What card not present fraud is and why every Shopify order carries it


TL;DR
Card not present fraud is a fraudulent purchase made without the physical card, which online means someone using a card number that is not theirs. Every Shopify order is a card-not-present transaction, so the merchant carries the fraud loss, not the bank. You get two defenses, prevention at checkout (AVS, CVV, 3D Secure) and representment after (Visa Compelling Evidence 3.0), and neither removes the dispute from your monitoring ratio.
Card not present fraud is a fraudulent purchase made without the physical card, which on the web means someone checking out with a card number that is not theirs. Every order on a Shopify store is a card-not-present transaction: the card is never dipped, tapped, or seen, so nothing at checkout proves the person holding the number is the person the bank issued it to.
That single fact decides who pays when a charge turns out fraudulent: you, the merchant, not the bank.
Card-absent fraud, CNP chargebacks, and the Visa fraud reason code all sit under this one umbrella. The ranking guides tend to stop at definitions; this is the operator version: how the loss reaches you, who eats it, and the two things you can actually do about it.
What is card-not-present fraud?
Card-not-present fraud (CNP fraud, also called card-absent fraud) is any unauthorised transaction where the card is not physically presented to the seller. Ecommerce is the obvious case. Phone and mail orders, and any checkout where a number is keyed rather than read from a chip, fall in the same category.
Ecommerce is the target for a structural reason. When the US finished migrating to EMV chip cards, counterfeiting a card for in-store use stopped working, so that fraud moved to the one channel where a chip proves nothing: online. A stolen card number, a matching billing address bought in the same breach, and a checkout form are all a criminal needs. US card fraud is now overwhelmingly card-not-present, and a Shopify catalogue sits squarely in the blast radius.
Who is liable for card-not-present fraud?
You are. This is the part that surprises operators moving from a physical shop.
In a card-present sale, the EMV liability shift put counterfeit-fraud losses on whichever party is least secure, usually the issuer after the chip rollout. Card-not-present sales never got that protection by default. The networks decided the merchant, who chose to accept a transaction it could not physically verify, carries the risk.
The merchant carries the loss, not the bank
In a card-not-present transaction the merchant accepts fraud liability, not the issuer. Verifi, a Visa solution, puts it plainly: "Since there is inherent risk in accepting these CNP transactions, the merchant accepts liability for each transaction (rather than the issuer)" (verifi.com, checked 2026-08-07). When the cardholder disputes, the issuer pulls the money back and you are usually out the goods too.
| Card present | Card not present | |
|---|---|---|
| Where it happens | in-store terminal | ecommerce, phone, keyed entry |
| How the card is verified | chip and PIN, or tap | card number and a few text fields |
| Who usually carries fraud loss | the issuer, after EMV | the merchant |
| Common fraud reason code | rare, mostly counterfeit | Visa 10.4, card-absent |
| Default liability shift | already sits with the issuer | none, unless you authenticate |
The practical shape of it: a criminal buys, you ship, the real cardholder reads the statement and files what a chargeback is. The issuer reverses the money, and you have lost the product too. A card-present merchant hit by the same stolen card would, in most cases, have the issuer absorb it.
How does a card-not-present fraud chargeback arrive?
It arrives with a code. On Visa, card-not-present fraud is dispute condition 10.4, Other Fraud, Card-Absent Environment. The cardholder tells their bank they did not authorise the charge, the bank files the 10.4, and the money leaves your account before you argue anything. Mastercard files the same claim as 4837. Each network runs its own list, which is why it pays to read Visa chargeback reason codes as their own document.
Two uncomfortable details sit inside a 10.4. The claim looks identical whether a criminal used a stolen card or the actual cardholder is denying a purchase they made, and your own order history is the only thing that tells them apart. Whichever it is, the dispute counts toward your Visa monitoring ratio the moment it is filed. Winning the representment recovers the money, not the case from the ratio.
How do you prevent card-not-present fraud?
Prevention is checkout screening, and every tool in it is partial. The three you will meet on Shopify:
| Control | What it checks | What it misses |
|---|---|---|
AVS | billing address numbers match the issuer's record | a criminal who bought the billing address in the same breach |
CVV | the security code was entered at checkout | anyone holding the full card details |
| 3D Secure (3DS2) | the issuer authenticates the cardholder, and can shift fraud liability to the issuer | non-fraud disputes, plus conversion lost to the extra step |
AVS and CVV are cheap and worth running, but neither stops a criminal holding full card details, which is most of what a data breach produces. 3D Secure (3DS2) is the only one that changes liability: on a transaction the issuer authenticates, fraud liability moves to it, and a later 10.4 generally cannot reach you. The cost is friction at the moment a customer decides whether to finish, and it does nothing for non-fraud disputes.
