Every online payment is a card-not-present transaction. Nobody checks a signature, nobody sees the buyer, and the merchant carries the liability if the card turns out to be stolen. That liability shift is the whole reason this term exists, and it is why an online shop and a physical one with identical turnover are treated so differently by acquirers.
The good news is that most of the exposure is manageable with ordinary measures. The bad news is that the measures interact: tighten one and you lose honest customers, loosen another and losses climb.
Three different things called fraud
Stolen card details. Someone uses card data they obtained elsewhere. The real cardholder disputes, the money comes back out of your account and the goods are gone. This is what most people mean by fraud, and it is the easiest kind to reduce technically.
Friendly fraud. The buyer made the purchase and disputes it anyway — sometimes dishonestly, often because a family member ordered, or because the descriptor on the statement was unrecognisable. No fraud filter catches this, because the transaction was genuine.
Testing. Automated attempts to find working card numbers by running tiny payments through your checkout. Your losses are small per attempt, but the decline rate spikes and acquirers notice. Platforms with free trials and low-value products get hit most.
The three need different answers, which is why «anti-fraud» as a single switch rarely helps.
What reduces stolen-card losses
Authentication is the strongest tool, since a successfully authenticated transaction usually shifts liability away from you. The question is when to apply it: on everything, and conversion suffers; on nothing, and you carry every loss. The practical approach is risk-based — authenticate when the signals look unusual and let the rest through. How this is configured sits in our processing setup.
Beyond that, the basics still work. Send full transaction data rather than the minimum, since address and device details give the issuer something to judge. Watch for mismatches between billing country, card country and delivery address. And set velocity limits, because a real customer rarely tries six cards in four minutes.
What reduces friendly fraud
This one is solved with clarity rather than technology. The single most effective change is the billing descriptor: if your statement line does not obviously match the brand the customer bought from, you will collect disputes from people who simply did not recognise the charge.
After that comes documentation. Keep what was bought, when it was delivered and what the customer agreed to, in a form you can produce months later. Disputes are won on evidence, and most merchants lose them by default because nobody collected any. Make support reachable too — a customer who can get a refund in two minutes does not call the bank.
What happens if you ignore it
Card schemes monitor dispute and fraud ratios, and crossing a threshold is not a conversation about money but about whether you continue processing. Programmes differ in detail, yet the pattern is the same: a warning period, a fee per event, then restrictions. An acquirer will usually warn you first, which is only useful if someone on your side is watching the same numbers.
That makes monitoring the real deliverable. Fraud rate, dispute rate and decline rate, tracked weekly rather than quarterly, give you time to react before anyone else does. We publish those in the merchant account reporting rather than on request.
What belongs in your own rules
A surprising share of disputes is prevented by text rather than technology. Your refund policy, delivery times and contact details are read by the issuing bank when it decides a dispute, and vague versions of all three make the merchant look careless.
Write the refund window as a number of days rather than «reasonable period». State who pays return shipping. Put a working contact that a person actually monitors, because a bank that cannot see any attempt to resolve things sides with the cardholder. None of this costs money, and it moves outcomes.
The payment methods you offer matter here too: methods with weaker dispute rights shift the balance, and the mix should be a deliberate choice.
Recurring questions are answered in our FAQ.
Where to set the dial
There is no universal setting, because the cost of a false decline differs by business. A shop selling a two-hundred-euro item can afford to authenticate more aggressively than one selling a five-euro subscription, where every extra step costs more than the fraud it prevents.
Start from your own numbers: what a lost order is worth, what a chargeback costs including the fee, and what share of your traffic is cross-border. Then set rules per segment instead of globally. It takes an afternoon and saves the argument that otherwise repeats every quarter.
The commercial side is on the pricing page, where rates for middle-risk businesses start from 1.8%.
The setup steps are on how it works.
Connection from 5 days. Fees from 1.8% — transparent terms, no hidden charges. Leave a request or book a consultation and we will put together the right setup for your niche and risk profile.

