How Does Credit Card Fraud Happen and Who Pays?

Credit card fraud happens in a handful of recognizable ways: someone steals the physical card or intercepts it in the mail, a hidden device captures the data at a card reader, a scam call or text tricks you into handing over your number, hackers breach a retailer’s systems, or bots guess valid card numbers online. Whichever route the criminal takes, federal law caps your personal liability for unauthorized credit card charges at $50, and Visa and Mastercard both go further with zero-liability policies that erase even that amount.1Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card2Visa. Zero Liability Policy3Mastercard. Zero Liability Protection Policy

Stolen Cards and Intercepted Mail

The oldest form of card fraud is also the simplest. A stolen wallet gives a thief the card number, expiration date, and the security code printed on the back — everything needed to spend. Shoulder surfing at an ATM or checkout terminal adds your PIN to the haul. Once a thief has the card in hand, they tend to move fast, hitting big-box retailers within minutes before you realize it is missing.

Mailboxes are a second entry point. Stealing an unopened credit card envelope is a federal crime, but the payoff is high enough that thieves keep trying.4Office of the Law Revision Counsel. 18 USC 1708 – Theft or Receipt of Stolen Mail Matter Generally A card sitting in its activation sleeve is essentially a blank check: the thief calls the activation number, sets a PIN, and starts spending.

Real-time transaction alerts are the single best defense here. Turn them on through your issuer’s app so a text or push notification lands the moment your card is used. That way you spot an unfamiliar charge within seconds instead of at the end of the month.

Skimmers and Shimmers at Card Readers

Skimming uses a small overlay device fixed to a legitimate card reader — a gas pump, ATM, or self-checkout terminal — to read the magnetic stripe as you swipe. A shim is a paper-thin circuit board slipped inside the card slot itself, where it intercepts data from the EMV chip during an otherwise normal transaction. Both are nearly invisible to the average user, and both are illegal under the federal statute on access device fraud.5Office of the Law Revision Counsel. 18 USC 1029 – Fraud and Related Activity in Connection With Access Devices

Captured data is often transmitted wirelessly by Bluetooth to a device nearby, then used to produce counterfeit cards with cloned magnetic stripes for in-person shopping.

Contactless payment sharply reduces this risk. Every tap generates a unique encrypted code in place of your actual card number, so even intercepted data cannot be reused. Swiping, by contrast, transmits the same static data every time, which is exactly what a skimmer is built to collect. If a terminal offers a tap option, use it.

Phishing, Vishing, Smishing, and SIM Swaps

Some fraud skips the technology and targets you directly. Smishing (text) and vishing (phone) both manufacture urgency: a warning that your account is locked, a suspicious charge to confirm, a code to read back. Callers often use spoofing software so the incoming number matches your bank’s real customer service line. The pressure is designed to get you talking before you think.

Email phishing runs the same play at scale. A convincing message with your bank’s logo drops you on a fake login page that mirrors the real one. Enter your username and password and the fraudster captures both in real time.

SIM swapping targets the security layer meant to protect you. A criminal contacts your mobile carrier, impersonates you, and convinces them to move your phone number onto a new SIM card. From that moment on, any two-factor authentication code sent by text lands on their phone, not yours, opening the door to your bank, email, and payment apps. Where your card issuer offers it, switch two-factor authentication from text messages to an authenticator app.

Retailer Breaches, Formjacking, and Dark Web Resale

Large data breaches skip individual cardholders and hit the servers of retailers, payment processors, and banks. Hackers exploit network weaknesses to reach databases holding thousands or millions of card records at once. The people who break in rarely use the data themselves. They bundle records into “dumps” and sell them on dark web marketplaces for cryptocurrency, with individual card records running from about $5 to $150 depending on the credit limit and how much personal data comes with them. Full identity packages — name, date of birth, Social Security number, and address — go for more.

Formjacking is a quieter variant. Attackers inject malicious code into a legitimate retailer’s checkout page so that when you type your card details, a copy is sent to their server. The order still processes, so nothing looks wrong to you or the merchant. The code can sit there for weeks or months before anyone notices.

You cannot prevent your data from being caught up in a breach on someone else’s system. What you can do is monitor. Review statements regularly, keep transaction alerts on, and consider an identity monitoring service that scans dark web forums for your information.

Card-Not-Present Fraud and Bot Attacks

Online purchases do not need a physical card, which opens the door to automated attacks. Carding bots run BIN attacks — they take the first six digits of a real bank identification number and cycle rapidly through the remaining digits, expiration dates, and security codes. To test whether a generated number is live, the bot places a tiny charge on some merchant’s site, sometimes as low as $1. If it clears, the working details go into a list for larger fraudulent purchases later.

Account takeover skips the guessing. A criminal logs into your existing account with a retailer or issuer using credentials pulled from a breach or phishing attack, then changes the password, shipping address, or phone number on file.6Office of the Comptroller of the Currency. Credit Card and Debit Card Fraud From there they can spend against your stored payment methods, order replacement cards to a new address, or run through your available credit.

Virtual card numbers blunt both attacks. Many issuers now let you generate a temporary 16-digit number, expiration date, and security code tied to your real account. Each virtual number is locked to a single merchant or transaction, so a stolen or guessed number goes nowhere. Some also let you set custom spending caps and expiration dates.

What You Actually Pay if Your Card Is Used

Federal law caps your liability for unauthorized credit card charges at $50, and the cap only covers charges made before you notify the issuer.1Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card2Visa. Zero Liability Policy3Mastercard. Zero Liability Protection Policy

There is a practical advantage on top of the dollar caps. An unauthorized credit card charge shows up as a disputed line item on a bill you have not paid yet, so your actual money stays in your checking account while the issuer investigates. Debit cards work differently and carry weaker protections under a separate federal rule, so if the compromised card was a debit card the math and the reporting deadlines are not the same.7Consumer Financial Protection Bureau. Liability of Consumer for Unauthorized Transfers

What to Do the Moment You See a Fraudulent Charge

Call the number on the back of your card and report it. For a credit card, that call alone ends your liability for anything that happens afterward. The issuer will freeze the card, reverse the fraudulent charges, and send a replacement.

Then file an identity theft report with the Federal Trade Commission at IdentityTheft.gov or by calling 1-877-438-4338. The report is official proof of the theft and secures certain rights when you deal with businesses and credit bureaus, and the site generates a personalized recovery plan based on what you tell it.8Federal Trade Commission. Identity Theft Recovery Steps

Next, place a fraud alert or credit freeze with any one of the three national credit bureaus. Contacting one requires that bureau to notify the other two: Equifax (800-685-1111), Experian (888-397-3742), or TransUnion (888-909-8872).9Federal Trade Commission. Credit Bureau Contacts A fraud alert lasts one year and forces lenders to verify your identity before opening new accounts in your name. A credit freeze goes further and blocks new accounts entirely until you lift it. Both are free under federal law.10Federal Trade Commission. Credit Freezes and Fraud Alerts

Finally, scan your recent statements for very small charges you do not recognize. Thieves often run a $1 or $2 test purchase to confirm a card works before making a larger one, and catching that test is your last chance to shut things down before the real hit lands.