What Are the Most Common Types of Payment Fraud?
Payment fraud takes many forms, and the controls that stop one type often do nothing against another. A business that has locked down its online checkout can still lose money to a fake invoice emailed to its finance team, and a business with strong internal controls can still absorb chargebacks from stolen cards.
Understanding the main fraud types helps you match controls to the risks your business actually faces, rather than treating fraud as a single problem.
What are the main types of payment fraud?
Stolen card and card-not-present fraud
A fraudster uses stolen card details to pay online, where no physical card or PIN is needed. The genuine cardholder later disputes the transaction and the merchant absorbs the chargeback. The strongest defence is 3D Secure authentication, which verifies the cardholder with their bank and generally shifts fraud liability to the issuer.
Friendly fraud
A genuine customer makes a purchase and then disputes it dishonestly — claiming they never received it, or that they did not authorise it — to get the goods and their money back. It is one of the hardest types to prevent because the transaction itself looks completely legitimate. Good chargeback evidence is the main defence.
Card testing
Fraudsters run large volumes of small transactions through a checkout to find out which stolen card numbers still work. The merchant suffers fees, declines and scheme scrutiny even though the individual amounts are tiny. See card testing and velocity checks.
Phishing and vishing
Fraudsters impersonate a bank or payment provider by email, SMS or phone call to trick victims into revealing card numbers, PINs, passwords or one-time PINs. A simple rule protects against most of it: banks and legitimate payment providers never ask for your PIN, password or full card details by phone, SMS or email. Any such request is phishing.
Invoice and business email compromise (BEC) fraud
A fraudster intercepts or imitates business email and sends a fake invoice, or a "change of banking details" notice, so that a legitimate payment is made to the fraudster's account. The defence is procedural: always verify banking detail changes through a known, independent channel — a phone number you already have, not one on the suspicious email.
Proof of payment (POP) fraud
A fraudster sends a forged proof of payment — a doctored EFT notification or fake SMS — and pressures the seller to release goods before the money reflects. Never release goods on a proof of payment alone; wait for cleared funds in the account.
Refund abuse
Customers exploit refund policies — claiming non-delivery of items that arrived, returning used or swapped goods, or systematically abusing goodwill refunds. Delivery confirmation and per-customer refund tracking limit the damage.
Money mule activity
Fraudsters recruit account holders to receive and forward stolen funds, disguising the money trail. Businesses can be exposed when paying out to mule accounts. This is one of the risks that KYC and AML controls are designed to catch.
How do you match controls to fraud types?
| Fraud type | Primary control |
|---|---|
| Stolen card / CNP | 3D Secure, AVS/CVV checks |
| Friendly fraud | Evidence retention, clear descriptors, proof of delivery |
| Card testing | Velocity checks, CAPTCHA, risk rules |
| Phishing / vishing | Customer and staff awareness, never sharing credentials |
| Invoice / BEC fraud | Out-of-band verification of banking details |
| POP fraud | Release goods only on cleared funds |
| Refund abuse | Delivery tracking, refund limits per customer |
| Money mules | KYC, transaction monitoring |
No single control covers everything, so layered defences matter: authentication at checkout, monitoring behind it, and trained people around it.
Related topics
Debit Order Disputes
How customers dispute debit orders through their bank, the timeframes and mandate rules that decide the outcome, and how DebiCheck changes the picture.
Card Testing and Velocity
How fraudsters use card testing attacks to validate stolen card numbers, and how velocity checks, CAPTCHAs and risk rules protect your checkout.