SardineCon SF/2026

Learn More
Card & payment fraud4 min de lectura

¿Qué es Card-not-present (CNP) fraud?

SUBSCRIBE

Card-not-present fraud is fraud where the physical card is never read, as in online, in-app, or phone orders, and the criminal only needs the card number, expiry, security code, and billing details. Since chip cards made in-person fraud hard, this is now the main channel for card fraud.

What is CNP fraud, in plain English?

Card-not-present fraud is exactly what it sounds like: fraud on a transaction where no physical card is presented or read. That covers online checkouts, in-app purchases, and phone or mail orders. Without a card to swipe, dip, or tap, the payment is authorized on data alone: the card number, expiry date, security code, and billing details.

That is the whole vulnerability. If a criminal has those details, from a breach, phishing, skimming, or a carding shop, they can transact as if they held the card. There is no chip to defeat and no clerk to check a signature, because the entire trust model rests on knowing the numbers. This makes stolen card data directly usable in the CNP channel.

CNP has become the dominant form of card fraud in chip-enabled markets. When chip cards made counterfeit in-person fraud difficult, criminals shifted to where the card never appears. That is why the tools for fighting it are all about verifying the buyer indirectly: address and security-code checks, 3DS authentication, and device and behavior signals.

CNP versus card-present fraud

What changes

Card-present

Card-not-present

Card needed

Physical card, chip, or stripe.

Only the card details, no card.

Main defense

Chip (EMV) cryptography.

AVS, security code, 3DS, device signals.

Typical loss owner

Least chip-compliant party.

Merchant, unless 3DS authenticated.

Trend

Fell sharply after chip rollout.

Now the dominant fraud channel.

Who is involved?

Who

Their role

The fraudster

Holds stolen card details and uses them in online, in-app, or phone orders.

The merchant

Accepts the remote payment and usually eats the chargeback unless the payment was authenticated.

The issuer

Authorizes the transaction on data and offers authentication tools like 3DS to shift liability.

The cardholder

The genuine owner whose details were stolen and who disputes the unauthorized charge.

What it looks like in practice

In practice

An online electronics store gets a rush of orders for the same high-demand laptop. Each order uses a different card but shares a pattern: a brand-new guest account, a billing address that does not match the shipping address, and delivery to a package-forwarding depot. The same device fingerprint appears across several of them.

None of the cards are declined, because the details are all valid, stolen data used in a card-not-present flow. The store ships before the pattern is spotted. Two weeks later the genuine cardholders dispute the charges, and because the payments were never authenticated through 3DS, the store absorbs the chargebacks. The mismatch, the new accounts, and the shared device were the signals it could have caught up front.

Why it dominates card fraud now

The shift is a direct consequence of chip. As EMV made in-person counterfeit fraud hard and expensive, criminals moved to the channel where the card is never seen and stolen data still works. Every breach, phishing kit, and skimmer now feeds a channel where the numbers alone are enough, so CNP became the path of least resistance.

For merchants, the sting is liability. In CNP, the merchant generally owns the loss unless the payment was authenticated through 3DS, which can shift chargeback liability to the issuer. That makes detection an economic priority, not just a security one. Because there is no card to verify, defense leans on indirect signals: address and security-code matching, 3DS on risky payments, and device and behavioral analysis to tell a genuine buyer from a fraudster with the right numbers.

What to watch in the data

  • Billing and shipping mismatch. Deliveries to an address unrelated to the card's billing details are a core CNP tell.
  • New device or account. First-time guest checkouts or fresh accounts paired with high-value orders.
  • Package-forwarding drops. Shipping to reshipper or freight-forwarding addresses used to obscure the destination.
  • Card velocity across merchants. The same card hitting many merchants fast, a sign of tested stolen data being cashed out.
  • AVS and CVV mismatches. Address or security-code results that do not fully match, especially on high-resale goods.

Quick questions

Why is CNP fraud so common now?

Chip cards made in-person counterfeit fraud hard, so criminals shifted to remote channels where the card is never read and stolen details still work. Every data breach and skimmer feeds this channel, making it the dominant form of card fraud.

Who pays for CNP fraud?

Usually the merchant, through a chargeback, unless the payment was authenticated with 3DS, which can shift liability to the issuer. That liability exposure is why CNP detection is an economic priority for merchants.

How do you fight it without a physical card?

With indirect verification: address verification, the security code, 3DS authentication on risky payments, and device and behavioral signals. The goal is to confirm the buyer is genuine even though no card is present to check.

Does a valid security code mean the buyer is genuine?

No. Security codes are frequently stolen alongside card numbers in breaches and phishing. Treat a match as one positive signal among many, not as proof, and weigh it against mismatched addresses, new devices, and shipping anomalies.

How is CNP different from card-present fraud?

Card-present fraud needs a physical counterfeit, lost, or stolen card at a terminal and is now rare in chip markets. CNP needs only the card details for a remote order and is far more common, with different defenses and liability rules.

Go deeper

Qué saber junto con Card-not-present (CNP) fraud