Card-Not-Present Fraud (CNP Fraud)

Card-Not-Present Fraud (CNP Fraud)

Card not present (CNP) fraud is payment fraud committed in transactions where the physical card is never shown: online, by phone, or by mail. The bad actor uses stolen card details, the number, expiration date, and security code, without the cardholder’s authorization. Because possession of the card is never verified, CNP channels carry the bulk of ecommerce payment fraud.

How CNP Fraud Works

Stolen credentials from breaches, phishing, and skimming circulate on the dark web, get validated through card testing, and are then spent at checkouts, typically on resalable goods shipped to addresses the fraudster controls, including reshipping hubs. The transaction authorizes normally: the card is valid, the funds exist, and the issuer has no reason to decline. The fraud only surfaces when the real cardholder spots the charge and disputes it.

Why CNP Fraud Falls on Merchants

Liability follows verification. In card present transactions with chip authentication, the issuer generally absorbs counterfeit fraud; in CNP transactions the merchant does. Every successful CNP fraud becomes a chargeback: lost merchandise, reversed revenue, and a dispute fee, with Mastercard and Datos Insights putting the average direct cost at $128 per chargeback before the goods are counted. The chip card migration pushed fraud into exactly this channel: as counterfeiting physical cards got harder, stolen-credential fraud moved online.

How to Prevent CNP Fraud

The defense has to distinguish the cardholder from someone holding the cardholder’s data. AVS and CVV checks help as signals; 3D Secure adds issuer authentication where the friction is justified; and the decisive layer is behavioral: device intelligence, network signals, order patterns, and identity history that stolen data cannot imitate. Blunt rules cost real revenue, since over-filtering produces false declines on legitimate shoppers whose details merely look unusual.

How Wyllo Helps

Wyllo Payment Fraud Protection screens CNP transactions in real time using device, network, and behavioral signals with expert analyst review of the grey area, maximizing approvals while stopping the stolen-credential orders that become chargebacks. An optional chargeback guarantee removes the downside entirely.

Frequently Asked Questions

What is the difference between CNP fraud and a CNP transaction?

A card not present transaction is any legitimate purchase made without the physical card, which describes essentially all of ecommerce. CNP fraud is the criminal subset: those transactions made with stolen credentials.

Does 3D Secure stop CNP fraud?

It shifts liability for authenticated transactions to the issuer and blocks some attacks, but it adds checkout friction and doesn’t address fraud that authenticates successfully, including social engineered one-time passcodes. Most brands apply it selectively, by risk.

Related Glossary Categories

Install Wyllo

Select your ecommerce platform to start your free two-week trial.​

See Wyllo in Action

Contact the Wyllo team and we’ll be in touch within one business day to schedule your personalized demo. 

Let's find those
bad actors.

Contact the Wyllo team and we’ll review your system together to identify the bad actors.