In the ever-evolving world of e-commerce and online transactions, security remains a top priority for businesses and consumers alike. Credit card fraud and chargebacks can be detrimental to both parties involved, leading to financial losses and potential damage to a company’s reputation. To combat these threats, the payment industry has introduced a powerful tool known as 3D Secure (3DS), which not only enhances security but also helps reduce chargebacks significantly.
The Chargeback ProcessThe Fair Credit Billing Act of 1974 mandates that all cardholders have a minimum of 60 days to dispute illegitimate charges. Most banks allow up to 120 days. Generally speaking, merchants will have 30 days to respond to each phase when dealing with Visa or Discover chargebacks.
Visa & Discover, per phase
Mastercard, per phase
American Express, per phase
What happens if you lose a chargeback? There is an arbitration process available whereby a merchant or a cardholder may request an arbitration. This is typically done in 2 steps: a pre-arbitration, where the acquiring bank (the merchant’s bank) sides with the cardholder’s bank or not. If both banks disagree, or if both parties disagree, the chargeback goes to the card brand — Visa, MasterCard, or American Express — for final arbitration.
A CNP account is a merchant account designated for accounts where more than 50% of transactions — the majority — are non-face-to-face, such as over the internet or keyed in. These accounts are underwritten and approved by the acquiring and issuing banks to accept CNP transactions. If a merchant keys in a transaction through an account not approved for mostly CNP activity, the card issuing bank may use chargeback reason code 10.3, “Other Fraud – Card-Present Environment” (Visa) or reason code 4837 (MasterCard). Most chargeback departments refuse merchant challenges under this reason code, which was created after 2015 when Visa and MasterCard introduced the “EMV Liability Shift” requiring merchants to stop taking magstripe cards and start taking EMV chip cards. This makes it harder for a merchant to contest a chargeback for keyed-in or internet transactions through an account established for EMV chip card sales — effectively trapping unknowing merchants into rules with little recourse if their account wasn’t established as CNP.
This is due to the 2015 and 2016 Visa and MasterCard “EMV Liability Shift.” Magstripe cards contain static data that can be easily copied or skimmed by fraudsters using inexpensive devices, making magstripe transactions highly vulnerable to fraud, including counterfeit card fraud and unauthorized use. Before 2015, counterfeit cards were covered by Visa and MasterCard if they were magstripe. EMV chip cards contain dynamic data that changes with each transaction, making it much more difficult for fraudsters to replicate or clone cards — providing a higher level of security and reducing the risk of counterfeit fraud.
When customers use their mobile phones to tap and pay, this is not the same as an NFC transaction from a card issued by a bank. Apple Pay and Google Pay both store card numbers in an app or software wallet which is then transmitted to a POS terminal by a tap-to-pay mechanism. But these payment types are processed as card-present transactions even though the customer is face to face at the point of sale. Also, criminals may store any card whatsoever in these software wallets, including stolen credit cards.
Chargebacks may occur when a customer contests the sales price or final bill of goods or services, or when goods or services rendered were defective. Examples of these chargeback codes are Visa’s 13.1 “Merchandise / Service Not Received” and 13.3 “Not as Described or Defective Merchandise / Services.” By having the proper verbiage, these chargeback codes can be contested and successfully challenged.
3D Secure (3-Domain Secure) is a security protocol designed to provide an additional layer of security for online credit and debit card transactions. It is called “3-Domain” because it involves three key parties in the process: the merchant/acquirer domain, the issuer domain (the bank), and the interoperability domain (the infrastructure provided by the card scheme, like Visa or Mastercard, to support the 3D Secure process).
When you make an online purchase with a card enrolled in a 3D Secure program (such as Verified by Visa, Mastercard SecureCode, American Express SafeKey, or others), the system checks to see if the card is enrolled in 3D Secure. If it is, a pop-up window or an inline frame appears during checkout, connected directly to your bank (the card issuer), which may ask you to enter a password, answer a security question, or increasingly authenticate via biometrics or a one-time passcode sent to your phone. This step ensures that the person making the transaction is the legitimate cardholder.
Most chargebacks are reported as “fraud” or “stolen card.” 3D Secure shifts the liability for these chargebacks from your business to the cardholder’s bank.
The requirement for showing ID during credit card transactions, as well as the need for signatures, has evolved with advancements in payment security technologies. The introduction of EMV (Europay, Mastercard, and Visa) chip technology has significantly altered the landscape of in-store payment authentication.
For many years, signatures were required to verify the cardholder’s identity and approve transactions, offering a layer of protection against fraud. However, the shift towards EMV chip cards, which began more significantly around 2015, marked a move away from reliance on signatures. EMV chip technology provides enhanced security through a unique, one-time code generated for each transaction, making it highly effective against counterfeit fraud — rendering the requirement for signatures largely obsolete.
By 2018, major credit card companies, including Visa, Discover, Mastercard, and American Express, had moved towards eliminating the need for customer signatures on credit card purchases, acknowledging that signatures did not significantly prevent fraud and the process was not as secure as newer technologies. This decision was also driven by a desire to speed up the in-store checkout process. The adoption of EMV technology has been broad, with a significant reduction in counterfeit fraud observed among EMV-compliant merchants. Visa, for example, has implemented Visa Secure to provide additional protection for online purchases, ensuring transactions are as secure online as they are in stores.
There are certain environments in which a customer presents their credit card in a card-present environment, but Visa and MasterCard do not provide any recourse if a chargeback is remitted to the merchant. Such retail environments are Automated Fuel Dispensers (AFD) and related unattended kiosks. These payment environments are tracked by the card brands using SIC codes and authorization codes from these devices, and can be targets for thieves — stolen cards can be presented and goods and services obtained. To fight this, there are measures which can greatly reduce, if not completely eliminate, the threat of these chargebacks.
Gas stations frequently get chargebacks from stolen credit cards at the pump. Because no signature is required at the pump, there is normally no recourse for the gas station to fight these chargebacks. Now, Zip Code verification helps protect gas stations from stolen cards — the cardholder must enter the Zip Code on file for the credit card, and if it’s not entered correctly, the card is denied.
Velocity Protection also protects gas stations from stolen credit cards. When cards are stolen, thieves often use the card several times in one day at a single gas station, stealing hundreds of dollars of gas. Velocity Protection helps prevent this by not allowing a single card to be used more than a specific number of times in one day, week, or month at a gas station.
Call us today at 1.800.928.2237