

Every online sale you accept without swiping a card carries a hidden risk. Card-not-present fraud is now the largest category of payment fraud in ecommerce, and it keeps growing as more spending moves online. If you sell digital goods, subscriptions, or physical products through a website or app, this is your fraud problem.
Recent industry reports estimate that CNP fraud accounts for the majority of card fraud losses worldwide, with billions of dollars lost every year. Merchants absorb most of that hit through chargebacks, refunds, lost goods, and higher processing costs. The stakes keep rising as attackers get smarter and faster.
The good news: prevention has caught up. Merchants who layer the right tools and processes can cut CNP fraud dramatically without adding friction that scares off real customers. Here’s what you need to know.
Card-not-present fraud is any fraudulent transaction where a card isn’t physically present at checkout. That covers online purchases, mobile orders, phone orders, and mail orders, essentially every non-face-to-face payment channel.
Because the merchant can’t inspect the card, verify the customer’s ID, or check a signature, the fraudster only needs the card number, expiry, and often a CVV. That data is easy to obtain on dark-web marketplaces after a data breach, phishing attack, or malware infection. Once purchased, criminals test stolen cards on small transactions, then move to larger orders once they know the card works.
Three forces are pushing CNP fraud up in 2026.
First, ecommerce keeps expanding. More digital transactions mean more targets and a wider attack surface. Card networks have also pulled back on in-store fraud vectors thanks to chip cards, so criminals have shifted online where controls are weaker.
Second, data breaches keep feeding the pipeline. Every stolen credential batch gives fraudsters more cards to test. Recent research indicates card-testing attacks have spiked in the last 12 months, with automated bots hammering merchant checkouts to validate stolen numbers.
Third, generative AI is lowering the barrier for attackers. Fraud rings now use AI to craft convincing phishing emails, build synthetic identity documents, and mimic legitimate shopping behavior to slip past rule-based detection. According to industry chargeback data published in 2026, merchants relying only on static rules are falling behind.
There’s no single tool that stops CNP fraud. Layered defense wins. The tactics below cover different attack vectors and work best together.
Even the best prevention lets some fraud through. When a customer disputes a CNP transaction, the burden of proof lands on you. Miss deadlines, submit weak evidence, or exceed the card networks’ chargeback ratio thresholds, and you risk fines, higher processing fees, or losing your merchant account.
That’s where dispute management and representment matter. Automated dispute tools pull the right evidence (delivery confirmation, IP logs, prior order history, 3DS2 authentication data) and file responses on time. For deeper tactics on responding to disputes and winning representment cases, our chargeback representment guide walks through the full playbook.
Card-not-present fraud isn’t slowing down, but the tools to fight it have never been stronger. Layer 3DS2, device fingerprinting, velocity checks, and smart fraud scoring, and prepare a fast dispute-response workflow for the fraud that gets through. Do both well and CNP fraud stops being a growth killer for your business.
