THE GUIDE · WHEN THINGS GO WRONG · 12 MIN

Fraud is a $33 billion industry with a supply chain.

Global card fraud ran $33.4 billion in 2024 (Nilson Report) — and it's organized like a business: wholesalers, testers, cash-out crews, even customer support. Know the supply chain and the defenses finally make sense.

SCROLL ↓
IN PLAIN WORDS — READ THIS FIRST

Payment fraud is not one hacker guessing your card number. It is an industry with a supply chain: wholesalers sell stolen card data in bulk, testers find which cards still work, and cash-out crews turn the working ones into goods and gift cards. Global card fraud ran $33.4 billion in 2024.

Every defense you meet at checkout — the one-time code, the bank-app ping, the "unusual activity" text — exists because of one link in that chain. Watch a card-testing attack run start to finish, then meet the six kinds of fraud and who pays for each.

PART 01

Anatomy of a card-testing attack.

The most common play in the book. A criminal buys stolen card numbers wholesale — but most are dead. Step one is finding out which still work. Your $1 donation page is their laboratory.

PART 02

The taxonomy.

Six species of payment fraud — each with a different victim, defense, and bill-payer:

SPECIES 1 · STOLEN CARD (CNP)

The classic

Breached or phished card numbers used online. The merchant usually eats it (chargeback rules), which is why every checkout runs fraud scoring. Declining share of total fraud — tokenization and 3DS are working.

SPECIES 2 · ACCOUNT TAKEOVER

Steal the account, not the card

Credential-stuffing into wallets, bank apps, and merchant accounts with saved cards. Beats card-level defenses because the fraudster is the customer, device and all. Defense: passkeys, device binding, behavioral biometrics.

SPECIES 3 · FRIENDLY FRAUD

The customer is the fraudster

Real purchase, fake dispute — forgot, regretted, or gamed it. By many industry estimates the largest dispute category by volume, and the hardest to fight: your adversary passed every fraud check, because they're real.

SPECIES 4 · TRIANGULATION

The fake storefront

Fraudster lists cheap goods on a marketplace, takes your payment, then buys the real item from a legit store with a stolen card and ships it to you. You got your shoes; the legit store gets the chargeback. Three corners, one loser.

SPECIES 5 · APP SCAMS

You press the button yourself

Authorized push payment fraud: fake invoices, "your account is at risk," romance and investment scams — engineered for instant rails where there is no undo. The fastest-growing category worldwide; the UK now forces banks to reimburse most victims, and others are following.

SPECIES 6 · MERCHANT FRAUD

The seller is the scam

Bust-out merchants: open an account, sell heavily, never ship, vanish with the settlement money — leaving the acquirer holding the chargebacks. This is why merchant onboarding feels like a loan application. It is one.

The words, one at a time.

Six terms carry most fraud conversations. Learn these and every vendor pitch and bank warning gets easier to parse.

Card testing
sorting stolen cards into live and dead
Bots fire tiny charges through a real checkout to find which stolen card numbers still work. The merchant's payment page does the sorting, for free.
10,000 cards hit a $1 donation page overnight. The ~8% that approve become a verified list worth 50× the raw one.
Why it matters: it's the first industrial step of most card fraud, and the reason checkouts rate-limit you.
Account takeover
stealing the whole account, not the card
Logging into someone's wallet, bank app, or merchant account — usually with a password reused from an old breach — and spending the card already saved inside.
A password leaked in a 2019 breach still opens a food-delivery account in 2026, card on file and ready.
Why it matters: it beats card-level defenses, because to every system the fraudster looks like the real customer.
Friendly fraud
a real customer disputes a real purchase
The purchase happened, then the cardholder disputes it anyway — forgot it, regretted it, or learned that disputing works.
A child's $40 in-game purchase becomes a parent's "I don't recognize this charge."
Why it matters: by many industry estimates the largest dispute category by volume, and every fraud check passes because the customer is genuine.
Mule account
the getaway car for stolen money
A real person's bank account — rented, bought, or socially engineered — that scam proceeds pass through on their way out of reach.
"Work from home: receive transfers, forward 95%, keep 5%." That job listing is money laundering.
Why it matters: mule networks are why scam money is so hard to freeze. It has crossed three accounts before the victim even calls the bank.
Velocity rule
counting things per key, per time window
A defense that counts events — cards per device per hour, attempts per IP per minute — and blocks when a counter looks inhuman.
100 different cards from one browser fingerprint in an hour. No human shops like that.
Why it matters: the cheapest defense there is, and the one card-testing attacks trip first.
False decline
blocking a good customer by mistake
A legitimate payment refused because the fraud model scored it risky. The industry also calls it an "insult."
Your card declines on holiday because a beach town at midnight didn't fit your pattern.
Why it matters: the decline you never notice costs more than the fraud you do — and most teams only measure one side.
PART 03

The scoreboard.

