Clean Fraud

Clean fraud is a card-not-present transaction made with stolen payment details that passes every automated check a merchant runs. The card number is valid, the CVV is correct, the billing address matches, and the order looks ordinary. Nothing about it is flagged, because on the fields the system examines there is nothing to flag.

The name describes the transaction, not the crime. It is fraud that arrives clean.

Also called Clean transaction fraud, undetectable fraud
Channel Card-not-present — ecommerce, phone and in-app orders
What makes it clean Correct CVV, matching AVS, plausible device and behavior
Source data Full identity records purchased as fullz
Who absorbs the loss The merchant, via chargeback and fees
Where it is catchable Identity and account layer, not the transaction layer

How clean fraud works

An ordinary stolen card number fails quickly. The billing address is unknown, the CVV is a guess, and the address verification service returns a mismatch that pushes the order into review. Most rule-based systems stop that transaction without a human ever seeing it.

Clean fraud starts from better inputs. The attacker buys a complete identity record rather than a card number — name, address, date of birth, card number, expiry, CVV, and often the email and phone attached to the account. With the full record, the fields a merchant checks all agree, because they were all taken from the same real person.

Everything after that is presentation. A residential proxy places the order in the cardholder’s own region. A clean browser profile avoids the device signals that flag an obvious attempt. The basket is unremarkable in size and content. The order ships to an address the attacker controls — or, when the merchant blocks address mismatches, to the cardholder’s own address, where the goods are intercepted before delivery.

None of this is technically sophisticated. It is the ordinary result of a market where stolen identity records are sold by the thousand, and it is why carding economics matter more than attacker skill.

Why it matters for identity verification

Clean fraud is the part of card fraud that transaction-level checks cannot reach, and the reason is definitional rather than technical. CVV and AVS answer one question: does the person placing this order hold the card’s details? In clean fraud the answer is yes. The check works correctly and returns the wrong conclusion, because possessing the details is exactly what the attacker bought.

Adding more transaction checks does not close this. Each new field the attacker can also copy becomes another field that agrees. The gap is not the number of signals; it is that all of them are drawn from data the attacker holds.

What the attacker does not hold is the cardholder. A control that asks the person to present themselves — a document plus a matched selfie at account creation, or a risk-based step-up at the point of a high-risk order — asks a question that stolen data cannot answer. It is also the reason clean fraud concentrates on guest checkouts and newly created accounts, where no such moment has happened.

Clean fraud compared with adjacent terms

Clean fraud Friendly fraud Card testing
Who placed the order A criminal The real cardholder A criminal
Card details Stolen Legitimately held Stolen, often unverified
Passes CVV and AVS Yes Yes Often no
Visible at checkout No No Yes — volume and decline rate
Resolved by Identity evidence Dispute representment Rate and velocity limits

The three are frequently reported together under one fraud figure, which is why merchant and issuer numbers diverge. A chargeback reason code does not say whether the person who placed the order was the cardholder, so first-party misuse and criminal fraud arrive in the same bucket.

What clean fraud detection cannot do

It cannot be solved at the transaction. By the time an order is scored, every attribute available has already been supplied by the attacker. Scoring harder produces more false declines against real customers rather than more catches.

Velocity rules miss the patient version. One order per identity, spread across merchants, generates no velocity signal anywhere. The pattern only exists in aggregate, which no single merchant can see.

A verified cardholder can still dispute. Identity verification establishes who is transacting. It does not prevent a genuine customer from later claiming they did not receive the goods, which is a different problem with a different remedy.

Frequently asked questions

Is clean fraud the same as friendly fraud?

No. Clean fraud is committed by a criminal using stolen details; friendly fraud is committed by the real cardholder disputing their own purchase. Both pass automated checks, which is why they are often counted together, but they need opposite responses — one needs identity evidence, the other needs transaction evidence.

Why do CVV and AVS fail against clean fraud?

Because they test whether the person has the card’s details, and the attacker does. Both checks return a correct result. The limitation is the question they ask, not the accuracy of the answer.

Which merchants see the most clean fraud?

Those selling high-resale goods with fast or digital fulfillment, and those that allow guest checkout. Short time between order and delivery leaves less room for the cardholder to notice the charge, and guest checkout removes the account-creation moment where identity could have been established.

Can machine learning detect clean fraud?

It helps at the margins by finding patterns across many transactions that no rule expresses — unusual combinations of device, timing and basket. It does not resolve the core issue, because a model trained on transaction attributes is still reading attributes the attacker controls.

Related reading

  • Card-not-present fraud — the broader category clean fraud sits inside
  • Chargeback — the reversal mechanism that delivers the loss to the merchant
  • Triangulation fraud — a scheme where stolen cards buy goods for an unwitting real customer
  • Fullz — the complete identity records that make a transaction look clean

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data