Skip to main content
Merchant SupportAgent Login
AMP Payment Systems
Menu

Chargebacks and fraud

What causes card-not-present fraud?

Direct answer

Card-not-present fraud occurs when someone uses payment credentials without presenting the physical card, often after credential theft, phishing, account takeover, malware, data breaches, social engineering, or automated testing of stolen card numbers. Merchant weaknesses—such as poor account security, no velocity controls, weak order review, or unsafe manual practices—can make attempts easier to execute.

Author
AMP Payment Systems
Review status
Primary sources checked; no named AMP subject-matter reviewer is claimed.
Published
Modified

Key facts

  • No single fraud tool catches every attack.
  • Approval does not prove the buyer is authorized.
  • Fraud controls should reflect channel, ticket, product, and fulfillment speed.

Common attack patterns

Criminals may test small transactions, take over customer accounts, redirect delivery, exploit rushed phone orders, or use bots against checkout and gift-card systems. Patterns change quickly.

Layered prevention

Use secure accounts, multifactor authentication, AVS and card-verification responses, velocity rules, device and behavioral signals, manual review, delayed fulfillment where appropriate, and clear escalation steps.

When the answer changes

  • Digital goods and immediate fulfillment reduce recovery time.
  • Overly strict controls can reject legitimate customers.

Common mistakes

  • Treating an authorization code as identity verification.
  • Disabling controls to improve conversion without monitoring loss.

What to verify

  1. Review fraud by channel and root cause.
  2. Test staff response, account security, rules, alerts, and incident contacts.

Primary sources

Apply the answer to your business

AMP can help organize your payment, POS, or statement questions. Any recommendation, availability, pricing, or approval depends on the final written configuration and provider terms.

Contact AMP

Merchant processing options

Tell us how your business accepts payments

Secure request

Draft saved

Do not submit SSNs, full bank account numbers, passwords, or cardholder data. Information is used to respond to your request.