Card-not-present fraud, commonly shortened to CNP fraud, is payment fraud that occurs when a purchase is made without the physical payment card being presented to the merchant. It is most closely associated with ecommerce, in-app purchases, mail or telephone orders, subscriptions and other remote payments.
Because the merchant cannot physically inspect the card, digital payment credentials and customer authentication become especially important. PCI Security Standards Council guidance describes card-not-present environments as including ecommerce and mail-order or telephone-order payments, while EMVCo uses the broader term remote payment fraud for fraudulent transactions carried out through internet, telephone or mail channels.
CNP fraud can harm consumers, merchants and financial institutions through unauthorized charges, chargebacks, account disruption, replacement-card costs and loss of trust. The strongest defenses therefore combine secure payment-data handling, authentication, tokenization, transaction monitoring and good account-security practices.
Quick answer: Card-not-present fraud is unauthorized payment activity in which the physical card is not presented to the merchant. It commonly affects online and other remote payments and is best reduced through layered controls such as tokenization, 3-D Secure, Strong Customer Authentication where applicable, AVS/CVV checks, fraud monitoring and secure handling of cardholder data.
What Does Card-Not-Present Mean?
A card-not-present transaction is a payment in which the merchant does not physically receive or read the customer's payment card at the point of sale. The payment details are instead provided through a remote channel.
- Online ecommerce checkout.
- In-app or mobile-app purchases.
- Mail-order or telephone-order transactions.
- Some subscription and recurring-payment arrangements.
- Other remote payments where the physical card is not presented to the merchant.
A CNP transaction is not automatically fraudulent. Most online payments are legitimate. The term CNP fraud refers specifically to unauthorized or deceptive activity occurring in this remote-payment environment.
What Is Card-Not-Present Fraud?
Card-not-present fraud occurs when someone uses payment credentials or an account without the legitimate customer's authorization in a remote payment channel.
EMVCo explains that remote payment fraud commonly involves stolen card information obtained through methods such as phishing, data compromise or other credential theft. The important fraud-awareness point is not how the information is stolen, but that remote-payment systems must assume payment credentials can become exposed and use additional controls to reduce their value and verify legitimate customers.
Card-Not-Present Fraud Examples
Common high-level examples include:
- Stolen card details are used to attempt an unauthorized ecommerce purchase.
- A compromised customer account is used to place an order using a saved payment method.
- A criminal uses information obtained through phishing to attempt a remote payment.
- A fraudulent transaction is attempted after payment data is exposed in a data breach.
- A subscription or digital-service account is taken over and used for unauthorized purchases.
These examples illustrate the fraud patterns without implying that every failed authentication, AVS mismatch or disputed transaction is criminal. Legitimate customers can also experience checkout errors, outdated billing details or account-access problems.
Card-Not-Present Fraud vs Card-Present Fraud
Feature | Card-not-present | Card-present |
|---|---|---|
Physical card at merchant? | No | Yes |
Typical channels | Ecommerce, app, phone/mail order | Store or attended payment terminal |
Important controls | Authentication, tokenization, AVS/CVV, fraud monitoring | EMV chip/contactless, terminal controls, issuer authorization |
Main challenge | Verifying a remote customer and protecting digital credentials | Protecting the physical-card/terminal transaction |
Why Is CNP Fraud a Serious Risk for Ecommerce?
Remote commerce is convenient precisely because the shopper and card do not need to be physically present. The same convenience means merchants must rely on digital signals to distinguish legitimate customers from unauthorized users.
- Payment credentials can be copied or exposed digitally.
- A merchant cannot physically inspect the card or compare it with the customer.
- Fraud attempts can originate from anywhere with internet or telephone access.
- Automated commerce allows large volumes of transactions to be processed quickly.
- Account takeover can bypass some card-focused checks if a criminal gains access to a legitimate user account.
What Are the Risks of Card-Not-Present Fraud?
