Chargebacks and fraud
What causes card-not-present fraud?
Direct answer
Card-not-present fraud occurs when someone uses payment credentials without presenting the physical card, often after credential theft, phishing, account takeover, malware, data breaches, social engineering, or automated testing of stolen card numbers. Merchant weaknesses—such as poor account security, no velocity controls, weak order review, or unsafe manual practices—can make attempts easier to execute.
- Author
- AMP Payment Systems
- Review status
- Primary sources checked; no named AMP subject-matter reviewer is claimed.
- Published
- Modified
Key facts
- No single fraud tool catches every attack.
- Approval does not prove the buyer is authorized.
- Fraud controls should reflect channel, ticket, product, and fulfillment speed.
Common attack patterns
Criminals may test small transactions, take over customer accounts, redirect delivery, exploit rushed phone orders, or use bots against checkout and gift-card systems. Patterns change quickly.
Layered prevention
Use secure accounts, multifactor authentication, AVS and card-verification responses, velocity rules, device and behavioral signals, manual review, delayed fulfillment where appropriate, and clear escalation steps.
When the answer changes
- Digital goods and immediate fulfillment reduce recovery time.
- Overly strict controls can reject legitimate customers.
Common mistakes
- Treating an authorization code as identity verification.
- Disabling controls to improve conversion without monitoring loss.
What to verify
- Review fraud by channel and root cause.
- Test staff response, account security, rules, alerts, and incident contacts.
Primary sources
- Protecting Personal Information: A Guide for BusinessFederal Trade Commission
- Visa Core Rules and Product and Service RulesVisa
Apply the answer to your business
AMP can help organize your payment, POS, or statement questions. Any recommendation, availability, pricing, or approval depends on the final written configuration and provider terms.
Contact AMP