Account Data Compromise
Account data compromise (ADC) is an incident where payment account data is exposed or stolen from a merchant, processor, or other entity.
Read full definitionShouldEye Trust Intelligence Glossary
Skimming, CNP fraud, payment-app scams, and related fraud patterns explained defensively.
Educational information only. ShouldEye does not provide legal, banking, or individualized financial advice. Dispute rights, deadlines, and outcomes depend on your payment method, card network, issuer, processor, jurisdiction, and the facts of your case. Legal Disclaimers
52 published definitions in this topic.
Account data compromise (ADC) is an incident where payment account data is exposed or stolen from a merchant, processor, or other entity.
Read full definitionAccount takeover (ATO) fraud occurs when an attacker gains control of a customer’s merchant or wallet account and abuses stored payments.
Read full definitionAn allowlist (whitelist) explicitly trusts certain customers, BINs, devices, or IPs to bypass stricter checks.
Read full definitionApplication fraud is deception during account, credit, or merchant onboarding to obtain access or funds.
Read full definitionBot fraud is automated abuse—card testing, stuffing, inventory hoarding, or fake signups—driven by scripts.
Read full definitionBust-out fraud builds apparent trust or credit, then rapidly monetizes and abandons the account.
Read full definitionCard enumeration systematically guesses or iterates card numbers and expiry/CVV combinations to discover valid credentials.
Read full definitionCard fraud is unauthorized or deceptive use of payment card credentials or plastic.
Read full definitionCard testing is automated probing of stolen card numbers with small authorizations to find live cards.
Read full definitionA card-testing charge is a small unauthorized authorization used by fraudsters to check whether stolen card details still work.
Read full definitionCard-not-present (CNP) fraud abuses card credentials without a physical card read—typically online, mail, or phone.
Read full definitionCard-present (CP) fraud occurs in person using counterfeit, stolen, or skimmed cards at acceptance devices.
Read full definitionClean fraud is fraudulent transactions that look legitimate—correct AVS/CVV, normal devices, and low rule scores—until losses appear.
Read full definitionA compromised card is a payment credential exposed in a breach, skimming incident, or malware event.
Read full definitionCoupon abuse is the misuse of discount codes—sharing single-use vouchers, stacking against policy, farming codes with bots, or redeeming codes never intended for that buyer.
Read full definitionA denylist (blacklist) blocks known-bad PANs, devices, emails, or other identifiers.
Read full definitionAn early fraud warning (EFW) notifies a merchant that an issuer has flagged a transaction as suspected fraud.
Read full definitionA false positive is a legitimate customer or payment incorrectly flagged as fraud.
Read full definitionFirst-party fraud is abuse committed by a customer who is a legitimate account or cardholder participant.
Read full definitionA fraud monitoring program is a network or acquirer regime that tracks merchant fraud/chargeback levels and can impose remedies.
Read full definitionA fraud rule is a deterministic condition that flags, challenges, or blocks a transaction.
Read full definitionA fraud score is a numeric risk estimate for a payment or account event.
Read full definitionFraud-to-sales ratio compares fraud losses (or fraud counts) to sales volume over a period.
Read full definitionA fraudulent transaction is a payment involving deception—commonly stolen credentials, scams, or manipulated checkout.
Read full definitionFriendly fraud is a chargeback or dispute filed by a cardholder (or household) on a purchase they actually authorized or received.
Read full definitionGift card fraud obtains, drains, or launders value through gift card issuance and redemption.
Read full definitionLoyalty fraud steals or manufactures loyalty points, miles, or rewards for unauthorized redemption.
Read full definitionMachine learning fraud detection uses models trained on historical labels to score new payment risk.
Read full definitionManual review is human investigation of payments or orders flagged by the risk engine.
Read full definitionA Mastercard SAFE report is a fraud advice filing that issuers submit when a Mastercard transaction is reported as fraudulent.
Read full definitionMerchant laundering is a form of transaction laundering where a merchant account disguises another business’s transactions.
Read full definitionNested payment processing is when a payment facilitator or merchant covertly processes for sub-merchants outside approved onboarding.
Read full definitionA notification of fraud is an issuer or network notice that a transaction has been reported or suspected as fraudulent.
Read full definitionPayment factoring (in fraud/risk usage) is processing another business’s card transactions through your merchant account for a fee.
Read full definitionPayment fraud is dishonest misuse of payment instruments, credentials, or processes to obtain goods, funds, or value.
Read full definitionPhishing payment schemes use fake messages or sites to steal credentials, OTPs, or to induce fraudulent payments.
Read full definitionPromotion abuse exploits discounts, referrals, or trial offers beyond intended use—often with fake accounts or bots.
Read full definitionRefund abuse is excessive or manipulative use of refund policies by customers, sometimes bordering first-party fraud.
Read full definitionRefund fraud obtains illegitimate refunds—often without returning goods or after using stolen tender.
Read full definitionReshipping fraud recruits people to receive goods bought with stolen payments and forward them, often abroad.
Read full definitionReturn abuse exploits return policies—wardrobing, partial returns, or empty-box schemes—for undeserved value.
Read full definitionA risk engine evaluates payments in real time using rules, scores, lists, and sometimes 3DS decisions.
Read full definitionSocial engineering payment fraud manipulates people into approving payments or revealing secrets that enable theft.
Read full definitionSynthetic identity fraud combines real and fabricated personal data to create a new identity used for credit or payments abuse.
Read full definitionA TC40 report is a Visa fraud advice record that issuers file when a cardholder reports a transaction as fraudulent.
Read full definitionThird-party fraud is committed by someone other than the legitimate account holder using stolen credentials or identity.
Read full definitionTransaction laundering processes payments for unidentified or illegal merchants through a seemingly legitimate merchant account.
Read full definitionA transaction rule is a processing or risk condition applied to individual payment attempts.
Read full definitionTriangulation fraud uses a fake storefront to take orders, buys the goods from a legitimate retailer with stolen cards, and ships to the victim buyer.
Read full definitionAn unauthorized transaction is a payment made without the account holder’s permission—often true fraud or account takeover.
Read full definitionA velocity check measures how many times an identity, card, device, or address attempts actions in a time window.
Read full definitionA velocity limit is the maximum allowed attempt or spend rate before a block or step-up triggers.
Read full definition