For consumers, the risks can include:
- Unauthorized transactions and temporary loss of access to funds or credit.
- Card replacement and account disruption.
- Time spent disputing fraudulent charges and securing accounts.
- Exposure of additional personal or account information when fraud is linked to a wider compromise.
For merchants, the risks can include:
- Chargebacks and financial losses.
- Higher payment-processing and fraud-management costs.
- Inventory or service losses tied to unauthorized orders.
- Customer-support costs and reputational harm.
- False declines if fraud rules become overly aggressive.
How Merchants Can Reduce Card-Not-Present Fraud
No single tool prevents every CNP fraud attempt. The most resilient approach uses multiple independent controls that protect payment data, authenticate customers and evaluate transaction risk.
1. Use Payment Tokenization
Tokenization replaces the Primary Account Number with a substitute token. Network tokens can be restricted to a merchant, device or payment scenario, reducing the usefulness of compromised payment credentials.
2. Use EMV 3-D Secure
EMV 3-D Secure helps merchants and issuers authenticate consumers during ecommerce transactions. PCI SSC describes 3DS security standards as helping prevent unauthorized card-not-present transactions.
3. Apply Strong Customer Authentication Where Required
In jurisdictions where SCA applies, qualifying electronic payments may require independent authentication elements. SCA and tokenization address different risks and can be used together.
4. Use AVS and CVV/CVC as Supporting Signals
Address Verification Service can compare billing details with issuer records where supported, while CVV/CVC can provide another indication that the shopper has access to the card security value. Neither should be treated as identity proof on its own.
5. Protect Payment Pages and Cardholder Data
PCI DSS applies security requirements to cardholder-data environments, including ecommerce systems. Merchants should minimize exposure of card data and use secure, validated payment providers and integrations.
6. Use Risk-Based Transaction Monitoring
Merchants can evaluate transaction amount, account history, device signals, authentication results, unusual behavior and other risk indicators to identify transactions that deserve additional review.
7. Protect Customer Accounts
Strong passwords, multi-factor authentication where appropriate, secure password-reset processes and monitoring for suspicious account changes help reduce account-takeover risk.
Why Tokenization Is Especially Useful Against CNP Fraud
Tokenization reduces reliance on broadly reusable card numbers. If a token is limited to a specific merchant, device or payment context, exposing that token does not necessarily provide a credential that works elsewhere.
This is why tokenization is particularly valuable in ecommerce, digital wallets, saved-card systems and recurring-payment environments where payment credentials may otherwise remain stored for long periods.
How 3-D Secure Helps With CNP Fraud
EMV 3-D Secure allows transaction and device information to be exchanged between merchants and issuers so the issuer can assess risk and, when needed, request stronger customer authentication.
It does not replace merchant fraud monitoring, but it provides a standardized authentication layer specifically designed for remote card payments.
What Role Does CVV Play?
Card verification values such as CVV2, CVC2 or CID are commonly requested during card-not-present transactions to help indicate that the customer has access to information associated with the card.
PCI DSS classifies these values as Sensitive Authentication Data and prohibits merchants from storing them after authorization. This means a merchant should never save CVV/CVC for future use, even if the rest of a card-on-file relationship is legitimate.
What Role Does AVS Play?
Address Verification Service compares submitted billing-address information with issuer records where the service is supported. A full match can be a positive signal, while partial matches, mismatches or unavailable results may justify additional risk analysis.
AVS is not an identity-verification system. A legitimate customer can have an address mismatch, and a fraudster can sometimes possess correct billing details. It should therefore remain one signal among several.
How Consumers Can Reduce the Risk of CNP Fraud
- Use unique passwords for shopping, banking and email accounts.
- Enable multi-factor authentication where available.
- Avoid entering payment information after following suspicious links or unsolicited messages.
- Keep browsers, phones and computers updated.
- Review card and bank statements regularly for transactions you do not recognize.
