Skip to main content

Card-Present Fraud

TL;DR
  • EMV chip transactions push counterfeit liability onto the issuer. Swipe it or key it and that liability stays with you
  • Your three real threats are skimming, employee theft, and counterfeit cards presented as a swipe
  • Check terminals daily, not weekly. A skimmer usually goes on and comes back off inside a day or two
  • Keyed entry is the worst deal at your counter. You pay a downgraded interchange tier and you eat the fraud loss on top
  • Most in-store fraud you'll actually see comes from staff, not from strangers

If you take payments in person, somebody has told you that's the safe channel. It's safer. It isn't safe, and the losses that do land are yours to keep, because card-present fraud rarely gets pushed back to the issuer the way CNP fraud does.

EMV moved counterfeit liability, but only on transactions where the chip actually gets used. Everything else - keyed entries, swipes, employee schemes, tampered hardware - stays on your side of the line.

None of this needs a fraud vendor. The controls that work at the counter are a two-minute terminal check, a written keyed-entry policy, and a per-employee report your processor already runs. See fraud metrics to size your exposure before you spend anything.

What Matters

  1. EMV liability shift only works if you dip the chip. Swipe or key the card and you own the fraud.
  2. Skimming didn't go away. Attackers still overlay devices on your terminals to harvest card data.
  3. Employee fraud is your biggest card-present risk. Refund schemes, keyed abuse, card data walking out the door.
  4. Keyed transactions are high-risk by definition. Every keyed entry should hit your velocity rules.
  5. Physical security is fraud prevention. Terminals in view, tamper checks, access control. See PCI DSS Requirement 9.

Skimming Detection

A skimmer sits between the customer's card and your terminal and copies the data on the way through. Nobody spots one by accident. Your staff will only find it if you've told them exactly what to look for.

Types of Skimmers

TypeHow It WorksDetection
Overlay skimmerFits over existing card slotWiggle test, visual inspection
Deep insert skimmerInside the card slotHarder to detect visually
Bluetooth skimmerTransmits data wirelesslyRF detection, Bluetooth scan
ShimmerThin device reads chip dataVery hard to detect

Daily Terminal Check

Two minutes, done by whoever opens:

  • Card slot sits flush, doesn't wiggle
  • No overlay on PIN pad
  • Terminal casing is intact, no gaps
  • Cables are secure, no additions
  • Tamper stickers/seals unbroken
  • Terminal serial number matches inventory

Weekly Deep Check

  • Compare terminal to photo of known-good state
  • Check for unusual Bluetooth devices nearby
  • Verify firmware version matches expected
  • Review transaction patterns for anomalies

Take the photos now, while you know the terminals are clean. You can't do a known-good comparison later if you've got nothing to compare against.


Terminal Tampering

Skimmers aren't the only way a terminal gets compromised. Somebody can open the housing, swap a component, or hand it back looking untouched.

Tamper Indicators

SignWhat It Means
Broken or missing tamper sealTerminal may have been opened
Loose screws or panelsInternal access attempted
Different colored partsReplacement components
Unusual weightInternal additions
Strange behaviorSlow transactions, unexpected prompts

What to Do If Tampering Suspected

  1. Stop using the terminal immediately - see terminal operations
  2. Don't run another transaction on it
  3. Preserve it as evidence. Don't open it, don't clean it, don't try to fix it
  4. Call your processor's security team
  5. Pull 30 days of transactions from that terminal - check metrics
  6. File a police report if it's confirmed - and document the whole thing for PCI incident response

Physical Security Basics

  • Terminals in view of staff at all times
  • Cable/lock terminals to counter
  • Limit who can access back of terminal
  • Lock terminals in safe overnight (high-risk locations)
  • Visitor/vendor check-in for anyone who touches terminals

Employee Fraud Schemes

Your staff are your biggest card-present fraud risk. It isn't close. When an insider runs the scheme, it's first-party fraud with your own credentials behind it.

Don't read that as distrust your team. Read it as build controls that clear the honest ones fast. A per-employee refund report does that. It also makes the dishonest ones obvious.

Common Schemes

Refund Fraud

Pattern: Employee refunds to their own card, or a friend's, with no sale behind it. (Refund fraud is the customer-side version. Different scheme, different controls.)

Signals:

  • High refund count for specific employee
  • Refunds without corresponding sales
  • Refunds to same card repeatedly
  • Refunds processed after hours or at close

Prevention:

  • Manager approval above a set amount ($50 is a normal starting line)
  • Match refunds to original transactions
  • Review refund reports by employee weekly
  • Dual control for cash refunds

Then watch your own threshold. Set approval at $50 and you've described a $49 scheme. You're not looking for one big refund. You're looking for a cluster just under your own line. Read the distribution, not the outliers.

Overstated Refunds

Pattern: The sale is real. The refund is real. The amount is wrong.