$33.4B
global card fraud losses, 2024 — on $51.9T of volume (Nilson Report)
42%
of global fraud losses hit the US — on only 26% of global card volume. CNP-heavy, magstripe legacy, scam testing ground
$41B
projected annual losses by 2030 — fraud grows with volume, never disappears
~6.5¢
lost to fraud per $100 of card volume globally — the "tax rate" the whole system prices in

The defense, in layers — every checkout you've ever used runs this gauntlet invisibly: velocity rules (100 cards from one IP? blocked) → device fingerprinting (is this browser who it claims?) → ML risk scoring (does this purchase fit the pattern?) → 3DS step-up (make the bank check) → manual review (a human, for the weird ones). Each layer is cheap to pass for you and expensive to pass at scale for a bot. That asymmetry is the entire science of fraud prevention.

WHEN IT BREAKS

When the defense fails.

Three mornings every payments team eventually has, and what each one actually means. Then a tree for the day a spike hits your dashboard.

FAILURE 01 · THE TESTING STORM
Your checkout becomes the lab
WHAT YOU SEEOvernight, thousands of $0–$2 authorization attempts hammer your checkout or donation page. Your approval rate collapses.
WHYBots are using your payment page to sort stolen cards. And the network counts the storm against you: Visa's monitoring tracks enumeration, so an unblocked attack can land the victim in a compliance program.
THE FIXRate-limit the checkout, challenge repeated attempts from one device, require CVV and postal code, and alert on approval-rate drops. The networks expect victims to block the attack — and fine the ones who don't.
FAILURE 02 · THE CLEAN TAKEOVER
The fraudster is your best customer
WHAT YOU SEEDispute claims from long-standing customers on orders that passed every check — right device, right history, new shipping address.
WHYCredential stuffing. Passwords reused across sites let the attacker log in as the customer and spend the saved card. Card-level defenses see nothing wrong, because nothing about the card changed.
THE FIXPasskeys or two-factor on login, a step-up check when a new shipping address or payout target appears, and a new-device alert the real customer will actually see.
FAILURE 03 · THE INSULT SPIRAL
The model blocks the good ones
WHAT YOU SEEFraud losses fall. Revenue falls faster. Regulars quietly stop coming back after one "your card was declined."
WHYThe rules were tightened after an attack and nobody measured the other side. False declines never show up on a fraud dashboard — they show up in churn, months later.
THE FIXMeasure the insult rate next to the fraud rate: declined orders recovered on retry, declines that generate support tickets. Review whichever rule fires most often on good customers.
A FRAUD SPIKE HIT. WHICH SPECIES IS IT?
1 · Are the transactions tiny, fast, and clustered on one device, IP range, or card range?
CARD TESTINGYou're the lab. Block at the gate — rate limits, device challenges, CVV checks — and document the response; the network's monitoring programs will ask what you did.
NORMAL-SIZED ORDERS — KEEP GOINGReal baskets, real amounts? Go to step 2.
2 · Did the orders come from existing accounts, shipping somewhere new?
ACCOUNT TAKEOVERThe login is stolen; the card is fine. Force re-authentication, review recent address and email changes, and check which other accounts share the same device.
NEW CUSTOMERS OR NO PATTERN — KEEP GOINGGo to step 3.
3 · Are the disputed orders real purchases, delivered, by genuine customers?
FRIENDLY FRAUDFight with evidence — delivery proof, usage logs, a billing descriptor people recognize — and make refunds easier than disputes. See how disputes actually work.
NONE OF THE ABOVECheck your own systems first. A misfiring retry loop or a confusing descriptor produces "fraud spikes" with no fraudster anywhere.
COMMON QUESTIONS — ASKED PLAINLY

The things everyone wonders.

Five questions people actually ask after a fraud scare.

HOW DID SOMEONE GET MY CARD NUMBER?
Almost never by targeting you. Card numbers leak in bulk — a breached merchant database, a phishing page, a skimmer on a gas pump — and get sold wholesale for cents to a few dollars each. Your number was one row in a spreadsheet of thousands. That's also the good news: bulk theft is why banks catch most of it quickly, because the same breach lights up patterns across thousands of cards at once.
WHY DID MY BANK BLOCK MY COMPLETELY NORMAL PURCHASE?
The fraud model scored it unusual, and unusual is relative to your pattern: a new city, an odd hour, a first-time merchant category, a bigger amount than your average. Banks accept a certain rate of these false alarms as the price of catching real fraud fast. The approve-it-in-the-app flow exists exactly for this moment — one tap teaches the model, and the retry usually goes through.
WHO ACTUALLY LOSES THE MONEY WHEN FRAUD HAPPENS?
Follow the liability rules. Stolen card used online: usually the merchant eats it through a chargeback. Counterfeit card at a chip terminal: the issuer — or a magstripe-only merchant, under the liability shift. A scam where you pressed send yourself: historically you, though that is changing — the UK now forces banks to reimburse most authorized-scam victims, and other countries are watching. The customer who promptly reports a stolen card is the best-protected party in the whole system.
IS TAPPING MY CARD SAFER THAN SWIPING IT?
Yes, meaningfully. A swipe hands over your real card number from a static magnetic stripe that a $30 skimmer can copy. A tap or chip insert generates a one-time cryptogram, and a phone tap doesn't even transmit your real number — a token stands in for it. Counterfeit-card fraud collapsed in every country that moved to chips. The fraud moved online instead, which is why the rest of this chapter exists.
WHAT ACTUALLY PROTECTS ME, BEYOND LUCK?
Three habits cover most of it. Use unique passwords or passkeys — account takeover runs on reuse, and it's one of the fastest-growing attacks. Turn on transaction alerts — fraud caught in minutes is a non-event; fraud found on a statement is a project. And treat urgency as a red flag: no real bank needs you to move money right now to keep it safe. Today's worst scams skip your card entirely and talk you into pressing send yourself.
FIELD NOTES — THE PRO LAYER

For the professionals.

