Skip to main content
Payments

8 Types of Payment Fraud Draining Merchants (And How to Stop Each)

A black credit card on a charcoal metal workbench under a single harsh overhead lamp, thin streams of glowing teal particles being siphoned off it into the surrounding shadow while faint shadowy hands reach in from the dark edges.

TL;DR: Eight fraud patterns account for most of what merchants lose to bad transactions: card-not-present fraud, friendly fraud, card testing, account takeover, triangulation, refund fraud, interception, and phishing-driven fraud. Each has a specific prevention action. As of April 1, 2025, Visa folds fraud and disputes into a single ratio (VAMP) that can fine you or end your account, so ignoring any one of these now costs more than the fraud itself.

Most merchants think about fraud as a stolen card getting used at their checkout. That is one type. There are at least eight, and the one that quietly costs the most is the one your own customers commit.

Here is the number that changed the math. Payment card fraud losses worldwide reached $33.41 billion in 2024, and the United States absorbed 41.87% of global losses on just 26.31% of card volume (Nilson Report, Issue 1298, December 2025). US merchants get hit harder per dollar processed than merchants anywhere else.

The bigger shift is on the network side. On April 1, 2025, Visa merged its old Dispute Monitoring Program and Fraud Monitoring Program into one Visa Acquirer Monitoring Program (VAMP), which counts fraud reports (TC40) and disputes (TC15) together and divides by settled card-not-present transactions. The threshold has tightened since launch: VAMP first flagged merchants as "excessive" at 2.20%, and as of April 1, 2026 that dropped to 1.5% (150 basis points) for merchants in the US, Canada, and the EU (Visa Acquirer Monitoring Program, 2025–2026 program updates). Mastercard's Excessive Chargeback program triggers at a 1.5% ratio with 100 or more chargebacks for two straight months. Cross those lines and you face fines, forced remediation, and in the worst case a spot on the MATCH list that blocks you from getting a new merchant account.

So payment fraud prevention stopped being only about the money a fraudster takes. For merchants, it is now about staying under a ratio that decides whether you can process cards at all.

Below are the eight types, how each one works, and the single action that stops it.

1. Card-Not-Present (CNP) Fraud

A fraudster uses stolen card details to buy from you online, by phone, or through a saved-card flow. There is no physical card to inspect and no chip to read, so the transaction looks normal until the real cardholder sees it and disputes the charge. After EMV chip cards pushed in-person fraud down, CNP became the category most merchant fraud falls into.

The cost lands twice. You lose the product or service, then you lose the disputed amount and often a chargeback fee on top.

Stop it: Turn on the full card-not-present stack. Address Verification Service (AVS) checks the billing ZIP, CVV requires the security code the fraudster usually does not have, and EMV 3-D Secure (3DS2) shifts liability for many fraudulent chargebacks back to the card issuer when the customer authenticates. AVS and CVV are the floor. 3DS is the ceiling, and it is the only one of the three that moves liability off your books.

2. Friendly Fraud (First-Party Misuse)

A real customer makes a real purchase, then disputes it with their bank and keeps the goods. Sometimes it is deliberate. Sometimes a family member made the charge, or the customer forgot the purchase and did not recognize the billing descriptor. Either way the money comes out of your account.

This is the type most merchants underestimate. First-party misuse now makes up more than 45% of all chargebacks (Mastercard State of Chargebacks, 2025). It is no longer the edge case. It is close to half the problem.

Stop it: Fight the winnable ones with evidence and prevent the rest with clarity. Keep delivery confirmation, AVS match records, IP logs, and prior order history so you can submit compelling evidence on representment. Then remove the trigger: make your billing descriptor match your brand name exactly, because a charge from "SP* WXZ LLC" gets disputed far more often than one that says your store name. Our chargeback prevention guide walks through the evidence package that actually wins these.

3. Card Testing and BIN Attacks

Criminals buy or generate lists of card numbers, then run thousands of tiny transactions through your checkout to see which cards are still live. A BIN attack takes a bank's identification number, the first six to eight digits, and brute-forces the remaining digits, expiration, and CVV. The amounts stay small, often under a dollar, to avoid tripping fraud filters and to keep the real cardholder from noticing.

Your checkout becomes their free testing lab. You pay the authorization fees, your decline rate spikes, and the validated cards get sold or spent elsewhere, sometimes back at your own store.

