Credit card fraud has moved off the physical card and onto the checkout page. This post breaks down the types of criminals still use, what each one costs and who absorbs it, and the practical checks that protect you, including one common safety test that no longer works the way most people think it does.
Ever since credit cards were introduced, credit card fraud has been climbing. You need to stay a step ahead, because as security mechanisms get tougher, criminals get smarter too. It is not always a clever or sophisticated hack that compromises your data. Sometimes it is you. In a large share of credit card fraud cases, users have been careless with passwords and PINs, clicked a fraudulent link, or shared personal data, which makes them an easy target.
Credit card fraud has many shapes and forms, and the purpose varies. Some frauds are committed to push through one large transaction, others to buy expensive goods for free. The volume now sits online. UK Finance reported £703.4 million in unauthorised fraud losses across 3.81 million cases in 2025, and remote purchase fraud, where stolen card details are used to buy something online, accounted for £423.5 million of that across 3.2 million cases. Card fraud is no longer a story about a wallet going missing.
Types of credit card fraud
The six patterns below cover almost everything a card issuer sees. They differ in more than method. What matters operationally is whether the card is physically present, who ends up paying, and which control actually catches it.
| Type | How it works | Card present or CNP | Who usually absorbs the loss | Primary control |
| Lost or stolen card | The physical card is taken and used before the holder reports it | Both | Issuer, once reported | Fast reporting and card blocking |
| Application fraud | A stolen identity plus forged supporting documents is used to open a new card account | Not applicable | Issuer | Document and identity verification at application |
| Card not present, remote purchase | Card number, expiry and security code are used online, by phone or by mail | CNP | Merchant, through chargebacks, in most scheme rules | EMV 3-D Secure step-up and transaction monitoring |
| Counterfeit or cloned card | Card data is copied, often by skimming, and written to a duplicate card | Card present | Issuer or acquirer depending on EMV liability shift | EMV chip and contactless, skimmer detection |
| Synthetic identity fraud | A fabricated identity, often real data mixed with invented details, is used to obtain a card | Not applicable | Issuer, usually written off as credit loss | Data consistency checks and identity verification |
| Stolen identity and account takeover | The criminal takes over an existing account or orders a replacement card on it | Both | Issuer | Re-authentication at high-risk events |
Liability varies by country, card scheme and how the transaction was authenticated, so treat the fourth column as the general pattern rather than a rule. In the UK, victims of unauthorised card fraud are legally protected and banks refund almost all cases.
Lost and stolen card fraud
The card is either stolen or lost, and the thief uses it. A stolen card without the PIN is hard to use in a terminal, but the card details on it can still be used to make online purchases. The way to shut that down is to report the loss to your bank as quickly as possible so the card is blocked and further requests are rejected.
Application credit card fraud
This happens when someone applies to a bank for a new card in another person’s name. The identity is stolen first, then used to complete the application. Fraudsters use forged supporting documents to substantiate it. Banks often call the applicant back to confirm the identity, and that step can be defeated too if the criminal controls the phone number on file.
There are several ways to investigate the true owner, and each of them gets probed and worked around over time.
Card not present (CNP) fraud
If someone has your card number, expiry date and security code, they can commit CNP fraud against you. It can be done by mail, by phone or over the internet. Where a merchant asks for the security code, a criminal can run repeated small transactions to work through combinations until one is accepted.
Two controls have changed this picture since this article was first written. EMV 3-D Secure lets an issuer step up suspicious transaction monitoring up to an authentication challenge instead of approving or declining it blind. Tokenisation replaces the real card number with a token that is useless outside the merchant it was issued for, which is why a breach of stored card data is worth less than it used to be.
Counterfeit and cloned card fraud
Copying a card is difficult. There is a magnetic stripe, a chip, and in some cases a hologram, and forging that combination takes effort. A criminal who has captured the card data, usually through a skimmer, can produce a duplicate and use it in a terminal.
This is the one category that has genuinely shrunk. EMV chip and contactless authentication made cloned cards far harder to use at the point of sale, which is exactly why criminal effort moved to card-not-present fraud and to provisioning stolen cards into digital wallets. UK Finance reported that criminals in 2025 were compromising one-time passcodes to register cards to digital wallets they controlled.
Synthetic identity fraud
A fraudster uses a temporary address and a false name to obtain a credit card. Banks often keep a checklist requiring a passport or driving licence for verification. This fraud is hard to pull off, but a determined criminal will. The modern version rarely uses a wholly invented person. It blends real data, often a genuine national insurance or social security number, with an invented name and date of birth, then builds a credit history over months before drawing down every available line at once. Because no real victim is being impersonated, nobody reports it, which is why it usually surfaces as a credit write-off rather than as fraud.
Stolen identity fraud
This is committed by someone who knows your card number and password. They can push through a large transaction or order a new card on the account. It is the hardest fraud to recover from, because it is often only discovered once the transaction has already gone through. Where the criminal takes control of the online account itself rather than just the card details, it becomes account takeover fraud.
