Card-Not-Present (CNP) Fraud
Definition
Fraudulent use of payment card data in a transaction where the physical card is absent, typically an online or telephone purchase. The attacker requires only card number, expiry date, and security code, data obtainable through breaches or phishing.
- Setting
- Physical card absent, e.g. online or phone purchase
- Data needed
- Card number, expiry date, security code
- Data source
- Breaches or phishing
- Category
- Online fraud and financial cybercrime
Common questions
Why has CNP fraud grown as chip-and-PIN adoption increased for physical cards?+
As chip technology made counterfeiting a physical card at a point-of-sale terminal harder, fraud displaced toward the channel that never required the physical card at all, since online and phone transactions only need the card's static data fields.
What investigative evidence typically links a CNP fraud to a suspect?+
Investigators examine IP addresses and device fingerprints used at checkout, shipping addresses for goods purchased with stolen card data, and account access logs, since the transaction itself leaves no physical trace like a signature or chip transaction record.
How do merchants and card networks try to reduce CNP fraud risk?+
Address verification checks, the card security code, and additional authentication steps such as 3-D Secure are layered onto CNP transactions specifically because the physical card cannot be inspected, unlike an in-person purchase.
Related terms
- Advance-Fee Fraud
- A scheme in which the victim is promised a large future payment in exchange for an upfront fee. Variants include the classic...
- Blockchain Analytics
- The use of tools such as Chainalysis, Elliptic, or CipherTrace to trace cryptocurrency fund flows across a public ledger. Because most public...
- Business Email Compromise (BEC)
- A fraud in which an attacker impersonates a trusted executive, finance counterpart, or supplier over email to authorise fraudulent wire transfers or...
- Money Mule
- A person who receives fraudulently obtained funds into their bank account and transfers them onward, taking a commission. Mules may be witting...
- Phishing
- A mass deception attack delivered by email, SMS (smishing), or voice call (vishing) in which the attacker impersonates a trusted entity to...