SardineCon SF/2026

Learn More
Card & payment fraud4 min de lectura

¿Qué es Card-present (CP) fraud?

SUBSCRIBE

Card-present fraud is fraud at a physical checkout using a counterfeit, lost, or stolen card. It matters less than it used to in chip markets, but it still bleeds through weak spots like magstripe fallback and older terminals that never read a chip.

What is card-present fraud, in plain English?

Card-present fraud happens at a physical point of sale, where a card is actually presented to a terminal or ATM. The fraudster uses a counterfeit card cloned from stolen data, or a real card that was lost or stolen, to buy goods or withdraw cash in person. The defining feature is the physical interaction: a swipe, dip, or tap at a machine.

In markets that adopted chip cards (EMV), this channel shrank dramatically. The chip generates a unique code per transaction, so a counterfeit card built from copied magnetic-stripe data cannot satisfy a proper chip read. That closed the door on the mass counterfeiting that once drove card-present losses, and pushed most fraud to card-not-present channels instead.

But it did not vanish. Card-present fraud now survives in the gaps: magstripe fallback when a chip supposedly fails, magstripe-only and unattended terminals, and regions where chip adoption is patchy. It is far rarer than online fraud where chips are in use, but the weak spots are real and worth watching.

Card-present versus card-not-present

What changes

Card-not-present

Card-present

Where it happens

Online, in-app, phone orders.

Physical terminal or ATM.

What the fraudster uses

Stolen card details only.

Counterfeit, lost, or stolen physical card.

Main weak spot

Data reuse from breaches.

Magstripe fallback, old terminals.

Prevalence in chip markets

Dominant channel.

Now far rarer.

Who is involved?

Who

Their role

The fraudster

Presents a counterfeit, lost, or stolen card at a physical terminal or ATM.

The merchant or ATM operator

Accepts the card. Liability often falls on whichever party is least chip-compliant.

The issuer

Authorizes the transaction and, depending on chip compliance, may bear the loss.

The cardholder

The genuine owner whose card or data was used, who disputes the in-person charge.

What it looks like in practice

In practice

A cardholder buys lunch downtown at noon. Ninety minutes later, his card is used to swipe several purchases at a convenience store in another state, each time as a magstripe fallback after the chip supposedly would not read. The store has an older terminal that accepts the swipe without much resistance.

His issuer's monitoring flags two things at once: the geography is impossible for one person in that time, and the transactions all downgraded to magstripe on a card that is chip-capable. Both point to a counterfeit card built from skimmed data being used at a weak terminal. The card is blocked mid-spree, but the pattern, fallback plus impossible location, is the classic card-present fraud signature.

Why chip pushed it to the margins

Chip cryptography broke the economics of card-present fraud. When every genuine chip transaction carries a one-time code that a cloned magstripe cannot reproduce, mass counterfeiting stops paying off. The result was a sharp fall in card-present losses in chip markets and a corresponding surge online, where the card is never read and data alone suffices.

What remains concentrates in the downgrade paths. The tells operators watch are magstripe fallback, stripe-only or unattended terminals, and swipes far from the cardholder's usual area, with a location that is impossible given recent activity being an especially strong signal. Liability usually falls on whichever party is least chip-compliant, which is why merchants and issuers both have a stake in closing fallback and retiring old terminals. It is closely related to cloning, skimming, and shimming, the techniques that supply the counterfeit cards.

What to watch in the data

  • Magstripe fallback. Swipes accepted after a claimed chip failure, especially repeatedly, can signal deliberate downgrade to a cloneable path.
  • Impossible geography. A card used in a location the genuine holder could not physically reach given the timing of their last transaction.
  • Stripe-only or unattended terminals. Activity at older machines, self-service pumps, or ATMs that do not enforce chip.
  • Out-of-area swipes. In-person use far from the cardholder's normal spending footprint.
  • Common point of purchase. Clusters of card-present fraud whose victims all used the same skimmed terminal earlier.

Quick questions

Is card-present fraud still a real threat?

It is much rarer in chip-enabled markets but not gone. It persists through magstripe fallback, stripe-only and unattended terminals, and regions with uneven chip adoption. Where chips are enforced, online fraud vastly outweighs it.

How did chip cards reduce it?

The chip produces a unique cryptographic code for each transaction, which a counterfeit card built from copied magstripe data cannot reproduce. That broke mass counterfeiting and pushed most fraud to card-not-present channels.

What is magstripe fallback and why does it matter?

Fallback is when a terminal accepts a swipe because a chip read supposedly failed. Fraudsters exploit it to use cloned magstripe data on chip-capable cards, so repeated fallback is a key warning sign.

Who is liable for card-present fraud?

Liability generally lands on whichever party is least chip-compliant. If a merchant accepts a swipe on a chip card at a non-compliant terminal, they are more likely to bear the loss, which incentivizes upgrading hardware.

What is the strongest single signal?

Geographic impossibility. A physical transaction in a place the cardholder could not have reached in the elapsed time strongly indicates a counterfeit or stolen card in use, often alongside magstripe fallback.

Go deeper

Qué saber junto con Card-present (CP) fraud