Stop it: Add velocity limits and a bot gate. Cap how many attempts one IP, device, or card can make in a set window, block repeated failed authorizations, and put CAPTCHA or an invisible bot check on the payment page. If you see a sudden wave of small-dollar declines, tell your processor immediately so they can apply emergency rate limiting at the gateway.

4. Account Takeover (ATO)

A fraudster gets into a legitimate customer's account with your business, usually through reused passwords, phishing, or credentials leaked in a breach. Once inside, they use the saved payment method, change the shipping address, and place orders that look like they came from a trusted repeat buyer.

The scale is not small. Account takeover drove $15.6 billion in losses in 2024, up from $12.7 billion the year before (Javelin 2025 Identity Fraud Study). Because the login is real, most basic fraud rules wave these orders straight through.

Stop it: Protect the login, not just the checkout. Require multi-factor authentication on customer accounts, add device fingerprinting so a known account signing in from a new device gets flagged, and watch for the tells: a login from a new location followed immediately by a shipping-address change and a large order. Treat that sequence as high risk even when the credentials check out.

5. Triangulation Fraud

This one hides inside a fake storefront. The fraudster sets up a too-good-to-be-true listing on a marketplace or a lookalike site. A real shopper buys from the fake store with a real card. The fraudster then orders the item from your legitimate store using a different stolen card, ships it to the shopper, and pockets the shopper's clean payment. The shopper is happy. You eat the chargeback when the stolen card gets reported.

Three parties, one victim who never knows it: you. Triangulation is hard to spot because the order itself looks fine and the delivery completes normally.

Stop it: Watch for the mismatch patterns triangulation leaves behind. Orders where the billing name, shipping name, and email do not align, repeat shipping addresses paired with many different cards, and unusual clusters of orders for the same high-resale item are the signatures. Feed these into your fraud rules, and monitor for fake listings impersonating your brand so you can get them taken down.

6. Refund and Return Fraud

The purchase is legitimate. The abuse happens on the way out. A customer claims an item never arrived, returns an empty box, swaps a real product for a broken one, or exploits a lenient policy to keep merchandise and get their money back. Organized versions run this at scale across many merchants.

The total is staggering. Fraudulent and abusive returns cost US retailers $103 billion in 2024, and 15.14% of all returns were flagged as fraud or abuse (Appriss Retail, 2024).

Stop it: Put controls on the refund path itself. Require manager authorization above a dollar threshold, track serial returners by customer and by shipping address, and match returned items to the original order and serial number before issuing money back. A written, enforced return policy is your evidence when a refund claim turns into a dispute.

7. Interception Fraud

A fraudster places an order with a stolen card, then races to redirect the package before it lands. They contact the carrier to reroute delivery, change the address right after checkout, or ask for a pickup at a location they control. The AVS check passed at purchase because the billing address was real. The goods still end up in the wrong hands.

This type targets the gap between authorization and delivery, a window your fraud tools usually stop watching once the payment clears.

Stop it: Lock the fulfillment details after authorization. Flag any shipping-address change made shortly after an order for manual review, disable customer-initiated carrier reroutes on flagged orders, and require re-verification when the shipping address does not match the billing address on higher-value purchases. For high-risk orders, ship with signature confirmation.

8. Phishing and Social-Engineering Fraud

Fraudsters trick your customers, or your own staff, into handing over card data, login credentials, or one-time passcodes. The resulting transactions look authentic because they use real details a real person surrendered. When the victim realizes what happened, the charge becomes a dispute against you.

This type scales with your brand. The more recognizable you are, the more attackers impersonate you in emails and texts that push customers to a fake payment page.

Stop it: Cut off the credential and reduce the payoff. Enforce 3-D Secure so a stolen card number alone is not enough to complete a purchase, train staff never to process a payment or share account access based on an unverified phone or email request, and give customers a clear way to report messages impersonating your business. Publish what a real message from you looks like so a fake one stands out.

The Pattern Behind All Eight

Six of these eight types now feed the same VAMP ratio. Fraud reports and disputes get counted together, so a wave of card testing and a spike in friendly fraud push you toward the same 1.5% cliff. That is why picking one fix is not enough. The merchants who stay clear of the monitoring programs run the full stack: authentication at checkout, velocity controls against bots, login protection against takeover, and refund controls on the back end.

Prevention is cheaper than remediation every time. Exiting a Mastercard excessive-chargeback designation takes three consecutive months back under threshold. Getting off the MATCH list can take five years. The controls above cost a fraction of either.

