Credit card fraud is unauthorized use of a card account or payment credential to obtain money, goods, services, or account access.
Credit card fraud is unauthorized use of a credit card account or payment credential to obtain money, goods, services, or account access. It can involve a stolen physical card, exposed card details, account takeover, a fraudulent application, or unauthorized use of a digital wallet linked to the account.
An unfamiliar charge is a warning sign, not proof of how the transaction occurred. The cardholder should verify the merchant descriptor, contact the issuer promptly through an official channel, preserve records, and follow the dispute procedure and deadlines that apply to the card and jurisdiction.
Classifying the problem correctly helps route it to the right process.
| Problem | Typical situation | Initial action |
|---|---|---|
| Unauthorized use | Someone without permission uses the card, number, token, or account | Contact the issuer immediately and identify the transactions |
| Billing error | Wrong amount, duplicate posting, missing credit, or another statement error | Use the issuer’s billing-error or dispute process |
| Merchant dispute | Goods were not delivered, were defective, or differed from the agreement | Contact the merchant, then ask the issuer about available dispute rights |
| Forgotten or unclear charge | Merchant descriptor differs from the brand name, or a household member made the purchase | Verify receipts, authorized users, and merchant details before alleging fraud |
| Identity theft | Personal information is used to open or control accounts | Contact issuers and credit bureaus and use the relevant identity-theft reporting process |
| Account takeover | An attacker changes login, contact, or payment information and controls an existing account | Contact the issuer through a trusted channel and secure related accounts |
A chargeback can result from a qualifying dispute, but fraud and chargeback are not synonyms. The issuer may investigate an unauthorized-use claim and route a financial reversal through card-network procedures.
Someone obtains the physical card and uses it before the issuer blocks or replaces it. Contactless, magnetic-stripe, chip, signature, or cash-access transactions can leave different authentication records.
The physical card is not presented. A person uses exposed card details for an online, telephone, mail-order, in-app, or recurring transaction. The cardholder may still possess the card.
An attacker gains access to the cardholder’s online account or impersonates the cardholder through customer service. Warning signs can include changed contact information, unfamiliar devices, password-reset notices, replacement-card requests, or new digital-wallet enrollment.
Stolen, synthetic, or false identity information is used to apply for credit. The victim may first notice a credit inquiry, new account, collection notice, or account that does not appear in ordinary card statements.
Card data or authentication information can be captured through a compromised terminal, skimming device, theft, or deception. Chip technology can reduce some counterfeit-card risks but does not prevent every type of fraud.
A message, call, website, or social-media account impersonates a bank, merchant, government body, or trusted person. The objective may be to collect card details, one-time codes, passwords, or authorization for a payment.
A payment token or wallet linked to the card is enrolled or used without the cardholder’s authority. Losing a phone does not automatically mean the card credential was used, but the issuer and mobile provider should be contacted when account access may be exposed.
Some legitimate transactions have unfamiliar descriptors or delayed posting dates. Verification should be quick, but it should distinguish a merchant-name issue from unauthorized use.
Assume a cardholder sees a posted $78.40 online charge with an unfamiliar merchant descriptor and a pending $1.00 authorization from the same descriptor.
The cardholder checks receipts, subscriptions, authorized users, and the merchant information available in the issuer’s app. No one recognizes the transaction. Instead of calling the number in an unexpected text alert, the cardholder opens the issuer’s verified app, locks the card, and calls the number shown on a recent statement.
The cardholder reports both transactions and learns that the email address on the account was changed the previous day. The issuer restricts the account, opens an investigation, replaces the card credential, and provides a case number. A temporary credit for the posted charge appears later, but the cardholder records it as provisional rather than final.
The follow-up record includes:
The unfamiliar descriptor alone did not prove fraud. The transaction review, unauthorized account change, prompt report, and preserved records gave the issuer evidence to investigate. The final liability and credit outcome still depend on the facts, agreement, governing rules, and jurisdiction.
Use the number on the physical card, a recent statement, or the issuer’s verified website or app. Do not use contact information supplied in a suspicious message. Report the lost card, exposed credential, account takeover, or specific transactions.
