FAQ Section
Disputes and Compliance

What Are the Most Common Types of Payment Fraud?

 

The main types of payment fraud affecting South African businesses, from stolen cards and friendly fraud to invoice scams and refund abuse.

Payment fraud takes many forms, and the controls that stop one type often do nothing against another. A business that has locked down its online checkout can still lose money to a fake invoice emailed to its finance team, and a business with strong internal controls can still absorb chargebacks from stolen cards.

Understanding the main fraud types helps you match controls to the risks your business actually faces, rather than treating fraud as a single problem.

What are the main types of payment fraud?

Stolen card and card-not-present fraud

A fraudster uses stolen card details to pay online, where no physical card or PIN is needed. The genuine cardholder later disputes the transaction and the merchant absorbs the chargeback. The strongest defence is 3D Secure authentication, which verifies the cardholder with their bank and generally shifts fraud liability to the issuer.

Friendly fraud

A genuine customer makes a purchase and then disputes it dishonestly — claiming they never received it, or that they did not authorise it — to get the goods and their money back. It is one of the hardest types to prevent because the transaction itself looks completely legitimate. Good chargeback evidence is the main defence.

Card testing

Fraudsters run large volumes of small transactions through a checkout to find out which stolen card numbers still work. The merchant suffers fees, declines and scheme scrutiny even though the individual amounts are tiny. See card testing and velocity checks.

Phishing and vishing

Fraudsters impersonate a bank or payment provider by email, SMS or phone call to trick victims into revealing card numbers, PINs, passwords or one-time PINs. A simple rule protects against most of it: banks and legitimate payment providers never ask for your PIN, password or full card details by phone, SMS or email. Any such request is phishing.

Invoice and business email compromise (BEC) fraud

A fraudster intercepts or imitates business email and sends a fake invoice, or a "change of banking details" notice, so that a legitimate payment is made to the fraudster's account. The defence is procedural: always verify banking detail changes through a known, independent channel — a phone number you already have, not one on the suspicious email.

Proof of payment (POP) fraud

A fraudster sends a forged proof of payment — a doctored EFT notification or fake SMS — and pressures the seller to release goods before the money reflects. Never release goods on a proof of payment alone; wait for cleared funds in the account.

Refund abuse

Customers exploit refund policies — claiming non-delivery of items that arrived, returning used or swapped goods, or systematically abusing goodwill refunds. Delivery confirmation and per-customer refund tracking limit the damage.

Money mule activity

Fraudsters recruit account holders to receive and forward stolen funds, disguising the money trail. Businesses can be exposed when paying out to mule accounts. This is one of the risks that KYC and AML controls are designed to catch.

How do you match controls to fraud types?

Fraud typePrimary control
Stolen card / CNP3D Secure, AVS/CVV checks
Friendly fraudEvidence retention, clear descriptors, proof of delivery
Card testingVelocity checks, CAPTCHA, risk rules
Phishing / vishingCustomer and staff awareness, never sharing credentials
Invoice / BEC fraudOut-of-band verification of banking details
POP fraudRelease goods only on cleared funds
Refund abuseDelivery tracking, refund limits per customer
Money mulesKYC, transaction monitoring

No single control covers everything, so layered defences matter: authentication at checkout, monitoring behind it, and trained people around it.

Back to Refunds, Disputes, Fraud and Compliance.

Copyright © 2026 Kwik Payments