Card-Not-Present Fraud: Prevention, Liability, and Chargeback Evidence

Chargebacks?
No longer your problem.
Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.
TL;DR:
- Card not present (CNP) fraud uses stolen card data to buy online, by phone, or by mail without the physical card.
- It splits into stolen-card (third-party) fraud and first-party friendly fraud, and each needs different evidence to win.
- Visa reason code 10.4 and Mastercard reason code 4837 cover most CNP fraud claims, and Compelling Evidence 3.0 can win Visa 10.4 disputes automatically with matching prior-transaction data.
- Layered defenses, AVS/CVV checks, 3D Secure, real-time risk scoring, and chargeback alerts deflect up to 90% of chargebacks before they post.
- Chargeflow Automation recovers the disputes that still slip through with a 100% submission rate.
Card not present (CNP) fraud occurs when a criminal uses stolen card details to make a purchase without the physical card. This happens typically online, over the phone, or via mail order. Because the merchant can't verify the cardholder in person, CNP transactions carry higher fraud and chargeback risk than in-store payments, though in-person fraud hasn't gone away either: attackers still use EMV bypass cloning techniques to defeat chip-card terminals.
Stop it with layered defenses: real-time identity and behavior scoring, post-purchase review before fulfillment, and proactive chargeback alerts. These deflect disputes before they hit your account.
Quick answer: Card not present fraud happens when someone uses stolen card data to buy online, by phone, or by mail without the physical card present. Stop it with layered defenses, AVS/CVV checks, 3D Secure, real-time risk scoring, and proactive chargeback alerts, that deflect up to 90% of chargebacks before they post.
Card not present fraud is the single biggest threat in eCommerce fraud prevention, and it is getting more expensive every year, as the latest chargeback statistics show. The Federal Reserve's debit card fraud data for 2023 puts card-not-present fraud at 54.3% of all debit card fraud losses, with merchants absorbing 49.9% of those losses, more than issuers and cardholders combined. When a shopper checks out online, you never see the card. You see data. That gap is exactly what fraudsters exploit, whether they are using stolen card numbers or filing false disputes after a legitimate delivery.
This guide breaks down what CNP fraud is, how it happens, and the warning signs. It covers the layered defenses that protect your revenue, the reason codes that show up on the resulting chargebacks, and the evidence that keeps you out of card network monitoring programs.
What Is Card Not Present Fraud?
Card not present fraud is any unauthorized or deceptive transaction made using card credentials instead of the physical card itself. It sits inside the broader category of chargeback fraud, but it specifically targets the moment a card cannot be physically presented: online checkout, phone orders, in-app purchases, and subscriptions, where you cannot dip a chip or verify a signature. Restaurants taking phone and online orders face the same exposure, driving a rise in restaurant chargebacks.
The core problem is verification. In a store, the card, the chip, and often the cardholder are all physically present. Online, you're trusting a string of numbers: the card number, expiration date, CVV, and billing address.
If a criminal has those details, bought on the dark web, phished, or skimmed, they can transact as if they were the cardholder.
Card-Present vs Card-Not-Present Fraud
The table below shows why the same stolen card costs a merchant far more online than in a store: liability, methods, reason codes, and defenses all differ.
| Factor | Card-present fraud | Card-not-present fraud |
|---|---|---|
| Where it happens | In-store terminals, ATMs, unattended kiosks | Online checkout, phone and mail orders, in-app purchases, recurring billing |
| Who bears the fraud loss | The issuer, once the merchant runs an EMV chip transaction (the 2015 liability shift) | The merchant, unless 3D Secure authentication completes and shifts liability to the issuer |
| Common methods | Counterfeit or cloned cards, lost or stolen cards, EMV bypass at the terminal | Stolen card data from breaches and phishing, card testing, account takeover, triangulation fraud |
| Typical chargeback reason codes | Visa 10.1 (EMV liability shift), Mastercard 4870 (chip liability shift) | Visa 10.4, Mastercard 4837, Amex F29, Discover UA02 |
| Primary defenses | EMV chip and PIN, contactless limits, staff training on ID checks | AVS and CVV, 3D Secure 2, device and IP risk scoring, velocity rules, post-purchase review, chargeback alerts |
CNP fraud splits into two main categories that demand different defenses:
- Third-party fraud: A criminal uses stolen card data to place an order; you lose the chargeback and goods.
- First-party (friendly) fraud: A customer receives goods, then disputes the charge anyway, claiming non-delivery or non-recognition.