- Use trusted merchants and secure checkout pages.
- Contact the card issuer promptly if a card or account appears compromised.
What To Do If You See a Card-Not-Present Transaction You Do Not Recognize
- Check whether the transaction could be a legitimate subscription, household purchase or merchant name you do not immediately recognize.
- If it remains suspicious, contact the card issuer using a trusted phone number or banking app.
- Follow the issuer's instructions for disputing the transaction and replacing or securing the card if necessary.
- Change passwords on affected merchant, email or financial accounts if account compromise is suspected.
- Review recent account activity for additional unauthorized transactions.
Common Misunderstandings About CNP Fraud
- Myth: Every online card transaction is high risk. Reality: most ecommerce payments are legitimate; CNP simply describes the payment channel.
- Myth: CVV alone proves the shopper is legitimate. Reality: CVV is one security signal, not full identity authentication.
- Myth: An AVS mismatch automatically means fraud. Reality: legitimate customers can have outdated or differently formatted billing details.
- Myth: Tokenization eliminates all fraud. Reality: it reduces credential exposure but cannot stop every account-takeover or social-engineering scenario.
- Myth: Stronger fraud controls should block more payments. Reality: good fraud prevention balances security with minimizing false declines for legitimate customers.
Frequently Asked Questions
What is card-not-present fraud?
Card-not-present fraud is unauthorized payment activity that occurs when the physical card is not presented to the merchant, typically in ecommerce or other remote-payment channels.
What does CNP mean in payments?
CNP stands for card not present. It describes transactions in which the merchant does not physically receive the payment card.
Is every online payment a CNP transaction?
Most traditional online card payments are card-not-present transactions, but being CNP does not mean the transaction is fraudulent.
What is the difference between card-present and card-not-present fraud?
Card-present fraud occurs in transactions where the card is physically presented, while CNP fraud happens in remote channels such as ecommerce, apps, phone or mail order.
How does tokenization reduce CNP fraud?
Tokenization replaces the PAN with a controlled token and can restrict that token to an approved merchant, device or payment scenario, reducing the usefulness of compromised credentials.
Does 3-D Secure prevent CNP fraud?
3-D Secure can reduce unauthorized ecommerce transactions by strengthening cardholder authentication, but it is one layer in a broader fraud-prevention strategy.
Does CVV stop online fraud?
CVV/CVC can provide an additional verification signal, but it does not prevent every fraud scenario and must not be stored after authorization.
Can AVS detect fraud?
AVS can identify billing-address mismatches that may contribute to a fraud-risk decision, but it cannot by itself determine whether a transaction is fraudulent.
What should I do after an unauthorized online card payment?
Contact the card issuer through a trusted channel, follow its dispute and card-security instructions, and secure any related accounts that may have been compromised.
Final Thoughts
Card-not-present fraud is a major payment-security challenge because remote commerce depends on digital credentials rather than a physical card being inspected at checkout.
The most effective response is layered defense: minimize exposure of card data, use tokenization, strengthen authentication with technologies such as 3-D Secure and SCA where applicable, combine AVS and CVV with broader risk signals, secure customer accounts and follow PCI DSS requirements for payment-data protection.
For consumers, the same principle applies: protect account credentials, be cautious with unexpected messages and payment prompts, review transactions regularly and contact the card issuer quickly when something looks wrong.
Authoritative References
- EMVCo - Remote Fraud and EMV Technologies
- PCI Security Standards Council - Merchants and Card-Not-Present Environments
- PCI Security Standards Council - PCI 3DS SDK Security Standard
- PCI Security Standards Council - Card Verification Codes in Card-Not-Present Transactions
- EMVCo - EMV Payment Tokenisation
- EMVCo - EMV 3-D Secure
Editorial note: This article is educational and focused on fraud awareness and prevention. Payment rules, liability and fraud-control capabilities can vary by jurisdiction, issuer, network and payment provider.



