Card-Not-Present (CNP) Fraud
Online, the card number is not the problem. The second factor is, and that is where CNP fraud now aims.
A card-not-present (CNP) transaction is one where the card and the acceptance device are not physically together: an online purchase, an in-app payment, a phone or mail order. RBI's 2025 authentication directions define it exactly that way. CNP fraud is the misuse of a card's details in such a transaction, without the card itself.
Because no chip and no PIN pad are involved, the card number, expiry date and CVV are enough to attempt a payment. What stands between a stolen number and a completed payment in India is the second authentication factor, and that is where most CNP fraud is now aimed.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
How Card Details Are Stolen
- check_circlePhishing pages that copy a bank's or merchant's checkout and capture the card details and OTP as the customer types.
- check_circleE-skimming: malicious code injected into a genuine merchant's checkout page, copying card details as customers pay.
- check_circleData breaches at merchants or service providers that stored card data they should not have kept.
- check_circleMalware on the customer's phone or computer that reads card entries or intercepts SMS OTPs.
- check_circleVishing: a caller collects the card number, CVV and OTP while posing as the bank, a courier or a refund desk.
The Rule Now: Two Factors, One of Them Dynamic
RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025, with compliance due by 1 April 2026, require every domestic digital payment to be authenticated by at least two distinct factors, unless a listed exemption applies. For anything other than a card-present transaction, at least one factor must be dynamic: proof that is unique to that transaction, such as an OTP or a device-generated cryptogram. The factors must be independent, so compromising one does not weaken the other.
No factor is mandated. Issuers may use SMS OTP, device binding, biometrics or other methods, and may add checks for risky transactions based on location, device and behaviour. If a loss arises from a transaction authenticated without complying with these directions, the issuer must compensate the customer in full.
Older Courseware: The ₹2,000 Relaxation Is Gone
Older material describes a 2016 RBI relaxation of the additional factor of authentication for CNP payments up to ₹2,000 through card-network solutions, plus a series of 2009-2014 circulars on CNP security. The 2025 authentication directions repealed all of those circulars. The listed exemptions today include recurring payments after the first one under the e-mandate framework, small-value contactless card payments, and a few specific use cases, not a general small-value CNP waiver.
Quick practice on banking operations. No signup.
Controls That Make Stolen Details Less Useful
| Control | What it does |
|---|---|
| Card-on-file tokenisation | Since RBI's 2021 tokenisation circular, no one in the payment chain other than the card issuer and card network may store the actual card number. Merchants keep a token unique to that card, merchant and token requestor, so a merchant breach leaks tokens that do not work elsewhere. |
| Online use off by default | Under RBI's 2020 card security circular, new cards work only at ATMs and PoS terminals in India until the holder switches on online or international use, with limits the holder can set 24x7. |
| Merchant name in alerts | RBI's 2026 security directions require OTPs and alerts for online transactions to name the actual merchant, not the payment aggregator, so a customer can see who is being paid. |
| Fraud monitoring | Banks must watch for bursts of transactions, high-risk merchant categories and strings of invalid CVVs that signal card-number testing. |
The Cross-Border Gap
The authentication directions cover domestic transactions. A card issued in India used at an overseas website was historically the weak spot, because the overseas merchant might not ask for a second factor at all. RBI required card issuers, by 1 October 2026, to validate non-recurring cross-border CNP transactions where the overseas merchant or acquirer raises an authentication request, to register their BINs with the card networks for this, and to run a risk-based mechanism for all cross-border CNP transactions.
How the IIBF Exam Tests This
Expect a definition question (is a phone order card present or not present?) and a control question (which measure protects card data stored by merchants: tokenisation). The trap is treating CVV as a second factor. CVV is printed on the card and static, so it is part of the card details a fraudster steals, not an independent dynamic factor.
FAQs
What is card not present fraud?expand_more
The use of stolen card details (number, expiry, CVV) to pay online, in an app or by phone, without the physical card. It is the main form of card fraud wherever chip cards have made physical cloning harder.
Is OTP mandatory for online card payments in India?expand_more
Two factors of authentication are mandatory, with at least one dynamic for card-not-present payments. SMS OTP is the most common dynamic factor but no longer the only permitted one under RBI's 2025 directions.
Can merchants save my card number?expand_more
No. Under RBI's card-on-file tokenisation rules only the issuer and the card network may store the actual card number. Merchants can store a token, plus the last four digits and the issuer's name for reconciliation.
How do I stop my card being used on foreign websites?expand_more
Use your bank's app, internet banking, ATM or IVR to switch off international and online use, or set low limits. RBI requires issuers to offer this switch round the clock.
Next steps
- Credit Card Fraudarrow_forward
- MFAarrow_forward
- Payment Processingarrow_forward
- Phishing, Vishing, Smishingarrow_forward
120 questions, 2 hours, scored instantly.
