Card Not Present Fraud (CNP)

Card-not-present (CNP) fraud is any fraudulent transaction where the physical card is never presented — online, in-app, or over the phone. It is the category that absorbed most card fraud after EMV chip adoption made counterfeiting cards at the terminal impractical.

What defines it The card is not physically present at the point of sale
Channels Ecommerce, in-app purchases, mail order, telephone order
What the fraudster needs Card number, expiry, CVV — and often nothing else
Why it grew EMV chip made card-present counterfeiting impractical; volume moved online
Data sources Breaches, phishing, skimming, card testing
Card testing Small transactions run to check which stolen numbers are still live
Liability Generally the merchant’s, through chargebacks
Principal controls 3-D Secure, tokenization, device and behavioral signals, address verification
The real cost False declines, which frequently exceed fraud losses

How it works

CNP fraud needs remarkably little. A card number, an expiry date, a CVV — sometimes a billing postcode. All of it is data, all of it circulates after breaches, and none of it proves the person entering it holds the card.

Card testing is the step most merchants underestimate. Before using stolen numbers at scale, a fraudster runs small transactions to find which are still live — often on charities, small merchants, or any site with a low-value payment form and weak rate limiting. A merchant seeing a surge of tiny authorizations is being used as a test bed, and the fraud lands somewhere else.

The controls each address a different part of the problem. 3-D Secure shifts liability to the issuer and adds an authentication step, at some cost to conversion. Tokenization replaces the card number with a token that is useless if stolen. Address verification checks billing details, which helps and is defeated by any data package containing an address. Device and behavioral signals assess whether this session resembles the legitimate cardholder.

The cost that gets least attention is false declines — legitimate transactions blocked by fraud rules. For many merchants these exceed actual fraud losses, and unlike fraud they carry a long tail: a customer wrongly declined at checkout often does not return, and that loss never appears in a fraud report.

Why it matters for identity verification

CNP fraud is a payment problem with an identity problem underneath it, and the two are usually managed by different teams.

Payment controls assess the instrument: is this card valid, is this transaction consistent with its history, does the billing address match. They do not assess the person. A fraudster with a complete stolen data package satisfies every instrument-level check because the instrument really is valid — it simply is not theirs.

The gap shows up hardest on high-value orders and on new accounts, where there is no transaction history to compare against. That is where verifying the person rather than the payment method changes the outcome: a step-up check confirming the buyer holds a genuine government document matching their face is something a stolen card number cannot satisfy.

Capturing the card and reading fraud signals at the point of entry closes part of it — distinguishing a card physically present from a number typed from a list. Microblink’s payment fraud workflow combines that with document and biometric checks so the escalation path is a verification rather than a decline.

Card-present vs card-not-present fraud

  Card-present Card-not-present
Card at point of sale Yes, physically No
Primary method Counterfeit, lost or stolen card Stolen card data used remotely
Effect of EMV chip Substantially reduced it Displaced volume into this channel
Liability Generally the issuer, where EMV was used Generally the merchant
Detection signals Terminal, location, chip data Device, behavior, velocity, address
Recourse Chargeback Chargeback, and usually merchant loss
Countered by Chip and PIN 3-D Secure, tokenization, identity verification

The liability row is why CNP fraud is a merchant problem in a way card-present fraud is not. EMV moved both the fraud and the cost.

What it can’t be solved by

Declining more. Tightening rules cuts fraud and cuts revenue, usually faster. False declines carry a customer-lifetime cost that fraud reporting never captures.

CVV checks alone. The CVV proves whoever is paying had access to the card’s data, not the card. Any breach or phishing package containing the CVV defeats it entirely.

Address verification alone. AVS checks billing details against issuer records. A complete stolen identity package includes the address, so it filters careless fraud and nothing more.

3-D Secure on its own. It shifts liability rather than preventing fraud, and adds an authentication step that costs conversion. Useful as part of a stack, and it does not make the transaction legitimate — it makes the loss someone else’s.

Frequently asked questions

What is card-not-present fraud?

A fraudulent transaction where the physical card is never presented — online, in-app, or over the phone. The fraudster needs only the card data, which circulates widely after breaches.

Why did CNP fraud increase after EMV chip cards?

EMV made counterfeiting cards for use at terminals impractical, so fraud moved to the channel where no physical card is required. The total did not fall as much as card-present fraud did — it relocated.

Who pays for card-not-present fraud?

Generally the merchant, through chargebacks, unless liability was shifted via 3-D Secure. This is the reverse of card-present fraud under EMV, where the issuer typically bears it.

What is card testing?

Running small transactions with stolen card numbers to find which are still active before using them at scale. Merchants with low-value payment forms and weak rate limiting are frequently used as the test bed, with the real fraud committed elsewhere.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data