When a thief runs charges on your credit card, you almost never pay for them. Federal law caps a cardholder’s liability for unauthorized credit card charges at $50, and the major card networks voluntarily drop that to zero in most cases. The real cost of credit card fraud lands on either the merchant that accepted the transaction or the bank that issued the card, and which one pays depends on the type of transaction and whose security was weaker.
What the Cardholder Actually Pays
Under 15 U.S.C. § 1643, your liability for unauthorized use of a credit card cannot exceed $50, and even that ceiling applies only if the issuer met certain conditions: it must have given you adequate notice of the potential liability, provided a way to report loss or theft, and included a method to identify authorized users.1Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card If any of those are missing, your liability is zero. The $50 cap also covers only charges that occurred before you reported the problem. Once you notify the issuer, you owe nothing for anything that follows.
Most cardholders never see even the $50. Visa’s Zero Liability Policy says you will not be held responsible for unauthorized transactions made with your Visa card, whether the card was lost, stolen, or fraudulently used.2Visa. Zero Liability Mastercard offers a similar guarantee, provided you used reasonable care in protecting the card and promptly reported the loss or theft.3Mastercard. Mastercard Zero Liability Protection Policy These are voluntary network commitments, not federal rights, and they have gaps: Mastercard’s policy excludes commercial cards and unregistered prepaid cards such as gift cards.
The protections also cover only truly unauthorized charges. If you handed your card to someone and later regretted the purchase, § 1643 does not apply. Disputes over product quality, undelivered goods, or other billing errors on an authorized transaction run through a different process.
When the Merchant Pays
Merchants absorb credit card fraud losses in two situations that account for most of the money: transactions run through outdated card readers, and purchases where the card was never physically presented.
The EMV Chip Liability Shift
Since October 2015, the major payment networks have enforced a liability shift tied to EMV chip technology. When a chip-enabled card is used at a merchant still relying on magnetic-stripe readers, the merchant absorbs the counterfeit fraud loss instead of the issuing bank. The principle is simple: the party with the weaker technology pays.4U.S. Department of the Treasury. EMV Merchant 101 If both the card and the terminal support chip authentication, standard network rules apply and the issuing bank typically pays.
The shift is a network rule, not a federal law, and it was designed to push merchants to upgrade. Fuel dispensers got an extended deadline, with the shift for gas pumps taking effect in October 2017.
Online, Phone, and Mail Order Purchases
Card-not-present transactions are the merchant’s problem by default. Because the merchant cannot physically verify the card or the person using it, the merchant generally bears the fraud liability when the real cardholder disputes the charge. To keep the money, the merchant has to prove the authorized cardholder made the purchase, using evidence like delivery confirmation to the billing address or device authentication data. Without that proof, the network reverses the funds from the merchant’s account through a chargeback.5Mastercard. How Can Merchants Dispute Credit Card Chargebacks
Merchants can shift that risk back to the issuing bank by using 3D Secure authentication, a protocol branded as “Visa Secure” or “Mastercard Identity Check” that verifies the cardholder’s identity before payment is processed. When a transaction is successfully authenticated through 3D Secure, the fraud liability moves off the merchant and back to the issuer.6Visa. 3D Secure – Your Guide to Safer Transactions
When the Issuing Bank Pays
The bank that issued the card pays when no one else can be held responsible. That includes transactions where the merchant followed all the security protocols (chip reader used, cardholder verified, 3D Secure completed), fraud stemming from data breaches outside anyone’s direct control at the point of sale, and any loss the bank absorbs to honor its own zero-liability promise to the cardholder. Banks build fraud-loss provisions into their annual budgets to cover these costs.
The issuing bank also runs the chargeback process, sitting between the cardholder and the merchant’s acquiring bank. If the merchant contests the chargeback and provides compelling evidence that the transaction was legitimate, the issuer reviews both sides and makes the call. If the merchant misses the response deadline, the merchant loses by default and the money stays with the cardholder.5Mastercard. How Can Merchants Dispute Credit Card Chargebacks Every dollar of fraud lands somewhere; the outcome is decided by which party’s security failure or contractual obligation makes them responsible.
Debit Cards Are Not the Same
If the fraud hit a debit card rather than a credit card, none of the above applies in the same way. Debit card fraud is governed by the Electronic Fund Transfer Act and Regulation E, which tie your liability directly to how fast you report:7eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E)
- Report within 2 business days of learning about the theft, and your liability is capped at $50.
- Report after 2 business days but within 60 days of the statement, and your liability can reach $500.
- Report after 60 days from the statement, and you can be liable for the full amount of unauthorized transfers that occur after the 60-day window, with no cap.8Consumer Financial Protection Bureau. Liability of Consumer for Unauthorized Transfers
A credit card carries a hard $50 federal cap no matter when you report, and network policies usually drop that to zero. A debit card can expose you to unlimited losses if you miss the 60-day statement review. The practical takeaway: paying with a credit card puts the fraud risk on the merchant or the bank; paying with a debit card can leave more of it on you.
How to Keep the Loss Off Your Statement
The federal cap and the network policies both assume you actually dispute the charge. That process runs through 15 U.S.C. § 1666, which treats unauthorized charges as billing errors. You must send written notice to your card issuer within 60 days after the statement containing the fraudulent charge was transmitted to you, identifying the account, the charge, and why you believe it is wrong.9Office of the Law Revision Counsel. 15 USC 1666 – Correction of Billing Errors
Once the issuer has your notice, it must acknowledge it within 30 days and resolve the dispute within two complete billing cycles, and in no event later than 90 days.10eCFR. 12 CFR 1026.13 – Billing Error Resolution During the investigation you do not have to pay the disputed amount, the issuer cannot try to collect it, and it cannot report you as delinquent on that balance to the credit bureaus.11Office of the Law Revision Counsel. 15 USC 1666a – Regulation of Credit Reports If the issuer confirms the error, it credits your account and any related finance charges disappear with it. If it finds no error, it must send you a written explanation and, on request, the documentary evidence.
Most issuers let you start the dispute through their app or online banking, which is faster. To lock in the § 1666 protections, follow up with written notice to the address the issuer designates for billing inquiries, which is often different from the payment address. Certified mail creates a paper trail that proves you met the 60-day deadline. Miss that deadline and the $50 cap under § 1643 still stands, since that statute has no reporting deadline of its own, but you lose the formal dispute process and the right to withhold payment while the issuer investigates, which is what makes recovery work in practice.