There is a second layer that screening misses entirely. A share of 10.4 disputes are not criminals at all, but real customers who did not recognise the billing descriptor or forgot the order, and screening waves them through because nothing looks wrong. Preventing the avoidable disputes screening cannot see, and deflecting a dispute in the window before it is formally filed, are the levers for that slice. Neither replaces fraud screening; they work on the disputes screening was never going to catch. For the layered view, chargeback protection walks the full stack.
Can you fight a card-not-present fraud chargeback?
Yes, for a share of them, through representment. The rule written for exactly this is Visa Compelling Evidence 3.0. It lets you answer a 10.4 by showing the cardholder already has a history with you.
Visa's own Compelling Evidence 3.0 merchant material (usa.visa.com, checked 2026-08-07) sets the test: two previous undisputed transactions, at least 120 days old and no older than 365 days from the dispute date, with at least two core data elements matching between them and the disputed order (User ID, IP address, shipping address, or device fingerprint), and one of those two matches must be the IP address or the device fingerprint. Meet it and liability can shift back to the issuer.
The catch is in the requirement: you need two prior clean orders on the same card. A first-time buyer, and any store built on one-off purchases, cannot qualify. Representment here is a tool for merchants with repeat customers, aimed at disputes where the cardholder genuinely transacted with you before.
Assembling one representment is 20 to 45 minutes of pulling delivery confirmation, matching data points, and writing it up, and each dispute carries a fee of roughly $15 to $25 win or lose. Reclaim files the representment for you, and it is completely free: no install cost, no success fee, and you keep 100% of what it recovers.
Reclaim is free
Redo funds the representment. Evidence is built and filed before the bank's deadline, and you keep 100% of what comes back.
Get started freeThe honest part
Two layers, and both have holes.
Prevention is a probability game, not a wall. Turn on AVS, CVV, and selective 3D Secure, and a determined criminal with full card details and a matching address still gets through. Turn 3D Secure on for every order and you lose real customers to friction, most of whom were never going to dispute.
Representment only reaches the disputes that qualify. Compelling Evidence 3.0 needs two clean orders between 120 and 365 days old, so your newest customers, the ones fraud tends to target first, are exactly the ones you cannot defend this way. You pay the fee regardless.
And the ratio forgives none of it: a 10.4 counts whether you win, lose, or never respond. VAMP uses a single count-based ratio, with an excessive-merchant threshold of 150 basis points (1.5%) across the US, Canada, Europe, AP, and LAC as of April 1, 2026, and 220 basis points in CEMEA. Those numbers move, so check Visa's current fact sheet. A run of card-not-present fraud can push you into a monitoring program in a quarter where you won most of the disputes.
Be careful with the loss figures you read, too. The clean, card-not-present-specific dollar numbers I chased sit behind paywalled reports, and vendor-blog headline figures mix channels and methodologies. The structural fact holds regardless: in a card-not-present sale, the loss lands on you.
Frequently asked questions
What is a card-not-present transaction?
A card-not-present (CNP) transaction is any payment made without the physical card presented to the seller: ecommerce, phone, and mail orders. Every Shopify checkout is card-not-present, which is why the merchant, not the issuing bank, carries the fraud liability on these sales by default.
Which reason code is card-not-present fraud?
On Visa it is dispute condition 10.4, Other Fraud, Card-Absent Environment, filed when a cardholder claims they did not authorise a card-absent charge. Mastercard files the same claim as 4837. The same code covers both a criminal using a stolen card and a cardholder denying a purchase they actually made, so your order history is what separates them.
Does 3D Secure stop card-not-present fraud?
It shifts liability rather than stopping fraud. On a transaction the issuer authenticates through 3D Secure (3DS2), fraud liability for a later card-absent dispute generally moves to the issuer. It does nothing for non-fraud disputes such as item not received, and the extra checkout step can cost conversion, so many merchants apply it selectively rather than to every order.
Can you win a card-not-present fraud chargeback?
Sometimes, through representment under Visa Compelling Evidence 3.0, which needs two prior undisputed transactions on the same card, 120 to 365 days old, with matching data points. Winning recovers the money but does not remove the dispute from your Visa monitoring ratio, so prevention still matters even when your win rate is high.
Pull last quarter's 10.4 disputes and split them two ways. First, did the same customer have two clean orders on that card between 120 and 365 days ago? That pile is your Compelling Evidence 3.0 candidates. Second, of the rest, how many went to an address or account you had never seen before? That pile is genuine third-party fraud, a checkout-screening problem, not a dispute problem. The two piles need different fixes, and the count in each tells you where the next hour is better spent.