For fast-growing brands, subscription businesses, and marketplaces, both types stack up fast. Chargeflow Insights centralizes every dispute across your processors into one dashboard. You can see which transactions are stolen-card fraud versus friendly fraud, the first step to stopping both.
How Does Card Not Present Fraud Actually Happen?
CNP fraud starts with stolen card data and ends with a chargeback on your account. Criminals obtain credentials through data breaches, phishing, malware, skimming, and dark-web marketplaces, then test and cash out those cards on eCommerce sites.
Here's the typical attack lifecycle:
- Data theft. Card details are stolen via a breach, a phishing email, a fake checkout page, or malware that captures keystrokes.
- Card testing. Fraudsters run small transactions to confirm which stolen cards are still active, often a flood of low-value orders in minutes.
- The fraudulent purchase. Once a card is validated, the criminal places a real order, often shipping high-resale-value goods to a reshipping address.
- The chargeback. The cardholder disputes the charge, and you lose merchandise, shipping, the transaction amount, and a fee.
Friendly fraud follows a different path. The customer genuinely orders, receives the item, then contacts their bank instead of you, because a refund feels faster, or because they are abusing your policies. Either way, the dispute lands on your account and counts against your chargeback ratio.
Subscription and SaaS businesses face a unique version: recurring billing disputes. A customer forgets they signed up, doesn't recognize the descriptor, and files a chargeback rather than canceling. Clear billing descriptors and InquiryAutomation (part of Chargeflow Automation) resolve pre-dispute inquiries on platforms like PayPal, Klarna, and Afterpay before they escalate to a claim.
What Are the Warning Signs of Card Not Present Fraud?
The clearest red flags are mismatched data, abnormal order behavior, and rushed high-value purchases. Spotting these patterns early lets you cancel or verify risky orders before you ship, which is far cheaper than fighting a chargeback after the fact.
Watch for these signals at and after checkout:
- Mismatched billing and shipping addresses, especially when shipping to a freight forwarder or known reshipping hub.
- Multiple declined attempts followed by a success: classic card testing behavior.
- Unusually large orders or bulk quantities of high-resale items from a brand-new customer.
- Rush shipping requests on first-time orders, designed to get goods out the door before the fraud is caught.
- Email, device, or IP mismatches: a disposable email, a VPN-masked IP, or a device fingerprint linked to prior fraud.
- Velocity spikes: the same card, device, or IP hitting your store repeatedly in a short window.
The hard truth: many of these signals look fine in isolation. A rushed large order from a new customer can be a perfectly good sale. That's why rule-based, pre-authorization tools alone produce false positives that block real revenue.
Chargeflow Prevent scores each transaction after authorization but before fulfillment, using device, IP, email, and payment-behavior intelligence from a global network of 15,000+ merchants. It automatically cancels, verifies, or approves orders based on your rules, catching the digital shoplifters without depressing your approval rate.
How Do You Prevent Card Not Present Fraud?
You prevent card not present fraud with layered defenses as part of a broader chargeback mitigation strategy. No single check is enough. Combine data-validation tools at checkout, behavioral and identity intelligence after authorization, and chargeback alerts that deflect disputes before they post, the core building blocks of any chargeback fraud prevention program.
Start with the foundational checks every merchant should enable:
- Address Verification Service (AVS): Confirms the billing address matches the card issuer's records.
- CVV verification: Requires the security code, which isn't stored in most breached datasets.
- 3D Secure (Visa Secure, Mastercard Identity Check): Adds issuer-side authentication and can shift liability for fraud chargebacks to the bank.
- PCI DSS compliance: Protects stored and transmitted card data, reducing your breach exposure.
Only 3D Secure creates a card network liability shift for unauthorized-use fraud, and only when authentication completes successfully. The protocol is maintained by EMVCo, whose EMV 3-D Secure specification is built to "prevent card-not-present (CNP) fraud" by exchanging authentication data between the merchant and the issuer, so most transactions are approved without a challenge and only higher-risk ones step up. AVS and CVV checks reduce risk but do not shift liability on their own, and none of these checks protect you from friendly fraud disputes filed by the actual cardholder after a legitimate delivery.
These basics stop unsophisticated attacks but miss friendly fraud and coordinated fraud rings entirely. Layer on intelligence-driven prevention:
- Real-time risk scoring that weighs device fingerprint, IP reputation, email age, and behavioral signals together rather than one rule at a time.
