Gift-card fraud is the theft or abuse of stored-value cards, whether by buying them with stolen payment data, draining balances off physical cards, or tricking victims into handing over the codes. The card acts as near-cash that is fast, hard to trace, and easy to resell, which is exactly why fraudsters and money launderers reach for it.
What is gift-card fraud?
Gift-card fraud covers any scheme that turns a stored-value card into stolen value. It shows up in three broad shapes: buying cards with stolen card data so the fraud converts to clean-looking merchandise, draining or cracking the balances off cards that belong to someone else, and reselling the resulting codes on secondary markets for cash.
The reason gift cards attract fraud is simple. A gift card is near-cash: once the code is captured, value moves instantly, there is no chargeback to the fraudster, and the trail is far shorter than a bank transfer. That makes it a favorite endpoint for card testing, account takeover, and scam payouts, and a common vehicle for moving value across borders.
For a fraud or AML team, gift cards sit at the cash-out edge of many schemes. They are where stolen credentials and stolen card numbers get converted into spendable value, which means a spike in gift-card activity is often the visible tail of an attack that started somewhere else.
How a gift-card scheme unfolds
A common cracking-and-resale pattern runs like this, from harvesting numbers to cashing out:
- HarvestGet card numbers or codes Fraudsters buy leaked card data, guess gift-card numbers with bots, or steal codes through takeover and phishing.
- LoadBuy or fund cards Stolen payment credentials buy new gift cards, or bots check balances on existing ones to find loaded cards.
- DrainMove the value off Balances are spent, transferred to a wallet, or captured before the real owner notices the funds are gone.
- Cash outResell for clean money Codes are sold at a discount on secondary marketplaces, converting the fraud into cash with little trace.
Who is involved?
Who | Their role |
The fraudster | Sources stolen data or codes, runs the bots, and buys, drains, or resells the cards. |
The victim | A cardholder whose payment data was stolen, or a gift-card owner whose balance is drained before they spend it. |
The retailer or issuer | Sells and honors the cards, absorbs disputed purchases, and sees the balance-check and redemption patterns. |
The resale marketplace | The secondary site where discounted codes are dumped for cash, wittingly or not, closing the cash-out loop. |
What it looks like in practice
A retailer sees a sudden burst of small gift-card purchases from hundreds of different accounts, each using a card that has never shopped there before. Many of the payments authorize, a handful decline, and the successful ones all load low-denomination cards that are redeemed within minutes.
Days later, chargebacks arrive from the real cardholders who never made those buys. The redeemed codes have already surfaced on a discount resale site. Tracing back, the purchases share a small pool of device fingerprints and a shipping-free digital delivery path, the signature of card testing feeding a gift-card cash-out.
Why it is dangerous for operators
Gift cards are dangerous because they collapse the time between fraud and loss. Value is redeemed within minutes, often before the authorization even settles, so the usual review window barely exists. And because the fraudster is holding stolen value rather than facing a chargeback, the cost lands squarely on the merchant or issuer as disputes and drained balances.
They are also a laundering-friendly instrument. Digital delivery removes shipping friction, low denominations stay under review thresholds, and resale converts everything to cash, which is why a gift-card spike deserves attention as both a fraud and an AML signal rather than a simple sales bump.
What to watch in the data
- Balance-check bursts. High-volume, automated balance inquiries against many card numbers point to cracking bots hunting loaded cards.
- Many cards, one device. A cluster of gift-card purchases sharing device fingerprints or IPs across unrelated accounts signals card testing.
- Instant redemption. Cards bought and drained within minutes, especially digital delivery with no shipping step, leaves no time to intervene.
- Low, repeated denominations. Repetitive small-value loads sit under review thresholds and add up while staying quiet.
- Chargeback echo. A wave of disputes tied to gift-card SKUs days after purchase confirms stolen payment data was behind the loads.
Quick questions
What is gift-card cracking?
It is the use of bots to guess or test large numbers of gift-card numbers and PINs against a balance-check endpoint. When a bot lands on a card that still holds value, the fraudster drains it before the rightful owner spends it.
Why do scammers ask victims to pay in gift cards?
Gift cards are near-irreversible and easy to liquidate. Once a victim reads the code over the phone, the value is gone with no chargeback and a short trail, which is why impostor and support scams so often demand them.
How does card testing connect to gift cards?
Fraudsters validate stolen card numbers by making small purchases, and low-value digital gift cards are an ideal test buy. The same run that confirms live cards also produces resellable codes, so the two steps fold into one.
Who eats the loss?
When stolen payment data funds the purchase, the merchant or issuer absorbs the chargebacks. When a legitimate owner's balance is cracked, the loss falls on whoever must make that customer whole, typically the retailer or program operator.
Is gift-card fraud a money-laundering concern?
Yes. Cards convert dirty value to near-cash, digital delivery removes friction, and resale markets turn codes into clean money. Volume patterns and cross-border resale make it a legitimate AML monitoring target, not just a fraud one.
What should a team do when it spots the pattern?
Rate-limit balance checks, add velocity and device controls on gift-card purchases, and delay or hold suspicious redemptions. Link shared devices and cards across accounts, and treat confirmed laundering flows for suspicious activity reporting.
Qué saber junto con Gift-card fraud

Informe de Fraude y ALD 2026
Olvídate de las predicciones. Este informe desglosa a qué se enfrentan realmente los equipos de fraude y ALD, y cómo responder.