If you would rather have fraud and chargeback controls built into your processing setup than bolt them on after a problem, ClickWerxs sets up merchant accounts with dispute and fraud support.

Frequently Asked Questions

What is the difference between fraud and a chargeback?

Fraud is the underlying crime, such as a stolen card or an account takeover. A chargeback is the payment reversal a cardholder's bank issues, which can result from real fraud or from friendly fraud where the customer disputes a legitimate charge. Under Visa's VAMP, both fraud reports and disputes now count toward the same ratio.

What chargeback ratio gets a merchant in trouble?

As of April 1, 2026, Visa's VAMP flags a merchant as excessive at a 1.5% ratio of combined fraud and disputes to card-not-present transactions, tightened from the 2.20% threshold VAMP launched with in April 2025. Mastercard's Excessive Chargeback program triggers at a 1.5% ratio combined with 100 or more chargebacks for two consecutive months. Staying well below 1% is the safe operating zone most acquirers advise.

Does 3-D Secure stop all payment fraud?

No. EMV 3-D Secure (3DS2) authenticates the cardholder at checkout and shifts liability for many fraudulent chargebacks to the issuing bank, which directly reduces card-not-present and phishing losses. It does nothing for friendly fraud, refund fraud, or triangulation, because those involve a real authenticated customer or a transaction that completes normally.

Which payment fraud type is growing fastest for small businesses?

First-party misuse, or friendly fraud, is the fastest-rising category. It now accounts for more than 45% of all chargebacks according to Mastercard's State of Chargebacks 2025 report, and it is difficult to prevent with standard fraud filters because the buyer and the card are both legitimate.

Can a payment processor help prevent fraud, or is it all on the merchant?

Both. Your processor can apply gateway-level velocity limits, tokenization, 3DS routing, and real-time fraud scoring, while you control checkout rules, refund authorization, and account security. The merchants who stay under the monitoring thresholds treat it as a shared setup, not a set-and-forget feature.


ClickWerxs facilitates merchant account applications and provides ongoing account management as an authorized representative of our banking and processing partners. Approval, rates, and terms are determined by the issuing processor and acquiring bank — ClickWerxs does not guarantee approval for any merchant account application. Processing rates and fee structures cited in this post reflect publicly available industry data and general ranges; your actual rate depends on your industry, volume, and card mix. This post is not legal or financial advice. For a custom quote, see clickwerxs.com/payments/get-a-quote.


Kaleb Dickhaut Founder, ClickWerxs linkedin.com/in/kaleb-dickhaut

Kaleb built ClickWerxs from the ground up — from payment processing ISO to the Command Center platform to the AI SEO methodology the blog runs on. He has onboarded hundreds of small businesses onto payment and CRM systems.


Sources

  1. Card network monitoring thresholds — Visa's Acquirer Monitoring Program (VAMP) replaced the Visa Dispute Monitoring Program and Visa Fraud Monitoring Program effective 1 April 2025 and measures fraud reports and disputes combined; the merchant Excessive threshold is 1.50% above a floor of 1,500 combined events per month as of 1 April 2026. Mastercard's Excessive Chargeback Merchant tier is 100 chargebacks and 150 basis points. Visa distributes VAMP terms through acquirer bulletins rather than a public page; confirm current thresholds with your acquirer.
  2. Processing rates, fee ranges and effective-rate figures in this post are industry-typical ranges compiled from published network schedules and from accounts reviewed in the ClickWerxs ISO portfolio. They are not quoted rates. Interchange itself is set by Visa and Mastercard on published schedules that change twice yearly; your actual cost depends on card mix, MCC, ticket size and volume.
  3. ClickWerxs ISO portfolio, aggregate observation — patterns described from merchant accounts under ClickWerxs management. Anonymized and reported in aggregate; individual account terms vary. Operator data.

ClickWerxs facilitates merchant account applications and provides ongoing account management as an authorized representative of our banking and processing partners. Approval, rates, and terms are determined by the issuing processor and acquiring bank — ClickWerxs does not guarantee approval for any merchant account application. Processing rates and fee structures cited in this post reflect publicly available industry data and general ranges; your actual rate depends on your industry, volume, and card mix. This post is not legal or financial advice. For a custom quote, see clickwerxs.com/payments/get-a-quote.

Ready to Stop Overpaying on Payment Processing?

Get a free rate comparison and see how much you can save with interchange-plus pricing.