What is card-not-present (CNP) fraud? | Transmit Security

Glossary

What is card-not-present (CNP) fraud?

Card-not-present (CNP) fraud is payment fraud in online or phone transactions where the physical card isn’t used. Learn how it works and how to prevent it.
by Transmit Security

Card-not-present (CNP) fraud is payment fraud that occurs in transactions where the physical card is not physically presented (online, over the phone, or by mail) using stolen card details to make unauthorized purchases. As commerce shifted online, CNP fraud became the dominant form of card fraud, since the protections built into in-person, chip-based transactions don’t apply.

Without the physical card and its chip, a merchant can’t rely on the card’s built-in security; they only have the card data, which is exactly what fraudsters steal and reuse.

How CNP fraud happens

Fraudsters obtain card details through data breaches, phishing, skimming, or purchase on the dark web, then use them for online or phone purchases. Because only the card number, expiry, and security code are needed (all of which can be stolen together) the barrier is low. Fraudsters often test stolen cards with small transactions ("card testing," frequently automated with bots) before making larger purchases, and they target merchants with weaker fraud controls.

Why it’s challenging to prevent

CNP transactions lack the physical and cryptographic assurance of a chip card, so merchants must assess risk from data and behavior alone. The tension is the familiar one: strict controls reduce fraud but add checkout friction and false declines that cost legitimate sales, while loose controls invite fraud and chargebacks. Merchants also bear more liability for CNP fraud than for in-person fraud, raising the stakes.

How to prevent CNP fraud

Defense layers several controls: risk-based transaction analysis (assessing device, behavior, and context, not just the card data), strong customer authentication where applicable (such as 3-D Secure and, in Europe, PSD2 SCA), bot detection to stop automated card testing, device and behavioral intelligence to spot unfamiliar or suspicious sessions, and tokenization to reduce the value of stored card data. The goal is to catch fraudulent transactions while minimizing false declines, applying friction (like a step-up) only when risk warrants, so genuine customers check out smoothly.

The false-decline cost of fighting CNP fraud

An underappreciated dimension of CNP fraud is that over-aggressive prevention can cost more than the fraud itself. False declines (legitimate transactions wrongly rejected as fraud) frustrate good customers, push them to competitors, and are estimated to exceed actual fraud losses for many merchants. So the CNP challenge is two-sided: block the fraud, but don’t strangle the far larger volume of genuine sales in the process. This is exactly where accurate, risk-based decisioning earns its value over blunt rules. Rich signals (device, behavior, network, and identity context) let a merchant distinguish a fraudster using stolen card data from a real customer whose purchase merely looks unusual, approving the latter smoothly while challenging or blocking the former. Optimizing only for fraud caught, while ignoring false declines, is a common and expensive mistake in CNP fraud management.

Frequently asked questions

What is a false decline in CNP fraud?

A legitimate transaction wrongly rejected as fraudulent, costly because false declines often exceed actual fraud losses and drive customers away.

What is card-not-present fraud?

Payment fraud in transactions where the physical card isn’t presented (online, phone, or mail) using stolen card details.

Why is CNP fraud so common?

Online commerce lacks the chip-based protections of in-person payments, and stolen card data is easy to obtain and reuse.

What is card testing?

Making small transactions (often bot-automated) to check whether stolen card details work before larger purchases.

How do you prevent CNP fraud?

Risk-based transaction analysis, strong customer authentication (3-D Secure/SCA), bot detection, device intelligence, and tokenization.

Related: Chargeback Management · Bot Detection · Strong Customer Authentication (SCA) · Risk Scoring · Transaction Monitoring

Request a Demo

By clicking the button, you agree to the Terms and Conditions