Fraud prevention and security

What is card-present fraud?

Card-present fraud is unauthorized payment activity associated with an in-person transaction where a card or payment device is presented at a physical point of sale. The transaction may involve a chip, contactless tap, or magnetic-stripe read. The label describes the acceptance channel; it does not prove who used the payment method or explain how the credentials were obtained.

A person might attempt card-present fraud with a lost or stolen card, a counterfeit card, or payment information captured through a compromised device. Merchants should use the transaction method, authorization response, staff observations, and approved system signals together rather than treating any single detail as proof of fraud.

How card-present fraud differs from remote fraud

Card-present transactions occur at a physical point of interaction, while card-not-present transactions occur when the physical card is not presented, such as many ecommerce or phone orders. The distinction matters because the checkout evidence and available safeguards differ by channel. An in-person workflow may use a chip, contactless credential, or magnetic stripe and may allow staff to observe the payment device and customer interaction.

Card-present does not mean risk-free. A stolen card may be used before the cardholder reports it, counterfeit credentials may be attempted through a magnetic stripe, and a tampered reader may expose payment data. At the same time, an unusual customer interaction or a declined payment is not automatically fraudulent. Staff need a consistent process that protects customers and avoids improvisation.

Common ways the risk can appear

Lost or stolen payment methods

An unauthorized person may try to use a physical card or payment-enabled device before the legitimate owner notices the loss or disables it. The merchant should follow the response shown by the payment system and its documented store procedure.

Counterfeit card attempts

Stolen account data may be encoded onto another card's magnetic stripe. EMV chip transactions use transaction-specific security data that helps address counterfeit use, but merchants should not describe any acceptance method as eliminating fraud.

Payment-device tampering

A criminal may alter, replace, or attach equipment to a reader to capture payment data. Changes to seals, cables, housings, serial numbers, or device behavior deserve prompt review under the merchant's established device-security process.

What authorization does and does not mean

An authorization response is the issuer's decision on the transaction request based on the information available at that moment. Approval is important, but it is not a promise that the person presenting the payment method is the authorized cardholder or that the transaction cannot later be disputed. A decline also does not prove fraud.

Merchants should process the payment using the method prompted by their approved terminal and follow the exact response displayed by their payment provider. If the transaction or customer interaction appears suspicious, staff should use a documented escalation path instead of inventing extra verification steps or overriding system instructions.

A practical store review process

Use the expected acceptance flow

Let the approved terminal guide chip, tap, or swipe handling. Do not force a different method merely because it seems faster, and do not bypass a response or prompt that requires staff action.

Train for consistent escalation

Give employees a clear contact and a safe way to pause a transaction when something appears wrong. The procedure should prioritize staff and customer safety and should reflect the provider's current instructions.

Protect payment devices

Maintain an inventory of readers, record identifying details, limit unsupervised access, and compare devices with known photographs or records. If a terminal appears altered, stop using it and contact the appropriate vendor or payment provider through a verified channel.

Document operational facts

Record the transaction time, terminal, response, and actions taken according to the business's normal retention process. Do not copy complete account numbers, security codes, PINs, passwords, or secret keys into general notes.

Questions merchants can ask about the checkout setup

  • Which payment methods should each terminal support, and what is the normal customer flow?
  • How should employees respond to fallback prompts, declines, or unusual terminal messages?
  • Who can install, replace, repair, or move payment devices?
  • How are terminal serial numbers, locations, cables, seals, and condition recorded?
  • What verified support channel should staff use if a device appears altered?
  • How are incidents escalated without collecting sensitive payment details through email or a general form?

Answers depend on the merchant's approved equipment, payment provider, operating environment, and internal procedures. Feature availability and response steps should be confirmed with the organizations that actually support the merchant's setup.

Related fraud-prevention guidance

Build a layered process

Review practical ways a business can reduce credit card fraud without relying on a single signal.

Review address signals

See how AVS works and why a match or mismatch should be interpreted with other information.

Choose the next operational step

Start by mapping every physical payment device, its normal transaction flow, and the person responsible for reviewing unusual activity. Confirm the current operating and escalation instructions with the merchant's actual payment provider and device vendor before changing a live checkout process.

Payments Max can help merchants organize payment-workflow questions and evaluation criteria. It does not replace provider instructions, incident-response support, or a business's own security advisors.

Privacy reminder: Never submit cardholder data, PINs, passwords, bank credentials, complete account numbers, or secret API keys through a general inquiry form.

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US