Card-Present Fraud
- EMV chip transactions push counterfeit liability onto the issuer. Swipe it or key it and that liability stays with you
- Your three real threats are skimming, employee theft, and counterfeit cards presented as a swipe
- Check terminals daily, not weekly. A skimmer usually goes on and comes back off inside a day or two
- Keyed entry is the worst deal at your counter. You pay a downgraded interchange tier and you eat the fraud loss on top
- Most in-store fraud you'll actually see comes from staff, not from strangers
If you take payments in person, somebody has told you that's the safe channel. It's safer. It isn't safe, and the losses that do land are yours to keep, because card-present fraud rarely gets pushed back to the issuer the way CNP fraud does.
EMV moved counterfeit liability, but only on transactions where the chip actually gets used. Everything else - keyed entries, swipes, employee schemes, tampered hardware - stays on your side of the line.
None of this needs a fraud vendor. The controls that work at the counter are a two-minute terminal check, a written keyed-entry policy, and a per-employee report your processor already runs. See fraud metrics to size your exposure before you spend anything.
What Matters
- EMV liability shift only works if you dip the chip. Swipe or key the card and you own the fraud.
- Skimming didn't go away. Attackers still overlay devices on your terminals to harvest card data.
- Employee fraud is your biggest card-present risk. Refund schemes, keyed abuse, card data walking out the door.
- Keyed transactions are high-risk by definition. Every keyed entry should hit your velocity rules.
- Physical security is fraud prevention. Terminals in view, tamper checks, access control. See PCI DSS Requirement 9.
Skimming Detection
A skimmer sits between the customer's card and your terminal and copies the data on the way through. Nobody spots one by accident. Your staff will only find it if you've told them exactly what to look for.
Types of Skimmers
| Type | How It Works | Detection |
|---|---|---|
| Overlay skimmer | Fits over existing card slot | Wiggle test, visual inspection |
| Deep insert skimmer | Inside the card slot | Harder to detect visually |
| Bluetooth skimmer | Transmits data wirelessly | RF detection, Bluetooth scan |
| Shimmer | Thin device reads chip data | Very hard to detect |
Daily Terminal Check
Two minutes, done by whoever opens:
- Card slot sits flush, doesn't wiggle
- No overlay on PIN pad
- Terminal casing is intact, no gaps
- Cables are secure, no additions
- Tamper stickers/seals unbroken
- Terminal serial number matches inventory
Weekly Deep Check
- Compare terminal to photo of known-good state
- Check for unusual Bluetooth devices nearby
- Verify firmware version matches expected
- Review transaction patterns for anomalies
Take the photos now, while you know the terminals are clean. You can't do a known-good comparison later if you've got nothing to compare against.
Terminal Tampering
Skimmers aren't the only way a terminal gets compromised. Somebody can open the housing, swap a component, or hand it back looking untouched.
Tamper Indicators
| Sign | What It Means |
|---|---|
| Broken or missing tamper seal | Terminal may have been opened |
| Loose screws or panels | Internal access attempted |
| Different colored parts | Replacement components |
| Unusual weight | Internal additions |
| Strange behavior | Slow transactions, unexpected prompts |
What to Do If Tampering Suspected
- Stop using the terminal immediately - see terminal operations
- Don't run another transaction on it
- Preserve it as evidence. Don't open it, don't clean it, don't try to fix it
- Call your processor's security team
- Pull 30 days of transactions from that terminal - check metrics
- File a police report if it's confirmed - and document the whole thing for PCI incident response
Physical Security Basics
- Terminals in view of staff at all times
- Cable/lock terminals to counter
- Limit who can access back of terminal
- Lock terminals in safe overnight (high-risk locations)
- Visitor/vendor check-in for anyone who touches terminals
Employee Fraud Schemes
Your staff are your biggest card-present fraud risk. It isn't close. When an insider runs the scheme, it's first-party fraud with your own credentials behind it.
Don't read that as distrust your team. Read it as build controls that clear the honest ones fast. A per-employee refund report does that. It also makes the dishonest ones obvious.
Common Schemes
Refund Fraud
Pattern: Employee refunds to their own card, or a friend's, with no sale behind it. (Refund fraud is the customer-side version. Different scheme, different controls.)
Signals:
- High refund count for specific employee
- Refunds without corresponding sales
- Refunds to same card repeatedly
- Refunds processed after hours or at close
Prevention:
- Manager approval above a set amount ($50 is a normal starting line)
- Match refunds to original transactions
- Review refund reports by employee weekly
- Dual control for cash refunds
Then watch your own threshold. Set approval at $50 and you've described a $49 scheme. You're not looking for one big refund. You're looking for a cluster just under your own line. Read the distribution, not the outliers.
Overstated Refunds
Pattern: The sale is real. The refund is real. The amount is wrong.
A customer returns a $40 item. The employee puts through $140. The extra $100 goes to cash, or to another card.
This walks straight past the control above. "Match refunds to original transactions" passes here, because there is an original transaction. Compare the amounts, not just that a sale existed.