The defender's handbook: what the models actually look at, decline strategy, monitoring programs, and fraud's geography.

VELOCITY & DEVICE SIGNALS — WHAT THE RULES ACTUALLY CHECK
'Velocity rules' means counting things per key per window: cards per device per hour, attempts per IP per minute, accounts per shipping address per week, BIN spread per session. Card-testing attacks light these up first — hundreds of $0–$1 auths from one device fingerprint. The fingerprint itself blends dozens of signals (user agent, screen metrics, fonts, canvas/WebGL rendering quirks, timezone-vs-IP mismatch), producing an ID that survives cookie clearing. Above rules sit ML scores consuming the same features plus history. The craft is the action ladder: silent-allow, step-up (3DS challenge), soft-block with retry, hard-block — because a false positive costs a customer while a false negative costs one basket. Mature teams tune to a cost function, not an accuracy number; a model that blocks $10 of fraud by declining $200 of good coffee is worse than no model.
DECLINE STRATEGY — THE REVENUE SIDE OF RISK
Fraud teams famously own declines but not their cost. The pro view: issuer declines split into hard (stolen card, closed account — never retry) and soft (insufficient funds, do-not-honor, suspected fraud — retry windows exist). The toolkit that recovers revenue: correct CIT/MIT tagging (merchant-initiated retries are judged differently), account updater and network tokens (fix expired/reissued cards silently), smart retry timing (after payday beats midnight), and 3DS step-up as an alternative to declining outright. Issuers run the mirror image: their 'suspected fraud' declines on good customers drive cards to the back of the wallet. The industry's dirty secret is that false declines cost multiples of actual fraud — estimates vary widely, but every serious study puts insult losses far above fraud losses. Optimize both sides or you're not optimizing.
MONITORING PROGRAMS — THE NETWORK IS WATCHING YOU TOO
Merchants worry about fraudsters; professionals also worry about the networks' surveillance of merchants. Visa's VAMP tracks your combined fraud-plus-dispute ratio (excessive at 1.5% for US/CA/EU/AP since 1 Apr 2026 — verified Jun 2026) and counts enumeration attacks separately — meaning being the victim of card testing can put you in a program if you don't block it. Mastercard runs parallel excessive-fraud/chargeback tiers. Acquirers, who eat the fines first, respond commercially: reserves up, pricing up, or termination. The operational takeaway: your fraud rate is a license to operate metric, not merely a loss metric, and 'we got attacked' is an explanation, not an exemption.
FRAUD HAS GEOGRAPHY — ATTACK MAPS FOLLOW CONTROL MAPS
Fraud concentrates wherever the local control stack is weakest. The US: card-not-present fraud dominates (late EMV migration pushed fraud online, no SCA mandate keeps it there). Europe post-PSD2: CNP fraud suppressed by SCA, so losses migrated to APP scams — social-engineering the human, the one factor SCA can't patch. UK: APP losses rival card fraud outright, hence the mandatory reimbursement regime. India: OTP-based 2FA pushed attacks toward SIM swap and mule-account networks; UPI's scale made collect-request scams a category. Brazil: Pix's speed produced kidnapping-adjacent coercion fraud, answered with night-time transfer limits and MED claw-backs. Design lesson: every control migrates fraud somewhere; the map of attacks is the map of controls, shifted six months.
THE FRAUD STACK — WHO SELLS WHAT
The vendor market breaks into layers: device intelligence (fingerprinting SDKs), identity verification (document + selfie at onboarding — the KYC step), transaction risk scoring (the ML engines inside PSPs or standalone), 3DS/authentication orchestration, chargeback tooling (alerts like Verifi/Ethoca that intercept disputes pre-chargeback, plus representment automation), and consortium data — the quiet moat, because fraud signals compound across merchants: the device that hit five other shops this hour is the signal no single merchant can see alone. This consortium effect is why fraud prevention consolidated into big platforms, and why 'we see X% of global e-commerce' is the sales pitch that actually matters.
PART 04

Remember three things.

1
Fraud migrates; it never dies. Chips killed counterfeiting → fraud went online. Tokenization hardened checkout → fraud became account takeover. Instant rails killed chargebacks → fraud became persuasion. Every defense is a redirection.
2
The bill always lands on whoever could have prevented it. CNP → merchant. Counterfeit at a chip terminal → issuer. APP scam → increasingly the bank, by regulation. Liability design is fraud policy.
3
~6.5 basis points is the system's pain tolerance. Fraud could be near-zero — with so much friction nobody would buy anything. The industry deliberately tunes for conversion over prevention, and prices the leftovers into your fees.