A customer returns a $40 item. The employee puts through $140. The extra $100 goes to cash, or to another card.

This walks straight past the control above. "Match refunds to original transactions" passes here, because there is an original transaction. Compare the amounts, not just that a sale existed.

Signals:

  • Any refund larger than the sale behind it
  • Refund value per employee climbing while refund count stays flat
  • Refunds that land on round numbers

Prevention:

  • Cap refunds at the original amount in the POS, not in the policy document
  • Flag every refund that exceeds its original, by any amount
  • Track refund value and refund count separately by employee

Skimming by Staff

Pattern: Employee uses a hidden reader to copy card data, then sells it or spends it.

Signals:

  • Employee handles cards out of customer view
  • Transactions take unusually long
  • Multiple fraud reports traced to your location

Prevention:

  • Customer-facing terminals only
  • Cards never leave the customer's hand
  • Clear sightlines to all terminals
  • Background checks for new hires

Keyed Transaction Abuse

Pattern: Employee types in card numbers from memory, a photo, or a note, and buys things.

Signals:

  • High keyed ratio for specific employee
  • Keyed transactions to same card
  • Keyed transactions after hours

Prevention:

  • Monitor keyed ratio by employee
  • Manager approval for keyed transactions
  • Review keyed transactions daily
  • Turn keyed entry off entirely on terminals that don't need it

Void/Cancel Manipulation

Pattern: Employee rings the sale, takes the cash, then voids the transaction.

Signals:

  • High void rate for specific employee
  • Voids at end of shift
  • Voids without customer present

Prevention:

  • Customer signature on voids
  • Manager approval for voids
  • Receipt required for all voids
  • Camera coverage of the register area

Monitoring by Employee

Track these per person:

MetricRed Flag Threshold
Refund count> 2x average
Refund value> 2x average
Keyed transaction %> 5%
Void rate> 2%
After-hours transactionsAny
Same-card refunds> 1 per month

The check that needs no suspect

Everything above needs you watching a particular person. This one doesn't. Run it first.

Track refunds as a share of gross sales, monthly, across the business. A refund scheme moves that ratio. It moves whether or not you know who's running it. Sales flat and refunds climbing is the shape. It's already in your processor's settlement reporting, so it costs you nothing.

Two things move it that aren't fraud. Seasonality, so compare to the same month last year. And a real product or fulfilment problem, which you want to find anyway. The ratio tells you to look. It doesn't tell you what you'll find.

If you want the scale of this

The ACFE publishes Occupational Fraud: A Report to the Nations as a free PDF. It's the standard benchmark for staff stealing from their own employer. It breaks out by organization size, by scheme, and by how each case got caught. It isn't payments-specific. It's also the only dataset of its kind that nobody's selling you a control off the back of.

Ask Your Dev

"Can we pull reports showing refund and void rates by employee? What about keyed transaction percentage?"


MOTO/Keyed Transaction Risk

Every keyed transaction is a bet you're placing with your own money.

When Keyed Entry Is Acceptable

ScenarioRisk LevelNotes
Established B2B customer, phone orderLowerKnown relationship, verify identity
Card present but chip failed onceMediumOne retry, then request different card
Delivery driver collecting paymentMediumConsider mobile terminal instead

When Keyed Entry Is a Red Flag

ScenarioRisk LevelNotes
Walk-in says chip "doesn't work"HighCommon fraud tactic
Customer reads card number from phoneHighLikely stolen card data
Rush to complete before closingHighPressure tactic
High-ticket item, new customerHighClassic fraud pattern
Employee keying without customer presentCriticalPotential internal fraud

Liability Shift Loss

Transaction TypeLiability for Fraud
Chip dip (EMV)Issuer
Contactless (NFC)Issuer
Swipe (mag-stripe)Merchant
Keyed (MOTO)Merchant

If you key a fraudulent transaction, you eat the loss. No exceptions.

Keyed entry costs you twice, and the second cost is the one people forget. It downgrades to a worse interchange tier than a chip read, so you're paying more per transaction on top of carrying the fraud.

Keyed Transaction Policy

  1. Chip must be attempted first
  2. If chip fails, tap must be attempted
  3. If both fail, request a different card
  4. Keyed entry requires manager approval
  5. Document the reason for every keyed transaction
  6. Never key a number read off a phone or a scrap of paper

Write those six lines on a card and tape it next to the register. A policy that lives in a binder isn't a policy.


EMV Liability Shift Mechanics

Liability shift decides who pays when a counterfeit card gets used. The line matters, because it's the difference between a chargeback you never see and one you can't fight.

How Liability Shift Works

Before the US shift (October 2015): the issuer usually ate counterfeit fraud.

After: whoever brought the weaker technology eats it.

