Insights on Crypto Payments, Infrastructure, and Operations

Card-Not-Present Fraud

Pronunciation: KARD-not-PREZ-unt FRAWD

Definition

Card-Not-Present Fraud is unauthorized use of payment-card credentials in a transaction where the physical card is not read or presented to the merchant, such as online, mobile, mail, or telephone commerce. It differs from card-present fraud because the merchant cannot rely on physical chip or device interaction and must assess remote identity and transaction signals. Controls may include tokenization, strong customer authentication, address and security-code checks where appropriate, device and behavior analysis, velocity limits, risk scoring, and post-transaction dispute monitoring.

Overview

Card-Not-Present Fraud is unauthorized use of payment-card credentials in a transaction where the physical card is not read or presented to the merchant, such as online, mobile, mail, or telephone commerce. The control exists to prevent deceptive or unauthorized transactions, reduce customer and merchant loss, and preserve evidence for recovery, dispute handling, and investigation. It differs from card-present fraud because the merchant cannot rely on physical chip or device interaction and must assess remote identity and transaction signals. It should be interpreted alongside Card-Present Fraud because the concepts can affect the same decision without representing the same control, event, or risk.

The workflow combines identity, device, behavior, communication, beneficiary, transaction, and historical signals before and after payment. High-risk changes or instructions should be verified through a trusted independent channel, and controls should not rely on information supplied inside the potentially compromised message or session. In this context, controls may include tokenization, strong customer authentication, address and security-code checks where appropriate, device and behavior analysis, velocity limits, risk scoring, and post-transaction dispute monitoring.

It should connect the term to Checkout Fraud where that relationship changes access, transaction treatment, investigation, communication, or recovery.

Records should preserve the original request, account and device events, approvals, beneficiary changes, transaction identifiers, communications, authentication results, review notes, and recovery actions. Teams should connect related attempts without exposing unnecessary personal or credential data.

Useful measures include attempted and confirmed loss, prevented value, false-positive rate, review time, recovery rate, beneficiary-change exceptions, customer complaints, repeat attacks, and control-bypass findings.

The relationship with Payment Risk Rule should be documented where it affects residual risk or control ownership.

Key Takeaway

Controls may include tokenization, strong customer authentication, address and security-code checks where appropriate, device and behavior analysis, velocity limits, risk scoring, and post-transaction dispute monitoring.

Sources

  1. PCI Security Standards Document Library — PCI Security Standards Council (2026-08-03)
  2. EMV 3-D Secure — EMVCo (2026-08-03)
  3. Digital Identity Guidelines: Authentication and Authenticator Management, SP 800-63B-4 — NIST (2026-08-03)