Fraud prevention and security

What is card-not-present fraud?

Card-not-present fraud is the unauthorized use of payment credentials when the physical card is not presented to the merchant. It can affect ecommerce orders, phone orders, mail orders, invoices, payment links, and other remote payment flows. The label describes the transaction setting; it does not mean every remote order is fraudulent or that a single warning sign proves misuse.

How card-not-present fraud happens

A remote checkout generally relies on information entered or transmitted without an employee physically examining the card. A fraudster may try credentials obtained through phishing, malware, a data breach, account takeover, or card-testing activity. The merchant, payment provider, and card issuer then evaluate the information available for the transaction.

Legitimate customers also shop remotely, ship gifts, travel, use new devices, or enter information incorrectly. That is why merchants should evaluate several signals together and avoid treating one mismatch as automatic proof of fraud. A proportionate review process can help distinguish unusual but legitimate purchases from activity that deserves more scrutiny.

Common warning signs to review

Order and customer signals

  • An unusually large order from a new customer
  • Several rapid attempts using different card details
  • Contact information that appears incomplete or inconsistent
  • A request to change shipping details after the order

Account and access signals

  • A login from an unexpected device or region
  • Recent password, email, or delivery-address changes
  • Repeated failed verification attempts
  • Activity that differs sharply from the customer's normal pattern

These are review prompts, not a universal decision rule. The relevance of each signal depends on the merchant's products, fulfillment model, customer history, payment provider, and the information returned with the transaction.

Authorization is not the same as confirming the buyer

An authorization response indicates that the issuer evaluated the submitted transaction and returned a result. It should not be treated as a guarantee that the person placing the order is the authorized cardholder or that the transaction cannot later be disputed. Merchants should understand which verification and risk signals their checkout actually collects, how those signals are presented, and what their provider recommends when information is unavailable or inconsistent.

Similarly, a decline does not prove fraud. Issuers may decline legitimate transactions for many reasons. Clear customer communication and a documented review path help staff respond consistently without exposing sensitive account information.

Practical controls for remote payments

  • Protect merchant accounts. Use unique credentials, limit administrative access, and enable the strongest multifactor authentication available for dashboards, email, and other systems connected to payment operations.
  • Use layered transaction review. Consider the verification, authentication, velocity, device, customer-history, and fulfillment signals supported by the selected payment setup. Availability and behavior vary by provider.
  • Set measured review rules. Route genuinely unusual orders for manual review instead of relying only on a single automatic threshold. Record why an order was approved, held, canceled, or escalated.
  • Train staff on escalation. Give employees a defined way to pause fulfillment and contact the appropriate internal owner or payment provider when an order looks suspicious.
  • Monitor repeated attempts. A burst of low-value or failed attempts can indicate account testing. Review the related guide on account testing fraud.

No control eliminates fraud, and adding too much friction can inconvenience legitimate customers. A merchant should tune controls to its transaction patterns, fulfillment risk, and provider capabilities, then review outcomes over time.

What to do with a suspicious order

Pause fulfillment when the available facts justify review. Check the order against the merchant's documented procedures, preserve relevant records, and use a known support channel to ask the payment provider what transaction signals are available. Do not ask a customer to send a full card number, security code, password, bank credential, or secret API key through email or a general contact form.

If the concern involves compromised systems or stolen business credentials, restrict affected access, involve the appropriate security owner, and follow the organization's incident-response process. For broader planning, see ways a business can reduce credit card fraud and the fraud prevention and security FAQ hub.

Card-not-present fraud and disputes

Fraud and disputes overlap, but they are not interchangeable. A customer may dispute a charge for reasons unrelated to stolen credentials, while a fraudulent order may be detected before fulfillment and never become a dispute. Merchants benefit from keeping accurate order, customer-communication, delivery, refund, and review records according to their provider's procedures and applicable retention requirements.

Businesses building a remote-payment workflow can also review the ecommerce and online payments FAQ hub to connect fraud controls with checkout, gateway, and customer-experience decisions.

Choose a next step based on the payment flow

Map where remote orders enter the business, which employees and systems can access them, what verification signals are available, and when fulfillment can be paused. Then discuss any gaps with the payment provider or qualified security advisor before changing live rules. Payments Max can help merchants organize questions for a payment-processing evaluation, but the final controls and responses depend on the merchant's provider, systems, risk profile, and operating procedures.

Privacy reminder: Never submit cardholder data, passwords, bank credentials, complete account numbers, or secret API keys through a general inquiry form.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US