sale happens, because rebuilding that trail afterward seldom works.
Is CNP fraud the same as friendly fraud?
No. CNP fraud puts a criminal behind stolen credentials. Friendly fraud, or first-party fraud, puts the account holder behind a dispute over a purchase they made themselves. The same reason code can carry both, yet 3D Secure defends against the first alone: in the second scenario, the account holder authenticates without any trouble.








