eCommerce fraud has been evolving since eCommerce itself began in 1994 — and the throughline hasn't changed: whatever the motivation, money, thrill, or intellectual challenge, it comes down to the intent of taking goods or services by trick or device.
What the internet actually changed
Removing face-to-face interaction removed the built-in checks that came with it. A phone order gave a representative the chance to ask clarifying questions and pick up on something being off; an online order gives a fraudster the anonymity to mask themselves by simply faking whatever data points get sent.
Early fraud trends (mid-1990s)
- The "famous names" attack: fraudsters exploited the total absence of name verification by placing orders under names like Mickey Mouse and Bill Clinton
- Card generators: applications that generated valid-format credit card numbers, distributed freely online
- Cross-merchant attacks: fraudsters shifted from hammering one merchant to hitting many sites with fewer attempts each, specifically to avoid detection
Escalating sophistication (late 1990s–2000)
- Testing stolen cards with small purchases before a full shopping spree
- Hijacking shipments by changing the delivery address after the order was placed
- Standing up dummy merchant sites specifically to launder fraudulent transactions
- Mass identity theft using data pulled through Freedom of Information Act requests
- Account takeover exploiting weak verification during account changes
- Organized fraud rings operating systematically across continents
How merchants responded — and the gap that remained
Merchants began requiring account verification for repeat purchases, but fraudsters simply adapted, changing card information within an already-established account to route around the new protections.
The scale of the gap is still stark: Visa estimates online fraud runs roughly seven times higher than card-present fraud, with some analysts putting the multiple as high as twelve times.