Merchant HasCard HasLiability
Chip terminalChipIssuer
Chip terminalNo chipIssuer
No chip terminalChipMerchant
No chip terminalNo chipIssuer

What "Chip Terminal" Means

  • Terminal must be EMV-capable
  • EMV must be enabled and active
  • Transaction must be processed as chip (not fallback)

All three, not two of three. If your terminal has a chip reader and your staff swipe anyway, you've lost the shift and you won't find out until the chargeback lands.

Fallback Transactions

When the chip fails and the terminal drops to swipe, that's a fallback.

  • Occasional fallback: some liability protection, and it varies by network
  • Repeated fallback: the protection goes away, and it's a signal something's wrong

If one terminal falls back constantly, it's almost always one of four things:

  • Dirty chip reader
  • Worn chip slot
  • Firmware issue
  • Someone testing you

Test to Run

2-week card-present security audit:

Week 1: Assessment

  • Inspect all terminals for tampering signs
  • Pull keyed transaction report by employee
  • Review refund patterns for past 90 days
  • Verify terminal firmware is current
  • Check physical security (locks, sightlines, access)

Week 2: Remediation

  • Address any tampering concerns
  • Investigate high keyed ratios
  • Stand up employee monitoring dashboards
  • Update terminal check procedures
  • Train staff on fraud indicators

Success criteria: All terminals verified clean. Keyed ratio under 2%. Monitoring in place.

If week 1 turns up nothing, that's a real result. Write down the date, keep the terminal photos, and run it again next quarter.


Scale Callout

VolumeFocus
Under $100k/mo CPDaily terminal checks. Manager approval for keyed entries. Basic employee monitoring.
$100k-$1M/mo CPAutomated employee metrics. Weekly refund review. Tamper detection procedures.
Over $1M/mo CPDedicated loss prevention. Camera integration. Real-time anomaly detection. Regular security audits.

Where This Breaks

  1. High-turnover retail. New faces every month means training never sticks. Don't fight that with a longer manual. Shorten the procedure until a new hire can do it on day one, and automate the monitoring.

  2. Mobile and delivery. A terminal you can't see is a terminal you can't inspect. Use cellular units you can track, and turn keyed entry off on them.

  3. Multi-location franchises. You won't get consistency by asking for it. Centralized reporting and a real audit schedule, or you're guessing.


Analyst Layer: Metrics to Track

MetricWhat It Tells YouTarget
Keyed transaction %Liability exposure< 2%
Refund rate by employeeInternal fraud riskCompare to average
Void rate by employeeManipulation potential< 2%
Fallback transaction %Terminal health< 1%
CP fraud/dispute rateOverall health< 0.3%
After-hours transaction %Anomaly indicatorInvestigate any

Location-Level Comparison

Running more than one site? Compare keyed %, refund rate and dispute rate across them. The outlier tells you where the problem is: a bad terminal, a bad hire, or a local fraud pattern that hasn't reached your other stores yet.

Trend Analysis

Week-over-week movement beats any single snapshot:

  • Keyed ratio climbing = investigate
  • Refunds climbing at one location = investigate
  • Voids spiking right before somebody resigns = investigate

CP Anomaly Monitoring

Build alerting for these card-present anomalies:

AnomalyDetection LogicAlert Threshold
Keyed entry spikeKeyed % > baseline + 2 std devReal-time alert
Off-hours transactionsTransactions outside business hoursAny occurrence
Refund without saleRefund not matched to prior saleAny occurrence
High-value voidVoid > $X (set threshold)Each occurrence
Multiple cards, same device3+ distinct cards on one terminal/hourReal-time alert
Repeated decline then success3+ declines followed by approvalFlag for review

Anomaly Investigation Workflow:

  1. Alert fires → Identify employee, terminal, transaction details
  2. Verify legitimate? → Check with manager, review camera
  3. If suspicious → Escalate to loss prevention
  4. If false positive → Tune threshold
  5. Document outcome → Train detection model

Employee Risk Scoring

Score on these factors:

FactorWeightSignal
Keyed % vs peersHighAbove-average = risk
Refund % vs peersHighAbove-average = risk
After-hours transactionsMediumAny = flag
Void patternMediumClustered voids = risk
TenureLowNew employees = higher monitoring

Score monthly and look at the top 10%. Most of them won't be fraud. They'll be your best closer, or the person who handles the complicated orders because nobody else will. That's fine. You're looking for the one who can't explain the pattern.


Next Steps

Preventing skimming and tampering?

  1. Train daily terminal checks - Staff inspection routine
  2. Perform weekly deep checks - Compare to known-good state
  3. Handle suspected tampering - Response protocol

Addressing employee fraud?

  1. Know common schemes - Refund, skimming, keyed abuse
  2. Monitor by employee - Per-employee metrics
  3. Put prevention controls in place - Manager approvals

Managing keyed transactions?

  1. Identify acceptable scenarios - Low-risk cases
  2. Recognize red flags - High-risk signals
  3. Enforce keyed policy - Chip first, approval required
Background reading for this page