Card Not Present Fraud: What It Is
No card, no reader, no way to see the buyer. Card not present fraud is the risk every online checkout carries, and here are the layers that reduce it.
The buyer is a name, a shipping address, and a card number. You never see the card. That is the whole problem.
What card not present fraud is
A payment is fraudulent when the cardholder did not authorize it. Most fraudulent payments are made using stolen cards or card numbers. In a card not present transaction, nobody taps, inserts or swipes anything. The buyer types a number into your checkout. The card itself can be far away.
That is why it is called card not present fraud. The card itself is absent. Only its details are there. For a fuller card not present fraud definition, the core idea is simple. The payment goes through, the goods ship, and the real cardholder never made the purchase.
Why it is harder to detect online
Online fraud is harder to detect than fraud at brick-and-mortar businesses. It is harder to be sure who the buyer is. In a store, the card is in hand. A chip, a PIN, a face. At your checkout, every signal is a piece of typed text that could belong to anyone.
A fraudster with a stolen card number needs only what your form asks for. There is no physical card to inspect and no person to look at. So the checks you run have to make up for that missing card, and no single check makes up for all of it.
How a fraudulent sale becomes a chargeback
The fraudster gets the order. The real cardholder sees a charge they never made. Once the cardholder spots the fraudulent use of their card, they dispute the payment with the card issuer. The disputed payment can then come back to you as a chargeback.
EMV 3-D Secure: the issuer checks the buyer
EMV 3DS is an e-commerce fraud prevention protocol. It checks that buyers are real for card-not-present purchases. It does this without adding needless friction to checkout. It works by moving part of the checking to the bank that issued the card.
EMV 3DS sends data between merchant and issuer. The issuer uses it to check the buyer and approve the payment. The issuer looks at what you send and decides whether it trusts the buyer. For higher-risk transactions, issuers may ask for more. This can be a one-time passcode, security questions, or biometrics. EMV 3DS also meets Strong Customer Authentication rules. It does so through two-factor authentication. For the fullest feature set, EMVCo advises using version 2.2 or newer.
Visa pioneered the original 3-D Secure protocol. It added a layer of identity checks before authorization. Visa then worked with other payment brands to build the next generation, EMV 3-D Secure.
Friction and the data-only flow
Visa's data shows a big gap. Authenticated eCommerce transactions have about 45% less fraud than non-authenticated ones. Visa also reports a 9% lift in approval rates for payments checked through Visa Secure.
Visa Secure supports a data-only mode for low-risk payments. Transaction details go to the issuer with no direct customer interaction. The buyer is not asked to do anything more. Issuers may ask for more on higher-risk payments. For a deeper look, see EMV 3D Secure.
CVC and AVS: what they catch, what they miss
The CVC is the three- or four-digit number printed directly on a card. A failed CVC or postal code check can indicate the payment is fraudulent. But CVC checks do not protect against the physical theft of a card. Businesses cannot store the CVC number.
AVS is a widely used fraud-prevention measure for card not present transactions. It compares the billing address the buyer typed with the address the bank has on file. But AVS checks can fail for legitimate payments. Treat both checks as signals to read, not verdicts to obey.
What to collect on every payment
Collect the CVC, postal code, and billing address for every payment. Every time, no exceptions. A check cannot compare anything if the field was left blank, and a skipped check is a hole in your fraud review. These fields give the checks something to compare.
Where to go next
Checks and authentication reduce the risk, but they do not remove it. Some stolen cards pass every check you run. For spotting the ones that slip through, start with card not present fraud detection. To put the full set of measures in place, see card not present fraud prevention.