Tips to prevent credit card fraud
None of the advice below is complicated. It survives on this list because the same handful of habits still account for most consumer exposure.
Card lost or stolen? Report it immediately
When you realise your card is lost or stolen, call your bank and report it right away so the card can be blocked. Banks limit your liability for transactions made on the card, depending on which card you hold, from the time of loss to the time you report it. The gap between those two moments is the window a criminal is working in.
Shred statements and destroy expired cards
People usually crumple up old credit card statements and throw them away. Shred them instead, because they carry information a fraudster can use. Do not throw expired cards away intact either. Cut them up, and make sure the card number is destroyed. Switching to paperless statements removes the paper trail altogether, which is the simpler version of the same advice.
Beware of phishing scams
Phishing is one of the most common methods fraudsters use. A phishing message looks like a genuine email and carries a malicious link that prompts you to enter your card number, security code, or PIN on a fake site built for exactly that purpose.
It is still the single biggest category by volume. Phishing and spoofing were the most frequently reported complaint type in the FBI’s 2025 Internet Crime Report, which logged 1,008,597 complaints in total. The same report carried its first-ever section on artificial intelligence, covering 22,364 complaints and nearly $893 million in losses, with cloned voices and fake profiles among the tactics listed. The spelling mistakes that used to give a phishing email away are no longer reliable tells.
Check the source of any call and the sender of any email carefully. If you are unsure, hang up and call the bank back on the number printed on your card, not the one you were given.
Paying online? Check the site properly
The old advice was to look for a padlock icon and an address starting with https. Do not rely on it. Encryption certificates are free and automated, so the majority of phishing sites now use https, and most browsers have removed the padlock icon precisely because people read it as a trust signal it was never meant to be. All HTTPS tells you is that the connection is encrypted, not who is on the other end of it.
What is worth checking instead is the domain itself, character by character, because lookalike spellings are the whole trick. Reach the site by typing the address or using a saved bookmark rather than following a link from an email or an advert. Use a card rather than a bank transfer, since card payments carry chargeback rights that transfers do not. And turn on transaction alerts, which catch the fraud you did not prevent.
Monitor your account and act fast
Credit card fraud is rising, and scammers use everything from phone calls and email to card skimmers and public wifi hotspots to collect your information. You could be a victim without knowing it yet. What is required of you is vigilance and regular monitoring of your transactions. If you find a fraudulent charge on your card, contact your provider without wasting a minute. The small test transaction, a charge of a pound or two you do not recognise, is often the first move before a large one.
How Shufti helps card issuers stop fraud at the application
Two of the six fraud types above are decided before a card is ever used. Application fraud and synthetic identity fraud both succeed at the point where an issuer accepts a set of documents and a name at face value. Shufti verifies the applicant against the document they present, checks that a real and live person is behind the selfie, and runs the data consistency checks that expose an identity assembled from parts rather than belonging to one person. Verification returns in under three seconds at 99.8 per cent accuracy, across 240+ countries and territories and more than 10,000 document types, so the check sits inside the application flow rather than beside it.
See how document and biometric checks would sit in your card application flow in a 20-minute demo.
Frequently Asked Questions
What is the most common type of credit card fraud?
By volume, it is remote purchase fraud, the card not present category, where stolen card details are used to buy something online. UK Finance recorded £423.5 million of remote purchase losses across 3.2 million cases in 2025, which is the largest single component of unauthorised fraud losses in the UK.
What is card not present (CNP) fraud?
CNP fraud is any fraudulent transaction where the physical card is not used at a terminal. The criminal needs only the card number, the expiry date and usually the security code, then spends online, by phone or by mail. It grew as chip authentication made cloned cards harder to use in shops.
What is synthetic identity fraud and how is it different from stolen identity fraud?
Stolen identity fraud impersonates a real person, so there is a victim who eventually notices and reports it. Synthetic identity fraud builds a person who does not exist, often by combining a real identifier with an invented name and date of birth. Nobody reports it, because nobody was impersonated, and it typically surfaces as a credit loss rather than as fraud.
Am I liable if someone uses my stolen credit card?
In most cases the issuer carries the loss on unauthorised transactions rather than the cardholder. UK Finance states that victims of unauthorised fraud are legally protected and that banks refund almost all cases. Protection depends on your jurisdiction and on reporting the loss promptly, so check the terms that apply to your card and report as soon as you notice anything.
Does a padlock icon mean a payment site is safe?
No. The padlock only ever indicated an encrypted connection, not a legitimate business. Certificates are now free and automated, so phishing sites routinely have them, and browsers have removed the padlock icon for that reason. Check the spelling of the domain instead, and reach payment pages through a bookmark or a typed address rather than a link in an email.