Signals:
- Any refund larger than the sale behind it
- Refund value per employee climbing while refund count stays flat
- Refunds that land on round numbers
Prevention:
- Cap refunds at the original amount in the POS, not in the policy document
- Flag every refund that exceeds its original, by any amount
- Track refund value and refund count separately by employee
Skimming by Staff
Pattern: Employee uses a hidden reader to copy card data, then sells it or spends it.
Signals:
- Employee handles cards out of customer view
- Transactions take unusually long
- Multiple fraud reports traced to your location
Prevention:
- Customer-facing terminals only
- Cards never leave the customer's hand
- Clear sightlines to all terminals
- Background checks for new hires
Keyed Transaction Abuse
Pattern: Employee types in card numbers from memory, a photo, or a note, and buys things.
Signals:
- High keyed ratio for specific employee
- Keyed transactions to same card
- Keyed transactions after hours
Prevention:
- Monitor keyed ratio by employee
- Manager approval for keyed transactions
- Review keyed transactions daily
- Turn keyed entry off entirely on terminals that don't need it
Void/Cancel Manipulation
Pattern: Employee rings the sale, takes the cash, then voids the transaction.
Signals:
- High void rate for specific employee
- Voids at end of shift
- Voids without customer present
Prevention:
- Customer signature on voids
- Manager approval for voids
- Receipt required for all voids
- Camera coverage of the register area
Monitoring by Employee
Track these per person:
| Metric | Red Flag Threshold |
|---|---|
| Refund count | > 2x average |
| Refund value | > 2x average |
| Keyed transaction % | > 5% |
| Void rate | > 2% |
| After-hours transactions | Any |
| Same-card refunds | > 1 per month |
The check that needs no suspect
Everything above needs you watching a particular person. This one doesn't. Run it first.
Track refunds as a share of gross sales, monthly, across the business. A refund scheme moves that ratio. It moves whether or not you know who's running it. Sales flat and refunds climbing is the shape. It's already in your processor's settlement reporting, so it costs you nothing.
Two things move it that aren't fraud. Seasonality, so compare to the same month last year. And a real product or fulfilment problem, which you want to find anyway. The ratio tells you to look. It doesn't tell you what you'll find.
The ACFE publishes Occupational Fraud: A Report to the Nations as a free PDF. It's the standard benchmark for staff stealing from their own employer. It breaks out by organization size, by scheme, and by how each case got caught. It isn't payments-specific. It's also the only dataset of its kind that nobody's selling you a control off the back of.
"Can we pull reports showing refund and void rates by employee? What about keyed transaction percentage?"
MOTO/Keyed Transaction Risk
Every keyed transaction is a bet you're placing with your own money.
When Keyed Entry Is Acceptable
| Scenario | Risk Level | Notes |
|---|---|---|
| Established B2B customer, phone order | Lower | Known relationship, verify identity |
| Card present but chip failed once | Medium | One retry, then request different card |
| Delivery driver collecting payment | Medium | Consider mobile terminal instead |
When Keyed Entry Is a Red Flag
| Scenario | Risk Level | Notes |
|---|---|---|
| Walk-in says chip "doesn't work" | High | Common fraud tactic |
| Customer reads card number from phone | High | Likely stolen card data |
| Rush to complete before closing | High | Pressure tactic |
| High-ticket item, new customer | High | Classic fraud pattern |
| Employee keying without customer present | Critical | Potential internal fraud |
Liability Shift Loss
| Transaction Type | Liability for Fraud |
|---|---|
| Chip dip (EMV) | Issuer |
| Contactless (NFC) | Issuer |
| Swipe (mag-stripe) | Merchant |
| Keyed (MOTO) | Merchant |
If you key a fraudulent transaction, you eat the loss. No exceptions.
Keyed entry costs you twice, and the second cost is the one people forget. It downgrades to a worse interchange tier than a chip read, so you're paying more per transaction on top of carrying the fraud.
Keyed Transaction Policy
- Chip must be attempted first
- If chip fails, tap must be attempted
- If both fail, request a different card
- Keyed entry requires manager approval
- Document the reason for every keyed transaction
- Never key a number read off a phone or a scrap of paper
Write those six lines on a card and tape it next to the register. A policy that lives in a binder isn't a policy.
EMV Liability Shift Mechanics
Liability shift decides who pays when a counterfeit card gets used. The line matters, because it's the difference between a chargeback you never see and one you can't fight.
How Liability Shift Works
Before the US shift (October 2015): the issuer usually ate counterfeit fraud.
After: whoever brought the weaker technology eats it.
| Merchant Has | Card Has | Liability |
|---|---|---|
| Chip terminal | Chip | Issuer |
| Chip terminal | No chip | Issuer |
| No chip terminal | Chip | Merchant |
| No chip terminal | No chip | Issuer |
What "Chip Terminal" Means
- Terminal must be EMV-capable
- EMV must be enabled and active
- Transaction must be processed as chip (not fallback)
All three, not two of three. If your terminal has a chip reader and your staff swipe anyway, you've lost the shift and you won't find out until the chargeback lands.
Fallback Transactions
When the chip fails and the terminal drops to swipe, that's a fallback.
