What it means
Card-present fraud is any unauthorised transaction completed at a physical point of sale, such as a shop till, a restaurant terminal or an unattended fuel pump. The defining feature is that the card, or a working copy of it, is presented to a reader by someone standing there.
It matters commercially because the cost does not automatically fall on whoever was careless; it falls on whoever the card scheme rules say should bear it. Since chip technology became standard, a merchant that still accepts a magnetic stripe swipe can be made to carry the whole loss even though the card was stolen from the cardholder.
The usual methods are skimming, where a hidden reader copies the stripe data as the card goes through, and shimming, where a thin device sits inside the chip slot and records the chip conversation. Stolen cards spent quickly before the cardholder notices, and terminals tampered with by staff, account for most of the remainder.
Controls here are mechanical rather than clever. Insist on chip or contactless instead of swipe, keep terminals in view, check terminal serial numbers against an asset list each week, and reconcile the transaction count at each device daily.
The measure worth reporting to management is fraud losses per terminal, because it points straight at the site or the shift where the problem sits. The nuance is that this type of fraud has shrunk as a share of total card fraud wherever chip and PIN was adopted, but it has not gone away.
It concentrates in unattended machines, in refunds pushed through by dishonest staff, and in cross-border use where falling back to the stripe is still allowed.
In practice
Real-world examples.
Example
A fuel retailer finds that two of its unattended pumps are producing chargebacks at ten times the rate of its staffed kiosks. An inspection reveals a skimming device fitted inside the card slot of both pumps. The retailer fits tamper-evident seals, moves to a daily visual check, and the chargebacks stop within a fortnight.
Example
A restaurant group still swipes cards on an older terminal at one site because the chip reader is unreliable. A counterfeit card is used there for $2,400 of meals, and because the transaction was taken by stripe the card scheme assigns the loss to the restaurant rather than to the issuing bank. Replacing the terminal would have cost $300.
Example
A duty-free shop at an airport accepts a card that has been reported stolen, because the sale sits below the amount at which the terminal asks for a PIN. Finance later spots a pattern of several such sales in one shift and tightens the floor limit on that device. The change costs a little checkout speed and removes most of the exposure.
Formula
Calculation
Card-present fraud rate = in-person fraud losses / total in-person card sales x 100
A retail chain takes $6,000,000 of card sales in person during a quarter across 40 terminals. Chargebacks traced to counterfeit and stolen cards used at those terminals total $9,000. The fraud rate is 9,000 / 6,000,000 = 0.0015, which is 0.15% of in-person sales. Spread evenly that is 9,000 / 40 = $225 per terminal, but site by site the chain finds that $5,400 of the $9,000 came from three unattended kiosks, which is 5,400 / 3 = $1,800 each, eight times the group average.Case study
Seen in the real world.
Marlowe Garden Centres is an illustrative, fictional chain of nine stores taking about $14,000,000 a year through 60 card terminals. Its fraud losses had been stable for years, so nobody looked at them closely.
When a new finance manager split the losses by device rather than by store, the picture changed. Four self-service tills at two sites produced $11,000 of the group's $16,000 annual loss, while the other 56 terminals produced $5,000 between them. All four were older units that could still fall back to a magnetic stripe swipe when a chip read failed.
Marlowe replaced the four units for $4,800, disabled stripe fallback, and added a weekly serial number check across the estate. In the following year losses on those devices fell below $1,000, which in this illustrative case paid back the hardware inside a single quarter.
Watch out
Common mistakes.
- Assuming in-person fraud is always the bank's problem, when scheme liability rules can put the loss on the merchant whenever the weaker technology was used at the till.
- Reporting fraud as one group total, which hides the handful of terminals or shifts that usually produce most of the loss.
- Treating a declined card as a harmless event and allowing repeated retries, which lets a criminal work out which stolen cards still function.
Questions
People also ask.
Does contactless payment increase card-present fraud?
It raises the risk of small unauthorised spends on a lost card, but the chip inside still prevents cloning, so total exposure is normally lower than with a magnetic stripe.
Who pays when a counterfeit card is used at a chip terminal?
If the merchant accepted the card by chip and followed the scheme rules, the loss usually sits with the card issuer rather than with the merchant.
How often should terminals be physically inspected?
Many retailers check serial numbers and seals weekly, with a daily visual check on unattended devices, because those are the easiest to tamper with unobserved.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
