Skip to content
Aashna Jain

How does card fraud actually happen?

2 min readFor everyoneTrust and riskTRUST AND RISK · 14 OF 19

Almost nobody steals your card. They steal the number, and they usually do it somewhere you have never been.

Three doors in
Stolen credentialsleaked data, phishingAccount takeoverhijacked loginCard not presentonline, no chipfraudulentchargeCardholder disputes

Almost every card fraud case starts through one of three entry points.

Route one: the breach

Someone else's database. A retailer, a hotel chain, a service you used once. The details are sold in bulk, and the person who eventually uses your card has no idea where it came from.

You did nothing wrong, there is nothing you could have done differently, and this is the single largest source.

Route two: phishing

A page that looks like a bank, a courier, a tax office. The one behavioural detail worth memorising: this almost always arrives with urgency attached. Your account will be closed, your parcel returned, your refund expires today.

Urgency is the tell. Legitimate institutions are almost never in a hurry.

Route three: skimming

A physical device over a card reader or an ATM slot, sometimes with a camera or an overlay keypad for the PIN. Fuel pumps and free-standing ATMs are the classic sites because nobody is watching them.

Chip and contactless made this much harder, which is why the magnetic stripe survives mainly as an attack surface.

Route four: you were persuaded

The fastest-growing category, and the one no card technology addresses. Someone convincing calls, and you provide the details or approve the OTP yourself.

Note what this defeats. 3D Secure, tokenization, fraud scoring: all of them are designed around the assumption that the real customer is not participating. When you approve it, the system sees a correctly authenticated payment, because that is exactly what it is.

What actually reduces it

Not vigilance about the physical card, which is barely the issue. Two habits close most routes:

Use credit, or a virtual card, for anything online. The exposure is the bank's, and a locked virtual number is worthless when the merchant is breached.

Never approve anything you did not initiate, and never say the code aloud. An OTP is not a verification of you. It is an authorisation of a payment. Anyone asking you to read one out is asking you to approve something.

And check statements. Card fraud very often starts with a tiny test charge weeks before the real one.

Thieves rarely pick the lock. They photograph the key while it hangs in the shop where you left it, and let themselves in months later.

Where you meet it

Every time your bank blocks a card you were holding. Every small unexplained charge that arrives weeks before a large one. Every call that already knows your name.

Get the next one in your inbox.

New fundamentals and one memo every two weeks.

Or subscribe on Substack ↗