Fraudsters running CNP schemes tend to be patient, sophisticated operators who continuously adapt to whatever a merchant's current defenses are. Recognizing the pattern of a scheme is usually the fastest way to catch it.
Eight schemes worth knowing
- Card generator fraud: systematically testing generated numbers against specific issuing banks, often ones with weaker security. Caught by watching velocity of use and velocity of change across transactions.
- Consumer satisfaction fraud: a customer disputes a legitimate purchase through a chargeback. Warm and hot lists with a two-strikes policy for repeat offenders help here.
- Credit & return fraud: buying with a stolen card, then returning the merchandise for a cash refund — especially common in omnichannel retail.
- Collusive fraud: an employee feeds security protocol details to a fraudster, or processes unauthorized transactions directly.
- One-hit schemes: a single high-value, easily resold purchase (electronics, jewelry) shipped express to a drop address.
- Morphing fraud: repeated attacks using slightly altered data each time — bust-outs, slow morphs, and multiple-personality attacks that can run for weeks or months.
- Fraud rings: organized groups that research a merchant's specific vulnerabilities before executing a coordinated, large-scale attack — often timed around the holidays.
- Identity theft: the most dangerous scheme, since stolen personal data lets the fraudster look exactly like a legitimate consumer. The FTC estimates roughly 700,000 cases a year.
What actually counters these
- Velocity checking — transaction frequency and data-point changes over time
- Hot and warm listing
- Geolocation verification
- Consumer authentication
- Fraud screening with cross-merchant visibility
- Address and phone reverse lookups
- Signature-required delivery