Security · 10 min read

How card fraud happens, and what stops it

Skimming, phishing, card-not-present testing and account takeover. How each one actually works, which control interrupts it, and the part no control covers.

By Vision Card ServicesPublished Updated 10 min read

Almost all card fraud is one of four things. Knowing which one you are looking at tells you what to do in the next five minutes, which matters more than knowing the statistics.

Four converging arrows meeting a solid vertical barrier, one of them deflected
Four routes in. One of them does not go through the card at all.

The controls that stop three of these four are ours. The fourth — persuading you to hand something over — is stopped only by one habit: nobody legitimate ever needs your one-time code.

1. Skimming, and why it has shrunk

Skimming copies card data at a physical device — a reader over an ATM slot, a tampered terminal, a handheld device in a back room. It was the dominant form of card fraud for years, and it worked because the magnetic stripe carried everything needed to make a working copy.

Chip changed that. A chip transaction produces a cryptogram unique to that payment, so a copy of the data cannot authorise a second one. Where chip and contactless are used, counterfeit fraud has become a marginal problem rather than the main one.Sources for this passage: EMVCo, the body behind chip and contactless specifications

What survives is the residue: stripe fallback where a terminal cannot read a chip, and ATMs in places with less physical oversight. Two habits still pay for themselves — cover the keypad, and glance at whether a slot or keypad looks or feels like an addition rather than part of the machine.

2. Phishing and impersonation, the one that still works

This is the largest category now, and it does not attack the card at all. It attacks you. A message that looks like a bank, a call that recites a real transaction, a link to a page that is a good copy of a login screen — the aim is to get a code, a password or a card number from a person rather than a system.

The reason it works is that the pretext is usually true. The caller may know your name, your bank and a recent transaction, because that data was already exposed somewhere. Being right about details is not evidence of legitimacy; it is the standard opening.

One rule defeats nearly all of it, and it has no exceptions: nobody legitimate ever asks for a one-time code, a PIN or a full card number. Not us, not any bank, not a fraud team, not the police. A code exists to prove to us that it is you. If we asked you to read it back, it would prove nothing at all.

The second rule is about direction. If a message asks you to sign in, do not use its link — open the app yourself. The genuine route is always the one you started.

  • No legitimate party asks for a one-time code, PIN or full card number
  • Never call back on a number supplied by the caller
  • There is no such thing as a safe account to move money to
  • Urgency is a technique, not a symptom of a real problem

3. Card-not-present testing

Where a card number has leaked — from a merchant breach, a compromised device, or a data set traded after the fact — the attacker rarely spends immediately. They test. A sequence of very small transactions at low-friction merchants establishes which numbers are live before anything expensive is attempted.

The rules merchants must follow about storing and transmitting card data exist to limit how often numbers leak in the first place, and they are the reason a well-run merchant does not hold your number in a form that is useful to anybody who steals it.Sources for this passage: PCI Security Standards Council

On the issuing side, this pattern is exactly what behavioural scoring is built to catch: several small transactions in quick succession, at merchant types the account has never used, often in another country. It is one of the more reliably detected patterns, which is why the first sign is frequently a declined transaction rather than a large loss.

What you can do: turn off online payments on any card you only use in person, and check the small transactions. A charge for a fraction of a unit of currency is not a rounding error — it is a test, and it deserves a freeze.

4. Account takeover

The most damaging and the least common. Rather than using a card, the attacker takes control of the account: changing the registered contact details, enrolling a new device, then ordering a replacement card or moving limits. Done well, the victim stops receiving the alerts that would have warned them.

It usually starts with the second category above — credentials or a code obtained by persuasion — which is why those two are worth treating as the same problem. Multi-factor authentication is the control here, and the reason the factors must be of genuinely different kinds: a password and a security question are one factor twice, and both can be obtained the same way.

The signal to watch for is silence. If alerts you used to get stop arriving, or a message tells you your contact details were changed and you did not change them, that is the moment to act rather than to wait and see.

What each control actually stops

Encryption protects data in transit and at rest, so an intercepted message or a copied file is not usable. It does nothing about a code you read aloud.

The chip cryptogram stops counterfeiting. It does nothing about a number used online.

Behavioural scoring stops testing and much anomalous spending. It occasionally declines a legitimate transaction, which is the price of catching the other kind quickly.

Multi-factor authentication stops account takeover, provided the factors are different in kind and the codes never leave you.

Dispute rights recover money after settlement. They are the last line, not the first, and they work best when the date, amount and merchant descriptor are recorded precisely.

If it is happening right now

Freeze the card in the app. It takes one tap, it is reversible, and it costs nothing if you turn out to be wrong about the transaction. Doing this first is almost always right.

Then write to us with the date, the amount and the merchant descriptor exactly as it appears, plus anything you have already done. If a person contacted you, forward the message rather than describing it — the headers and the exact wording are frequently more useful than the content.

It is also worth knowing what you are entitled to before you need it: consumer protection obligations on card issuers in the United Arab Emirates are published by the regulator rather than by any individual provider.Sources for this passage: Central Bank of the UAE

And the boring measure that outperforms all of the above: check your recurring list twice a year. A meaningful share of the transactions people report as fraud turn out to be a subscription under a merchant descriptor nobody recognised.