Insights on Crypto Payments, Infrastructure, and Operations

Card-Present Fraud

Pronunciation: KARD-PREZ-unt FRAWD

Definition

Card-Present Fraud is unauthorized or deceptive use of a payment card or payment device in a transaction where it is physically presented to a terminal or acceptance device. It differs from card-not-present fraud because chip, contactless, terminal, fallback, and merchant-location evidence can influence authorization and liability. Controls should protect terminals, prefer secure chip or contactless methods, restrict fallback, monitor counterfeit and lost-card patterns, train staff, reconcile terminal activity, and investigate unusual reversals, refunds, and merchant behavior.

Overview

Card-Present Fraud is unauthorized or deceptive use of a payment card or payment device in a transaction where it is physically presented to a terminal or acceptance device. The control exists to prevent deceptive or unauthorized transactions, reduce customer and merchant loss, and preserve evidence for recovery, dispute handling, and investigation. It differs from card-not-present fraud because chip, contactless, terminal, fallback, and merchant-location evidence can influence authorization and liability. It should be interpreted alongside Card-Not-Present Fraud because the concepts can affect the same decision without representing the same control, event, or risk.

The workflow combines identity, device, behavior, communication, beneficiary, transaction, and historical signals before and after payment. High-risk changes or instructions should be verified through a trusted independent channel, and controls should not rely on information supplied inside the potentially compromised message or session. In this context, controls should protect terminals, prefer secure chip or contactless methods, restrict fallback, monitor counterfeit and lost-card patterns, train staff, reconcile terminal activity, and investigate unusual reversals, refunds, and merchant behavior.

It should connect the term to Payment Originator where that relationship changes access, transaction treatment, investigation, communication, or recovery.

Records should preserve the original request, account and device events, approvals, beneficiary changes, transaction identifiers, communications, authentication results, review notes, and recovery actions. Teams should connect related attempts without exposing unnecessary personal or credential data.

Useful measures include attempted and confirmed loss, prevented value, false-positive rate, review time, recovery rate, beneficiary-change exceptions, customer complaints, repeat attacks, and control-bypass findings.

The relationship with Payment Risk Rule Set should be documented where it affects residual risk or control ownership.

Key Takeaway

Controls should protect terminals, prefer secure chip or contactless methods, restrict fallback, monitor counterfeit and lost-card patterns, train staff, reconcile terminal activity, and investigate unusual reversals, refunds, and merchant behavior.

Sources

  1. PCI Security Standards Document Library — PCI Security Standards Council (2026-08-03)
  2. EMV 3-D Secure — EMVCo (2026-08-03)
  3. NIST Cybersecurity Framework 2.0 — NIST (2026-08-03)