- Occasional fallback: some liability protection, and it varies by network
- Repeated fallback: the protection goes away, and it's a signal something's wrong
If one terminal falls back constantly, it's almost always one of four things:
- Dirty chip reader
- Worn chip slot
- Firmware issue
- Someone testing you
Test to Run
2-week card-present security audit:
Week 1: Assessment
- Inspect all terminals for tampering signs
- Pull keyed transaction report by employee
- Review refund patterns for past 90 days
- Verify terminal firmware is current
- Check physical security (locks, sightlines, access)
Week 2: Remediation
- Address any tampering concerns
- Investigate high keyed ratios
- Stand up employee monitoring dashboards
- Update terminal check procedures
- Train staff on fraud indicators
Success criteria: All terminals verified clean. Keyed ratio under 2%. Monitoring in place.
If week 1 turns up nothing, that's a real result. Write down the date, keep the terminal photos, and run it again next quarter.
Scale Callout
| Volume | Focus |
|---|---|
| Under $100k/mo CP | Daily terminal checks. Manager approval for keyed entries. Basic employee monitoring. |
| $100k-$1M/mo CP | Automated employee metrics. Weekly refund review. Tamper detection procedures. |
| Over $1M/mo CP | Dedicated loss prevention. Camera integration. Real-time anomaly detection. Regular security audits. |
Where This Breaks
-
High-turnover retail. New faces every month means training never sticks. Don't fight that with a longer manual. Shorten the procedure until a new hire can do it on day one, and automate the monitoring.
-
Mobile and delivery. A terminal you can't see is a terminal you can't inspect. Use cellular units you can track, and turn keyed entry off on them.
-
Multi-location franchises. You won't get consistency by asking for it. Centralized reporting and a real audit schedule, or you're guessing.
Analyst Layer: Metrics to Track
| Metric | What It Tells You | Target |
|---|---|---|
| Keyed transaction % | Liability exposure | < 2% |
| Refund rate by employee | Internal fraud risk | Compare to average |
| Void rate by employee | Manipulation potential | < 2% |
| Fallback transaction % | Terminal health | < 1% |
| CP fraud/dispute rate | Overall health | < 0.3% |
| After-hours transaction % | Anomaly indicator | Investigate any |
Location-Level Comparison
Running more than one site? Compare keyed %, refund rate and dispute rate across them. The outlier tells you where the problem is: a bad terminal, a bad hire, or a local fraud pattern that hasn't reached your other stores yet.
Trend Analysis
Week-over-week movement beats any single snapshot:
- Keyed ratio climbing = investigate
- Refunds climbing at one location = investigate
- Voids spiking right before somebody resigns = investigate
CP Anomaly Monitoring
Build alerting for these card-present anomalies:
| Anomaly | Detection Logic | Alert Threshold |
|---|---|---|
| Keyed entry spike | Keyed % > baseline + 2 std dev | Real-time alert |
| Off-hours transactions | Transactions outside business hours | Any occurrence |
| Refund without sale | Refund not matched to prior sale | Any occurrence |
| High-value void | Void > $X (set threshold) | Each occurrence |
| Multiple cards, same device | 3+ distinct cards on one terminal/hour | Real-time alert |
| Repeated decline then success | 3+ declines followed by approval | Flag for review |
Anomaly Investigation Workflow:
- Alert fires → Identify employee, terminal, transaction details
- Verify legitimate? → Check with manager, review camera
- If suspicious → Escalate to loss prevention
- If false positive → Tune threshold
- Document outcome → Train detection model
Employee Risk Scoring
Score on these factors:
| Factor | Weight | Signal |
|---|---|---|
| Keyed % vs peers | High | Above-average = risk |
| Refund % vs peers | High | Above-average = risk |
| After-hours transactions | Medium | Any = flag |
| Void pattern | Medium | Clustered voids = risk |
| Tenure | Low | New employees = higher monitoring |
Score monthly and look at the top 10%. Most of them won't be fraud. They'll be your best closer, or the person who handles the complicated orders because nobody else will. That's fine. You're looking for the one who can't explain the pattern.
Next Steps
Preventing skimming and tampering?
- Train daily terminal checks - Staff inspection routine
- Perform weekly deep checks - Compare to known-good state
- Handle suspected tampering - Response protocol
Addressing employee fraud?
- Know common schemes - Refund, skimming, keyed abuse
- Monitor by employee - Per-employee metrics
- Put prevention controls in place - Manager approvals
Managing keyed transactions?
- Identify acceptable scenarios - Low-risk cases
- Recognize red flags - High-risk signals
- Enforce keyed policy - Chip first, approval required
Background reading for this page
- Terminal operations and fleet management
- PCI DSS requirements for physical security
- Fraud types and how CP differs from CNP fraud
- EMV liability shift rules
Related Pages
- Card-Present Terminal Decisions - Terminal selection
- Terminal Operations - Day-to-day management
- Fraud Prevention - Prevention strategies
- Velocity Rules - Pattern detection
- EMV & Contactless - Chip security
- PCI DSS - Physical security requirements
- Refund Fraud - Employee abuse patterns
- First-Party Fraud - Customer abuse
- Chargeback Prevention - Dispute reduction
- Fraud Metrics - Measuring CP fraud