Credit Card Fraud

Credit card fraud is the unauthorized use of a credit card or card number to obtain money, goods or services. It divides into two families that share a name and almost nothing else: fraud on an existing account, where a real cardholder’s details are misused, and new account fraud, where a card is opened in someone else’s name or in a name that belongs to nobody. The second is an identity problem wearing a payments label.

Two broad families Existing account misuse, and new account fraud
Existing account methods Stolen card numbers, card-not-present transactions, account takeover, skimming
New account methods Stolen identity applications, synthetic identities, bust-out schemes
Dominant channel Card-not-present, following the shift to chip at the point of sale
Primary data source Breached credential sets, sold as complete packages
Reporting (U.S.) The FTC logs credit card fraud within its identity theft categories, where it is consistently the largest
Merchant exposure Chargebacks, fees, and the cost of goods already shipped
Control point for new account fraud Identity verification at application

How it works

Existing account fraud starts with data the fraudster did not have to earn. Card numbers circulate from breaches, skimmers, phishing and malware, and they are sold in bundles alongside the cardholder’s name, address, date of birth and often the security code — the package known as fullz. Possession of that bundle defeats most of the checks built to confirm a legitimate cardholder, because those checks ask for exactly the information the bundle contains.

The migration to chip cards at physical terminals worked. It made counterfeiting a card for in-person use difficult enough that the activity moved rather than stopped, into card-not-present fraud where no chip can be read and the merchant has only data to judge by. That is the structural reason online fraud rose as in-store fraud fell.

New account fraud runs on different rails. Rather than misuse an existing card, the fraudster applies for one — using a stolen identity, or a synthetic identity assembled from real and fabricated elements. The account is genuine from the issuer’s perspective. It behaves well, accumulates limit, and then goes bad in a single window, a pattern called bust-out. Losses land as credit losses rather than as fraud losses, which is one reason this category is persistently understated.

Why credit card fraud matters for identity verification

The two families need different defenses, and treating them as one problem is the common failure.

Existing account fraud is a transaction problem. It is fought with velocity rules, device signals, behavioral models, 3-D Secure, and the card checks that run inside authorization — address verification and the security code. Those controls examine a transaction and decide whether to let it through.

New account fraud is an identity problem, and no transaction control reaches it. By the time the account transacts it is a legitimate account. The only point at which the fraud is visible is the application, where the question is whether a real, correctly identified person is applying. That is document verification with authentication, biometric comparison to bind the document to the applicant, and checks for the signals that distinguish a fabricated identity from a thin-file real one.

For issuers this changes where effort should sit. Tightening transaction controls does nothing about accounts that were fraudulent before their first purchase. Payment card capture with fraud signals addresses the transaction side, and payment fraud controls work best when the identity established at application is solid enough that the behavioral baseline means something.

The two families compared

Existing account fraud New account fraud
Whose account A real cardholder’s Opened by the fraudster
Detected by Transaction monitoring, velocity, device and behavioral signals Identity verification at application
Victim Cardholder and issuer or merchant The issuer, and any real person whose identity was used
Loss classification Fraud loss Often booked as credit loss, understating the fraud
Typical detection lag Days Months

What fraud controls can’t do

Card checks do not identify anyone. The security code and billing address confirm possession of data, and that data is in circulation. They filter casual attempts and no more.

Transaction monitoring cannot see fraud that predates the transaction. A synthetic account behaving normally is indistinguishable from a real one, because the behavior is real.

Chargeback data lags badly. Disputes surface weeks or months later, so a merchant reading chargebacks is measuring a decision made long ago.

Blocking harder costs real revenue. False declines are a large and under-measured cost, and a control tuned only against fraud rate will be tuned wrong.

Frequently asked questions

What is the difference between credit card fraud and identity theft?

They overlap. Misusing an existing card number is credit card fraud but not necessarily identity theft. Opening a new card in someone else’s name is both. The distinction matters because the two are prevented at different points — one at the transaction, the other at the application.

Why did card fraud move online?

Chip cards made counterfeiting a card for in-person use difficult, so the activity shifted to channels where no chip can be read. In card-not-present transactions the merchant judges by data alone, and the necessary data is widely available from breaches.

What is a bust-out?

An account, often opened with a synthetic identity, that behaves impeccably for months to build credit limit and trust, then maxes every available line in a short window and is abandoned. Because the account looked healthy, the loss is frequently recorded as a credit loss rather than as fraud.

Can transaction monitoring stop new account fraud?

Not on its own. Once an account exists, its activity is genuine activity by the person who opened it, so there is nothing anomalous to detect. New account fraud is prevented at the application, by verifying that a real and correctly identified person is applying.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data