Announcing our New Developer Hub
Announcing our New Developer Hub
Announcing our New Developer Hub
Announcing our New Developer Hub
/
Fraud Prevention
July 12, 2026
Sep 8, 2026

Card-Not-Present Fraud: Prevention, Liability, and Chargeback Evidence

White circular logo with interlocking shapes at the center surrounded by overlapping orbit-like elliptical lines and scattered blue diamond shapes.

Chargebacks?
No longer your problem.

Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.

600+ reviews
No credit card needed.

TL;DR:

  • Separate unauthorized card-not-present payments from service and billing disputes.
  • Combine account security, payment authentication, and contextual order review.
  • Check transaction-specific liability treatment instead of assuming universal 3D Secure protection.
  • Measure legitimate customer impact alongside fraud prevention and recovery outcomes.
Loading the Elevenlabs Text to Speech AudioNative Player...

Card-not-present fraud is unauthorized use of payment credentials in a transaction where the card is not physically presented to the merchant, such as an online or telephone purchase. Prevention combines payment authentication, account security, transaction review, and controls before fulfillment.

Card-not-present describes the payment channel, not every reason a customer might dispute a purchase. A missing delivery, duplicate charge, or canceled subscription can produce a dispute without stolen-card fraud. Keep unauthorized payments separate from service problems and first-party misuse when analyzing losses.

Understand the Main Card-Not-Present Fraud Paths

PatternWhat HappensUseful Control
Stolen payment credentialsSomeone uses another person’s card detailsRisk-based authentication and transaction review
Account takeoverAn intruder purchases through a compromised accountAccount security, sensitive-action verification, session controls
Card testingAutomated attempts check whether credentials workRate limits, bot controls, monitoring of attempt patterns
TriangulationA fraudulent seller uses stolen credentials to fulfill another buyer’s orderReview connected order and payment signals before shipment
First-party misuseA buyer disputes a purchase they authorizedClear records and claim-specific investigation

First-party misuse belongs in your broader dispute strategy, but should not be counted automatically as stolen-card fraud. The payment fraud guide helps separate payment abuse from billing and fulfillment errors that require different fixes.

Use Signals Together Instead of Treating Them as Proof

Review unusual payment attempts, abrupt changes in order value, account changes, delivery redirection, and repeated failures in context. A new device or different shipping address can be legitimate. Gifts, travel, and shared households make rigid single-signal rules prone to blocking good customers.

Compare each signal with the transaction and account history. A sudden burst of attempts followed by an expensive order warrants a different response from an established customer sending a gift. Document the reason for manual review so support can explain delays without exposing internal fraud thresholds.

Investigate account takeover when a familiar account behaves unusually. A long customer history is useful context, but it does not make a compromised session safe. Likewise, triangulation fraud can involve an innocent delivery recipient who did not place the order directly with your store.

Layer Controls Across the Payment Journey

  • At account access, use secure authentication and protect recovery flows.
  • At checkout, apply supported payment verification and risk-based authentication.
  • Across repeated attempts, monitor velocity and automated abuse.
  • Before fulfillment, review material changes to the order or delivery destination.
  • After purchase, resolve customer confusion and investigate reported unauthorized activity.

The OWASP authentication guidance supports account protections such as multifactor authentication and reauthentication for sensitive actions. These controls complement payment checks; a successful login and a card authorization answer different questions.

Protect the payment data itself. The PCI Security Standards Council guidance on card verification codes states that these codes must not be stored after authorization. Preserve the permitted verification result through your provider, not the security code as a future evidence attachment.

Understand What Authentication Does and Does Not Cover

Authentication can affect liability for eligible fraud disputes, but treatment depends on the specific transaction and rules. Check the recorded outcome, eligibility, and any exceptions. Do not describe all 3D Secure attempts, exemptions, or frictionless payments as carrying identical protection.

Merchants using Stripe can review its 3D Secure authentication flow to understand the relevant transaction states. Authentication does not establish that goods arrived, a service matched its description, or a cancellation was handled correctly.

Keep fulfillment controls proportionate to the remaining risk. A post-authorization review can be useful before goods leave the warehouse, but your team needs an exception process for legitimate customers. Measure declined good orders and review delays alongside fraud losses when adjusting rules.

Respond to a CNP Dispute Based on the Claim

Read the chargeback reason code and check the case deadline. If the payment was genuinely unauthorized, a delivery record alone may not support a challenge. Evaluate the facts and applicable liability treatment instead of responding automatically to every case with proof of shipment.

For a supported response, connect the transaction, relevant authentication result, customer communication, and claim-specific records. Follow the evidence standardization workflow to create a readable packet. Explain what each record establishes and avoid unsupported statements about customer intent.

If the claim concerns nonreceipt or a service problem, investigate that issue directly. If a refund was already issued, reconcile its status before taking another financial action. The appropriate response may be to resolve a valid complaint rather than defend an incorrect charge.

Measure Prevention and Recovery Separately

Track attempted fraud, confirmed unauthorized payments, service-related disputes, response completion, and net recovered value as distinct measures. A prevention rule that blocks many legitimate buyers can reduce dispute counts while harming the business. Compare similar channels and customer groups before expanding a rule.

Use the multi-account dispute reporting workflow to keep definitions consistent across processors. Review payment approvals, fulfillment holds, refunds, and disputes together so that movement in one metric does not conceal a problem elsewhere.

Chargeflow supports a broader payment-risk workflow through post-purchase prevention, supported alerts, automated recovery, and analytics. Select the capability that addresses your observed gap and confirm integration coverage. No individual tool removes the need for accurate fulfillment and accessible customer support.

Frequently Asked Questions

Is every card-not-present chargeback fraud?

No. Card-not-present chargebacks can concern unauthorized payments, nonreceipt, cancellation, duplicate processing, or other issues. The payment channel does not establish the cause of the dispute.

Does 3D Secure prevent every CNP chargeback?

3D Secure can affect liability for eligible fraud disputes, but does not prevent every chargeback or resolve service and delivery complaints. Check the actual authentication result and applicable conditions.

Does delivery prove a CNP payment was authorized?

Delivery can support fulfillment, but does not independently prove that the cardholder authorized the payment. Unauthorized-payment claims need an assessment of payment and account evidence.

You can organize evidence and manage supported responses with Chargeflow’s automated chargeback recovery.

SHARE THIS ARTICLE
White circular logo with interlocking shapes at the center surrounded by overlapping orbit-like elliptical lines and scattered blue diamond shapes.

Chargebacks?
No longer your problem.

Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.

600+ reviews
No credit card needed.
subscribe

The latest chargebacks, fraud, and ecommerce content, in your inbox. Every week.

Sign up now and never miss out the latest trends!
By providing your email you're agreeing to our Terms of Service and Privacy Notice
Diagram with dashed and curved lines forming segmented arcs highlighted by three blue diamond markers on the left side.Abstract circular grid design with blue diamond markers on a half-black, half-white background.