
Every online merchant accepts a form of risk that a physical retail store largely does not: the person completing the transaction is never actually seen. That gap is where card-not-present fraud lives, and by 2026 it accounts for the large majority of overall payment card fraud, a share that has kept climbing as more commerce moves online and fraud tactics have grown more automated.
Quick Answer: Card-not-present fraud, often abbreviated CNP fraud, occurs when a stolen or compromised card is used to make a purchase without the physical card present, typically online, by phone, or by mail. Because there is no chip to read or signature to compare, merchants rely on other verification tools, including Address Verification Service, CVV matching, 3D Secure authentication, and machine learning-based risk scoring, to catch fraudulent transactions before they are approved. No single tool eliminates CNP fraud, but layering several together significantly reduces exposure.
What Is Card-Not-Present Fraud?
Card-not-present fraud happens when someone uses stolen card details to make a purchase without the physical card being present at the point of sale. This covers online purchases, phone orders, and mail orders, the three primary channels where a merchant cannot physically inspect the card or verify the cardholder's identity in person.
The fraudster does not need the physical card at all, only the card number, expiration date, and often the CVV code, all of which can be obtained through data breaches, phishing, skimming devices, or purchased in bulk on illicit marketplaces. Because eCommerce transactions are card-not-present by definition, every online store carries this exposure regardless of size.
This is distinct from card-present fraud, where a physical counterfeit or stolen card is used at an in-person terminal. Card-present fraud has declined significantly since EMV chip technology became standard, because chip cards are far harder to counterfeit than the magnetic stripe cards they replaced. Fraud did not disappear as a result; it shifted toward the channel where verification is inherently weaker, which is exactly why CNP fraud has become the dominant fraud category for merchants operating online.
Why Are Online Merchants the Primary Target?
The shift toward card-not-present fraud is a direct consequence of a security improvement elsewhere in the payments ecosystem. As in-person fraud became harder to execute due to chip card adoption, fraudsters moved to the channel where identity verification is inherently more difficult: transactions where no physical card or signature is involved.
Why CNP transactions are structurally more vulnerable:
No physical card to inspect for signs of tampering or counterfeiting
No chip authentication, which is the strongest fraud deterrent available for in-person transactions
No signature comparison, though signature verification was already a weak fraud control before online shopping became dominant
Verification relies entirely on data the fraudster may already possess: card number, expiration date, billing address, and CVV
For a small or mid-sized eCommerce merchant, this means fraud risk is not proportional to business size. A small online store with weak fraud controls can be just as attractive a target as a large one, sometimes more so, because smaller merchants are statistically less likely to have layered fraud protection in place.
What Fraud Prevention Tools Actually Work Against CNP Fraud?
No single tool eliminates card-not-present fraud. Effective prevention comes from layering multiple verification checks so that a transaction has to pass several independent tests before being approved.

Core fraud prevention tools, from foundational to advanced:
Address Verification Service (AVS)
Compares the billing address entered at checkout against the address the card issuer has on file. A mismatch does not always mean fraud, since customers sometimes enter address information incorrectly, but a mismatch combined with other risk signals is a strong indicator worth flagging.
CVV verification
Requires the three or four digit security code printed on the card. Because the CVV is not stored in card magnetic stripe or chip data and is not always captured in data breaches, requiring it filters out a meaningful share of fraud attempts using card numbers obtained through less sophisticated means.
3D Secure authentication
Adds a real-time authentication step, often a one-time passcode sent to the cardholder's phone or a biometric confirmation, before the transaction completes. This is one of the strongest tools available against CNP fraud and, when properly implemented, shifts chargeback liability for fraudulent transactions away from the merchant and onto the card issuer.
Velocity checks
Flags unusual patterns, such as multiple transaction attempts in a short period from the same card, IP address, or device, which is a common signature of automated fraud attempts testing stolen card numbers.
Machine learning risk scoring
Evaluates each transaction in real time against a broad set of signals, including device fingerprinting, transaction history, purchase patterns, and known fraud indicators, to assign a risk score. High-risk transactions can be automatically held for review or declined before completing.
Order review for high-risk transactions
For transactions that trigger multiple risk signals without being automatically declined, a manual or semi-automated review step before fulfillment adds a final check, particularly valuable for high-ticket orders or first-time customers.
How Do AVS and CVV Verification Actually Work Together?
These two tools are the most foundational and widely available fraud checks, and understanding how they work together clarifies why relying on just one leaves gaps.

AVS confirms that the billing address matches what the issuing bank has on file. CVV confirms that the person completing the transaction has physical or recorded access to the security code on the card itself, something that is not always captured when card numbers are stolen through certain breach methods.
Used together, a transaction that passes both AVS and CVV checks is significantly less likely to be fraudulent than one that fails either. A transaction that fails AVS but passes CVV, or vice versa, is not automatically fraudulent, but it is a signal worth weighing alongside other risk factors rather than ignoring. Most payment gateways allow merchants to configure how strictly these checks are enforced, whether to automatically decline mismatches or simply flag them for review.
What Does a Real CNP Fraud Prevention Setup Look Like in 2026?
By 2026, most reputable payment gateways include AVS and CVV checks as standard, non-optional features. The differentiation between gateways now happens at the more advanced layers.
A baseline setup for a small to mid-sized eCommerce merchant should include AVS and CVV verification enabled and enforced, 3D Secure available and applied at minimum to higher-risk transactions, and basic velocity checks to catch obvious automated fraud attempts. This baseline catches a meaningful share of unsophisticated fraud attempts without adding friction to legitimate customers.

A more mature setup, appropriate for merchants processing higher volume or selling products attractive to fraud such as electronics, gift cards, or luxury goods, adds machine learning risk scoring and a manual review workflow for transactions that fall into a gray zone between clearly legitimate and clearly fraudulent.
The trade-off across every layer is the same: stricter fraud controls catch more fraud but also risk declining legitimate customers or adding friction that increases cart abandonment. Getting this balance right is less about turning every tool to its strictest setting and more about calibrating based on your specific product category, average order value, and customer base.
Want to Know If Your Fraud Prevention Setup Is Actually Working?
Many merchants have AVS and CVV checks turned on by default without knowing whether they are configured correctly, or without any additional layer beyond that baseline. Rapid Payments reviews your current fraud prevention setup and identifies where the gaps are before they turn into losses.