- A cross-merchant network that flags actors already caught defrauding other stores, because fraud rings reuse identities.
- Post-purchase review that holds risky orders for verification before they ship, eliminating the loss on goods and the dispute.
- Proactive chargeback alerts that catch disputes in the pre-chargeback window and let you refund within 24 hours to avoid a formal chargeback and its fee.
| Defense Layer | What It Does | What It Stops |
|---|---|---|
| Address Verification Service (AVS) | Confirms the billing address matches the card issuer's records. | Basic stolen-card transactions. |
| CVV Verification | Requires the card security code, which isn't stored in most breached datasets. | Card testing and low-effort fraud. |
| 3D Secure (Visa Secure, Mastercard Identity Check) | Adds issuer-side authentication at checkout. | Unauthorized charges, and shifts fraud liability to the bank. |
| PCI DSS Compliance | Protects stored and transmitted card data. | Data breaches and downstream fraud exposure. |
| Real-Time Risk Scoring | Weighs device fingerprint, IP reputation, email age, and behavior together. | Sophisticated and coordinated fraud attempts. |
| Cross-Merchant Network | Flags actors already caught defrauding other stores. | Repeat abusers and organized fraud rings. |
| Post-Purchase Review | Holds risky orders for verification before fulfillment. | Loss of goods and the resulting dispute. |
| Proactive Chargeback Alerts | Catches disputes in the pre-chargeback window, letting you refund within 24 hours. | Formal chargebacks and their fees. |
This is where the Chargeflow stack delivers. Chargeflow Alerts aggregates Verifi, Ethoca, Visa, Mastercard, and the Chargeflow Network to deflect up to 90% of chargebacks before they hit your account. It keeps your dispute ratio safely below card network thresholds, including Visa's Acquirer Monitoring Program (VAMP), which lowered its "Excessive" merchant threshold to 1.5% of combined fraud-and-dispute transactions effective April 2026.
Prevent blocks the fraudulent orders. And the disputes that still slip through? Chargeflow Automation recovers them on autopilot with an average 300% increase in win rate and a 4X ROI guarantee.
You pay 25% only on what is recovered, no long contracts, no setup fees.
Activate Alerts and Prevent today.
How Do You Recover Revenue After a CNP Chargeback?
When a chargeback gets through your defenses, you recover revenue by submitting compliant, evidence-backed dispute responses fast, at scale. Manual chargeback management cannot keep up with high transaction volumes, and missed deadlines mean automatic losses.
Winning a CNP dispute comes down to evidence quality and submission speed. Card networks want proof tied to their specific requirements.
Compelling Evidence 3.0 for Visa lets you submit prior transaction history to prove the cardholder authorized the purchase. Assembling that evidence by hand for every chargeback is slow, error-prone, and unscalable for a growing brand.
Chargeflow Automation handles the entire lifecycle for you:
- Detects new chargebacks directly from your processors in real time.
- Collects and enriches 1,000+ data points per dispute automatically.
- Assembles personalized, card-scheme-compliant evidence, including Compelling Evidence 3.0.
- Submits every response on time with a 100% submission rate, no missed deadlines.
- Predicts outcomes with ChargeScore™ win-probability so you know where you stand.
For payment platforms, payment service providers, and marketplaces, Chargeflow Connect embeds this entire engine: Automation, Alerts, Insights, and Prevent, white-labeled into your product. Offer chargeback protection to your own merchants across 45+ PSPs. The result across the platform: $200M+ in revenue recovered and 20,000+ merchants protected.
Which Reason Codes Show Up on Card Not Present Disputes?
Card networks tag every CNP dispute with a reason code, and the code determines which evidence actually wins the case. The two you will see most often: Visa reason code 10.4, "Other Fraud, Card-Absent Environment," for stolen-card claims, and Mastercard reason code 4837, "No Cardholder Authorization," the card-absent equivalent. Both require proof the transaction was authorized by the genuine cardholder, not just proof that goods shipped.
| Network and reason code | Description | Response window | Evidence that wins |
|---|---|---|---|
| Visa 10.4 | Other Fraud, Card-Absent Environment | Up to 30 days for the acquirer; most processors give merchants less | Compelling Evidence 3.0 prior-transaction match, Visa Secure authentication record, AVS and CVV2 match, proof of refund |
| Mastercard 4837 | No Cardholder Authorization | 45 days from the chargeback date | Identity Check (3DS) authentication, prior undisputed transactions on the same account, AVS match, delivery to the verified address |
| Amex F29 | Card Not Present | 20 days from the chargeback notice | Proof of delivery to the cardholder's billing address, CID verification response, shipping address matched to prior undisputed orders |
| Discover UA02 | Fraud: Card Not Present Transaction | 30 days from the chargeback notice | AVS and CVV match, signed delivery confirmation, IP address and email tied to the cardholder for digital goods |
Compelling Evidence 3.0 exists specifically for Visa 10.4 disputes: submit two prior undisputed transactions from the same cardholder, matched on at least two of four data points (account ID, shipping address, IP address, or device ID, with at least one being IP address or device ID), and the liability shift is automatic. Reason codes tied to delivery and description ("Not as Described," "Not Received") fall under friendly fraud rather than CNP fraud, and need delivery and tracking evidence instead of authentication history.
Feed dispute outcomes back into your prevention rules. A reason code that keeps repeating on the same SKU, shipping region, or customer segment shows you where your pre-authorization controls are still leaking, closing the loop between recovery and prevention.
Stop Card Not Present Fraud With Layered Defenses
Card not present fraud is not a single problem with a single fix: it is stolen-card attacks and friendly fraud hitting your account from every channel. Beating it requires a layered defense plus automated recovery. Stop the fraudulent orders before fulfillment, deflect disputes before they post, and recover the chargebacks that slip through, all on autopilot.
With Chargeflow's Prevent, Alerts, Automation, and Insights working together, you cut chargebacks by up to 90% and win more disputes. Stay out of card network monitoring programs. Start for free.
Frequently Asked Questions
What is the difference between card present and card not present fraud?
Card present fraud requires the physical card at the point of sale. Card not present fraud uses only stolen card data in remote channels like online, phone, or mail orders.
CNP transactions are far more vulnerable because chip-and-PIN and signature verification aren't available to confirm the real cardholder is making the purchase. That's why CNP is now the leading source of fraud and chargebacks for eCommerce businesses.
Who is liable for card not present fraud: the merchant or the bank?
In most cases, the merchant absorbs the loss for card not present fraud, including the disputed amount, the shipped goods, and a chargeback fee. Using 3D Secure can shift fraud liability to the card issuer on authenticated transactions.
It doesn't cover friendly fraud where a real customer disputes a legitimate order. Layered prevention and automated dispute recovery are how you protect your bottom line against both scenarios.
Can you win chargebacks caused by card not present fraud?
Yes, you can win CNP chargebacks, especially friendly fraud cases, by submitting strong, card-scheme-compliant evidence before the deadline. Evidence like delivery confirmation, IP and device matches, prior transaction history, and Compelling Evidence 3.0 data can prove the cardholder authorized and received the purchase. Chargeflow Automation builds and submits this evidence automatically, delivering an average 300% increase in win rate with a 4X ROI guarantee.
How fast can you deploy CNP fraud protection?
You can deploy Chargeflow Alerts in under 24 hours with one-click integrations into 100+ eCommerce, payment, and support platforms. Prevent starts with your first 1,000 scanned transactions free and no minimums, while Automation works on success-based pricing: you pay 25% only on recovered chargebacks. There are no long-term contracts or setup fees, so you can protect your revenue almost immediately.
How do card-not-present chargebacks work?
A card-not-present chargeback starts when the cardholder tells their issuer they did not authorize an online, phone, or mail-order charge. The issuer reverses the transaction, debits your acquirer, and codes the dispute as fraud (Visa 10.4, Mastercard 4837, Amex F29, or Discover UA02). You then have roughly 20 to 45 days, depending on the network and your processor, to accept the loss or submit evidence that the genuine cardholder authorized the purchase. Win, and the funds return; lose, and you absorb the sale, the goods, and the chargeback fee, and the case still counts toward your dispute ratio.
Can threat intelligence prevent card-not-present (CNP) fraud?
Yes. Threat intelligence, meaning real-time device, IP, email, and behavioral signals cross-referenced against a shared merchant network, catches both stolen-card fraud and repeat abusers that rule-based checks miss. Chargeflow Prevent scores every transaction after authorization but before fulfillment using intelligence from 15,000+ merchants, cancelling or verifying risky orders without hurting your approval rate.
Score every card-not-present transaction after authorization but before fulfillment. See how Chargeflow Prevent works.

Chargebacks?
No longer your problem.
Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.














.png)
.webp)

.webp)