An app’s card-lock feature can be useful, but locking is not a substitute for reporting. Ask whether the issuer will close or restrict the credential, replace the card, change the account number, or disable a digital-wallet token.
Keep:
This record helps distinguish the original transaction, temporary credit, permanent credit, card replacement, and final decision.
Calling promptly can stop further use, but a jurisdiction may also require or protect a written billing-error notice sent to a particular address by a deadline. Read the statement and card agreement and follow the issuer’s instructions.
Continue paying undisputed amounts as required. Do not assume that opening a dispute cancels the entire balance, closes the account, or ends a merchant contract or subscription.
Change the card-account password and any reused password. Review email security, mobile-carrier access, digital wallets, authorized users, and recovery methods. Enable multifactor authentication where available. Never provide an authentication code to an unsolicited caller.
If the incident involves a new account, changed identity information, or more than one compromised account, review credit reports and consider the fraud-alert or security-freeze options available in the jurisdiction. In the United States, IdentityTheft.gov provides an FTC recovery process. In Canada, the FCAC guidance directs victims to credit bureaus and the national fraud-reporting system when appropriate.
Watch the replacement account and related financial accounts. A provisional credit can be removed if the issuer concludes the charge was authorized. Read the final explanation, compare it with the evidence, and use the issuer’s complaint or appeal process if material facts were missed.
The phrase unauthorized use has a narrower meaning than “a purchase I did not want.”
The CFPB explains that when a cardholder gives another person permission to use a credit card, use outside the cardholder’s intended purpose may still be treated as authorized until the issuer is notified that the person no longer has authority. Exact outcomes depend on facts and law.
This distinction matters for:
Tell the issuer the facts accurately. Do not report a purchase as unauthorized merely to bypass a merchant’s return policy or a valid debt.
The following examples are not a global rulebook.
| Jurisdiction example | Official guidance |
|---|---|
| United States | FTC guidance states that federal law generally limits responsibility for unauthorized credit-card charges to $50. CFPB guidance says a written billing-error notice generally should be sent within 60 calendar days after the charge appeared on the statement to preserve applicable billing-error rights. |
| Canada | FCAC guidance says that for credit cards issued by federally regulated institutions, maximum liability for unauthorized use is generally limited to $50, subject to the governing rules and issues such as gross negligence. FCAC also says the institution must investigate a reported unauthorized transaction. |
These summaries omit important conditions and do not determine an individual case. Network zero-liability policies can provide protections beyond statutory minimums, but their terms and exclusions should be checked. Provincial, territorial, state, account, business-card, and issuer-specific rules may differ.
A credit card generally uses an issuer’s credit line. A debit card generally accesses deposit-account funds.
| Credit card | Debit card |
|---|---|
| Unauthorized charge affects a revolving credit account | Unauthorized transfer can remove deposit funds directly |
| Credit-card billing and unauthorized-use rules may apply | Electronic-fund-transfer rules and different reporting periods may apply |
| Disputed amount may affect available credit | Missing funds can affect cash needed for bills immediately |
Report either type immediately. Do not rely on a credit-card liability statement when the transaction actually used a debit, prepaid, bank-transfer, or peer-to-peer payment product.
Fraud controls can evaluate:
Possible responses include approval, decline, step-up authentication, customer confirmation, manual review, credential replacement, or post-transaction investigation. An approval is not proof that the cardholder authorized the transaction, and a decline is not proof of fraud.
Automated models also create false positives and false negatives. Institutions should evaluate detection performance, customer harm, explainability, access controls, privacy, bias, operational escalation, and model change management rather than relying on a single accuracy statistic.
No practice eliminates all fraud. The goal is to reduce exposure and shorten the time between suspicious use and issuer action.
EMV technology and PCI DSS address particular payment and security risks. Neither guarantees that a transaction is legitimate or that a data breach cannot occur.
This article provides general financial education, not personalized legal, credit, cybersecurity, or fraud-recovery advice. Liability, reporting periods, investigation procedures, and remedies depend on the card, transaction facts, issuer, governing law, and jurisdiction.