Online fraud prevention for merchants

Fraud is not one problem, it is several wearing the same coat. Here is how each one works and the layered defence that stops them without strangling your conversion rate.

Stolen card fraud is the classic: someone buys with card details that are not theirs, the real cardholder disputes it, and you lose the goods and the money. The defence is real time risk scoring before authorisation: velocity checks that spot the same card or device hammering your checkout, mismatch flags between billing, shipping and IP geography, and amount thresholds tuned to your typical order.

Card testing is quieter and often missed. Fraudsters fire hundreds of small authorisations at your checkout to find which stolen cards are alive, leaving you with authorisation fees and a damaged reputation with your acquirer. Rate limiting, CAPTCHA on suspicious patterns and velocity rules kill it, and a properly configured risk engine spots the pattern within minutes.

Account takeover targets your customers rather than your checkout: credentials from a breach elsewhere are used to log in, change addresses and spend stored value. Device fingerprinting, alerts on detail changes, and re-authentication for sensitive actions are the controls, and tokenisation means even a compromised account exposes no usable card data.

Refund and policy abuse sits in the grey zone: claims of non-delivery, serial returns, promo code farming. Pure fraud tools miss it because every transaction is technically genuine. The fix is data: delivery confirmation with signature or photo, order history flags for repeat claimants, and policies that are generous to first offences and firm on patterns.

The mistake most merchants make is over-blocking. Every false decline is lost revenue and often a lost customer for life, and industry studies consistently find false declines cost merchants more than fraud itself. This is why generic fraud templates are dangerous: a rule set built for electronics retail will not fit a travel business. Calibration to your actual trading pattern matters more than any individual tool.

The layered model, in order. 3D Secure 2 authentication shifting liability on every authenticated payment, an AI risk engine scoring each transaction against rules tuned by a human analyst who knows your business, tokenisation removing stored card data worth stealing, hosted payment pages keeping card data off your servers entirely, and Open Banking as a route where the bank authenticates the customer directly. Every eCom Pay account ships with all five layers, plus the dedicated Risk Analyst who keeps them tuned.

Written by the eCom Pay team. Reviewed August 2026. Last updated August 2026.

Get your fraud setup reviewed free

A Risk Analyst will look at your current rules and tell you where fraud is getting through and where good customers are being blocked.

Call us Get approved