Card-Not-Present Fraud: How Merchants Can Fight Back in 2026
11 mins
Card-not-present fraud

TL;DR / Key Takeaways

  • Card-not-present (CNP) fraud happens when a stolen card is used for an online, phone, or mail-order transaction where the physical card isn’t verified.
  • Global CNP fraud losses continue to climb faster than in-store fraud, driven by data breaches, phishing, and AI-generated attacks.
  • Prevention leans on layered defenses: 3D Secure, device fingerprinting, address verification, velocity checks, and behavioral signals.
  • Chargebacks from CNP fraud hurt margins, ratios, and processor relationships. Fighting back requires both prevention and strong dispute handling.

The State of Card-Not-Present Fraud in 2026

Every online sale you accept without swiping a card carries a hidden risk. Card-not-present fraud is now the largest category of payment fraud in ecommerce, and it keeps growing as more spending moves online. If you sell digital goods, subscriptions, or physical products through a website or app, this is your fraud problem.

Recent industry reports estimate that CNP fraud accounts for the majority of card fraud losses worldwide, with billions of dollars lost every year. Merchants absorb most of that hit through chargebacks, refunds, lost goods, and higher processing costs. The stakes keep rising as attackers get smarter and faster.

The good news: prevention has caught up. Merchants who layer the right tools and processes can cut CNP fraud dramatically without adding friction that scares off real customers. Here’s what you need to know.

What Is Card-Not-Present Fraud?

Card-not-present fraud is any fraudulent transaction where a card isn’t physically present at checkout. That covers online purchases, mobile orders, phone orders, and mail orders, essentially every non-face-to-face payment channel.

Because the merchant can’t inspect the card, verify the customer’s ID, or check a signature, the fraudster only needs the card number, expiry, and often a CVV. That data is easy to obtain on dark-web marketplaces after a data breach, phishing attack, or malware infection. Once purchased, criminals test stolen cards on small transactions, then move to larger orders once they know the card works.

Why Card-Not-Present Fraud Is Growing?

Three forces are pushing CNP fraud up in 2026.

First, ecommerce keeps expanding. More digital transactions mean more targets and a wider attack surface. Card networks have also pulled back on in-store fraud vectors thanks to chip cards, so criminals have shifted online where controls are weaker.

Second, data breaches keep feeding the pipeline. Every stolen credential batch gives fraudsters more cards to test. Recent research indicates card-testing attacks have spiked in the last 12 months, with automated bots hammering merchant checkouts to validate stolen numbers.

Third, generative AI is lowering the barrier for attackers. Fraud rings now use AI to craft convincing phishing emails, build synthetic identity documents, and mimic legitimate shopping behavior to slip past rule-based detection. According to industry chargeback data published in 2026, merchants relying only on static rules are falling behind.

How to Prevent Card-Not-Present Fraud?

There’s no single tool that stops CNP fraud. Layered defense wins. The tactics below cover different attack vectors and work best together.

  1. Enforce 3D Secure 2 (3DS2) on high-risk transactions. It shifts chargeback liability to the issuer on authenticated payments and blocks many stolen-card attempts. Modern 3DS2 flows are near-invisible for low-risk customers, so friction stays minimal.
  2. Use Address Verification Service (AVS) and CVV checks on every transaction. Failed AVS or CVV should trigger manual review or an automatic decline on high-risk orders.
  3. Add device fingerprinting and behavioral biometrics. These tools flag when the same device is trying multiple cards, or when typing patterns and mouse movements look automated instead of human.
  4. Set velocity limits. Cap the number of transactions from a single card, IP, email, or device in a short window. Card testers rely on speed, so tight limits break their model.
  5. Screen risky signals. Mismatched billing and shipping countries, disposable email domains, VPN or proxy usage, and orders placed in unusual overnight patterns all deserve extra scrutiny.
  6. Run machine-learning fraud scoring. Modern fraud engines learn from your transaction history and flag anomalies faster and more accurately than any static rule set.

Handling the Chargebacks That Slip Through

Even the best prevention lets some fraud through. When a customer disputes a CNP transaction, the burden of proof lands on you. Miss deadlines, submit weak evidence, or exceed the card networks’ chargeback ratio thresholds, and you risk fines, higher processing fees, or losing your merchant account.

That’s where dispute management and representment matter. Automated dispute tools pull the right evidence (delivery confirmation, IP logs, prior order history, 3DS2 authentication data) and file responses on time.  For deeper tactics on responding to disputes and winning representment cases, our chargeback representment guide walks through the full playbook.

Conclusion

Card-not-present fraud isn’t slowing down, but the tools to fight it have never been stronger. Layer 3DS2, device fingerprinting, velocity checks, and smart fraud scoring, and prepare a fast dispute-response workflow for the fraud that gets through. Do both well and CNP fraud stops being a growth killer for your business.