Skip to content

Card-Not-Present (CNP) Fraud

Definition

Fraudulent use of payment card data in a transaction where the physical card is absent, typically an online or telephone purchase. The attacker requires only card number, expiry date, and security code, data obtainable through breaches or phishing.

Setting
Physical card absent, e.g. online or phone purchase
Data needed
Card number, expiry date, security code
Data source
Breaches or phishing
Category
Online fraud and financial cybercrime

Common questions

Why has CNP fraud grown as chip-and-PIN adoption increased for physical cards?+

As chip technology made counterfeiting a physical card at a point-of-sale terminal harder, fraud displaced toward the channel that never required the physical card at all, since online and phone transactions only need the card's static data fields.

What investigative evidence typically links a CNP fraud to a suspect?+

Investigators examine IP addresses and device fingerprints used at checkout, shipping addresses for goods purchased with stolen card data, and account access logs, since the transaction itself leaves no physical trace like a signature or chip transaction record.

How do merchants and card networks try to reduce CNP fraud risk?+

Address verification checks, the card security code, and additional authentication steps such as 3-D Secure are layered onto CNP transactions specifically because the physical card cannot be inspected, unlike an in-person purchase.

Related terms

Advance-Fee Fraud
A scheme in which the victim is promised a large future payment in exchange for an upfront fee. Variants include the classic...
Blockchain Analytics
The use of tools such as Chainalysis, Elliptic, or CipherTrace to trace cryptocurrency fund flows across a public ledger. Because most public...
Business Email Compromise (BEC)
A fraud in which an attacker impersonates a trusted executive, finance counterpart, or supplier over email to authorise fraudulent wire transfers or...
Money Mule
A person who receives fraudulently obtained funds into their bank account and transfers them onward, taking a commission. Mules may be witting...
Phishing
A mass deception attack delivered by email, SMS (smishing), or voice call (vishing) in which the attacker impersonates a trusted entity to...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.