Skip to main content
Back to the wiki
Fraud & Scams

What Is Card-Not-Present (CNP) Fraud?

Last updated on July 20, 2026

Card-not-present (CNP) fraud is payment fraud committed in transactions where the physical card is never shown to the merchant — online checkouts, phone orders, in-app purchases, subscriptions. In these channels, possession of the card data is functionally possession of the card: a number, expiry date, and security code typed into a form cannot prove who is typing. That structural gap explains the defining trend of modern payment fraud: as EMV chips made counterfeiting physical cards impractical at the terminal, fraud did not shrink — it migrated online, and CNP fraud now accounts for the large majority of card fraud losses in every mature market.

How stolen data becomes stolen goods

The CNP fraud chain is industrialized end to end. Card data enters the market through breaches, phishing, and skimming scripts injected into checkout pages, then circulates in bulk through underground shops. Because bulk data is unreliable — cards expire, get cancelled, or were mistyped — buyers validate it first through carding: automated small-value authorizations run against live checkouts, with card cracking filling in missing expiry dates and security codes by brute-force permutation. Validated cards are then monetized: physical goods shipped to drops or reshippers, digital goods and gift cards flipped instantly, or purchases laundered through the storefront sleight-of-hand of triangulation fraud. Each stage leans on automation, because every stage is a numbers game that only pays at volume.

The authentication counterweight

The payment industry's answer is to attach identity evidence to remote transactions. Address and security-code checks (AVS, CVV) filter the crudest attempts. 3-D Secure interposes the cardholder's bank, which can demand a confirmation in the banking app; in the European Economic Area, PSD2's Strong Customer Authentication mandates such two-factor confirmation for most electronic payments — a regulatory push that measurably squeezed CNP fraud within Europe. The friction is real, though: every additional challenge abandons some carts, so the ecosystem runs on risk-based exemptions in which low-risk transactions skip the challenge. That bargain works exactly as well as the risk assessment behind it, and it is the assessment that automated fraud probes for soft spots.

Where merchants can intervene

Merchants cannot fix stolen card data, but they control the surfaces where it gets tested and spent. Velocity limits and rate limiting cap how many attempts one session can make; fraud scoring weighs order, address, and history signals; and human verification at the checkout — the role of CaptchaFox, which separates automated card-testing runs from genuine buyers before the payment request fires — removes the automation layer that makes bulk CNP abuse economical. Pushing bots out of the checkout does not end card fraud, but it forces it back to manual scale, and manual scale is where the existing payment defenses were designed to win.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is Carding?

Carding is the automated testing of stolen credit card data against payment forms to find cards that still work before selling or exploiting them.

Read more
What Is Chargeback Fraud?

Chargeback fraud is the abuse of the card dispute process to reverse legitimate charges — the merchant loses the goods, the revenue, and pays a fee on top.

Read more
What Is Click Fraud?

Click fraud is the automated or incentivized clicking of paid ads to drain an advertiser's budget or inflate a publisher's revenue — no buyer ever intended.

Read more
What Is Coupon Fraud?

Coupon fraud is the systematic abuse of discount codes, referral bonuses, and promotions — often through fake accounts that redeem one-time offers at scale.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices