Fraud defense

Preventing Card Fraud at Your Business

Fraud looks different at a counter, on a website and over the phone. The defenses are different too, and most of them are affordable.

Card fraud is not a single problem. A stolen card used at your counter, a stolen number typed into your checkout and a staff member skimming at the register are three separate threats, each needing a different defense. When fraud succeeds, you often bear the cost: the goods are gone, the payment is reversed and a chargeback fee lands on top.

The encouraging part is that the biggest gaps are usually the simplest to close. The card networks and your processor offer tools for each channel, and a few disciplined habits at the point of sale do much of the rest. Here is how to protect each part of your business.

Key takeaways

  • Fraud differs by channel, so match your defenses to how you accept payment.
  • Use the chip or tap in person; the EMV liability shift puts counterfeit risk on merchants who do not.
  • Require address and security code checks on card-not-present sales and consider 3-D Secure.
  • Limit payment attempts to blunt card-testing bots.
  • Employee controls and daily void and refund reports catch internal fraud early.

In person: use the chip and the tap

Chip cards generate a unique code for each transaction, which makes counterfeit cards far harder to use than the old magnetic stripe. Since the EMV liability shift, a merchant who still swipes a chip card on a non-chip terminal can be responsible for counterfeit losses that would otherwise fall on the issuer. That is the strongest reason to run an EMV-capable terminal and insist on the chip.

Contactless payments and mobile wallets add another layer, because they use one-time values and the actual card number is never shared with the terminal. For larger purchases, compare the name on a photo ID with the card and watch for cards that have been obviously altered, but never rely on a signature as protection.

Online and by phone: verify what you can

Without the card in hand, you lean on data. Address verification compares the billing postal code and street number with the issuer's records, and the security code on the back confirms the buyer has the physical card. Both are inexpensive and should be required on every card-not-present order. For riskier transactions, 3-D Secure sends the cardholder through an authentication step and can move liability for certain fraud disputes to the issuer.

Pay attention to context. Orders for unusually large quantities, shipping addresses that differ sharply from the billing address, rush shipping on a first order and several declined attempts followed by a success all deserve a second look before you ship.

Watch for card testing

Criminals with lists of stolen numbers often test them on small online purchases or donation forms to see which still work. You may see dozens or hundreds of tiny charges in minutes, many declined. Defenses include limits on attempts per visitor or IP, CAPTCHA at checkout, requiring security codes and blocking suspicious regions where you do not sell. Act quickly when you see a burst, because large volumes of declines can attract attention from issuers and your processor.

Inside your business

Not all fraud comes from outside. Staff with access to the terminal can issue refunds to their own cards, skim numbers or void sales and pocket cash. Basic controls make this much harder:

  • Give each employee a unique login and review a daily report of voids, refunds and no-sale openings.
  • Require manager approval for refunds above a set amount, and refund only to the original card.
  • Keep terminals in sight and inspect them periodically for tampering or unfamiliar attachments.
  • Never allow staff to write down or photograph card numbers.
  • Rotate who closes the register and reconcile batches against the deposit.

Layer your defenses

No single tool stops everything, and extra friction costs sales, so tailor the mix to your risk. A low-value, in-person business needs a chip reader, wallet acceptance and basic staff controls. A website selling electronics needs address and code checks, 3-D Secure on larger orders and manual review rules. A business taking phone orders needs a tight routine for verifying new customers and storing nothing it should not.

Protect your own environment as well. Complete your PCI self-assessment, keep software current, use strong unique passwords with multi-factor sign-in on your payment portals and limit who can access them.

A fraud-readiness checklist

Use this as a starting point for a quarterly review:

  1. Confirm every terminal reads chip and contactless and that staff do not bypass the chip.
  2. Require security code and postal code on all keyed and online orders.
  3. Decide which orders trigger manual review and who handles it.
  4. Enable attempt limits and challenges on your checkout.
  5. Review void and refund reports weekly.
  6. Turn on multi-factor sign-in for the payment dashboard.
  7. Write down what to do when you suspect fraud, including who to call.

Help from MCCPS

MCCPS offers EMV and contactless hardware, reporting that makes unusual activity visible and free 24/7 technical support. The team can also review your statements for fraud-related fees and chargeback patterns during a free analysis. Call 844.826.6227 to talk about the right layers for how you sell.

Frequently asked questions

Who pays when a fraudulent card is used at my business?

It depends on how the card was accepted. If the fraud is disputed and you did not follow the rules, such as swiping a chip card where chip was available, the loss can fall on you through a chargeback. Following chip, verification and authentication practices shifts more risk away from you.

Does asking for ID stop card fraud?

It helps with obvious mismatches but is not reliable on its own, and some card network rules restrict requiring ID as a condition of payment. Rely mainly on chip and tap authentication, then use ID checks at your discretion for suspicious situations while following your processor's policies.

What is 3-D Secure?

3-D Secure is an authentication step for online card payments in which the issuer may ask the cardholder to verify the purchase, for example with a code or app approval. When it succeeds, liability for certain fraud chargebacks can shift to the issuer. It can add friction, so many merchants use it selectively.

How can I tell if my website is being card-tested?

Look for bursts of small transactions, many declines, repeated attempts from the same IP address or unusual patterns of cards from different countries. Set alerts with your gateway, limit attempts, require security codes and add a challenge at checkout. Contact your processor early if you see a surge.

Do small businesses really need fraud tools?

Yes, because criminals often target businesses they expect to be less protected. Most useful protections are inexpensive or already included, such as EMV, address and code checks and staff reports. Start with the basics suited to your channel, then add layers as volume or risk grows.

#merchant fraud prevention#card not present fraud#counterfeit card fraud#3-D Secure#AVS CVV checks#card testing

This article is general information, not legal, tax or compliance advice. Card-network and state rules change — confirm current requirements before acting. Savings depend on your individual statement analysis.

Need working capital? MCCPS merchants can explore business funding through our partner Fidelity Funding — fast decisions, soft pull only.

Visit Fidelity Funding
👋 Hi! Tell me your monthly card sales and I’ll estimate what processing is costing you.