You sell software keys, courses, game credits, templates, or downloads. Customers get what they paid for in seconds, which is exactly what they love and exactly what fraudsters love too. When the chargebacks arrive weeks later, you are left arguing that someone received a product that never touched a shipping label.
Digital goods payment processing fraud follows a predictable pattern. Once you see the mechanism, the defenses become obvious, and so does the evidence you need to keep.
Why instant delivery is a fraud magnet
A physical store has a built-in delay. Orders are packed, shipped, and tracked, and a suspicious order can be stopped before the box leaves. Digital products have no gap. The payment clears, the license key appears, and the value is gone.
That makes digital goods attractive for two kinds of abuse. Criminals use stolen cards to buy items they can resell, like gift cards, game currency, or software licenses. And they use cheap digital products to check whether stolen card numbers still work.
With digital goods, fulfillment is instant and irreversible, so your fraud decision has to happen before the payment, not after it.
Card testing: the attack that targets your checkout
Card testing, also called enumeration, is when a fraudster runs large batches of card numbers through a checkout to find the live ones. Low-priced digital items are ideal targets because small charges draw less attention and checkout flows are often frictionless.
The damage goes beyond the few fraudulent sales that get through. Thousands of declined authorizations land on your merchant account in a short window. Your processor sees a spike that looks like you either built a weak checkout or are part of the problem.
Visa now measures this directly. Its Visa Acquirer Monitoring Program includes an enumeration ratio that flags merchants where card testing makes up a large share of authorization attempts. Repeated card-testing attacks can push an account into network monitoring even if few fraudulent sales succeed.
Signs you are being tested
- A burst of small authorizations, many declined, in minutes or hours
- Many different card numbers from the same IP address, device, or email pattern
- Sequential or similar card numbers, or identical billing details across attempts
- Orders for the cheapest item in your catalog, often at odd hours
How to shut it down
Add velocity limits on card attempts per IP address, device, account, and session. Put a bot challenge in front of checkout when traffic looks automated. Require an account login before purchase for higher-risk items. Watch decline rates in real time so an attack is stopped in minutes, not discovered on your monthly statement.
Fraud filters at the gateway level help here too. Our overview of fraud protection tools for high-risk merchants covers what to look for.
Stolen cards and true fraud disputes
When a stolen card buys your product, the real cardholder eventually sees the charge and disputes it as fraud. For card-not-present sales without strong authentication, the merchant usually carries that loss, along with the dispute fee.
Fraud disputes also count against you twice in the card networks' eyes. The issuer reports the fraud, and the cardholder files the dispute, and both feed the monitoring ratios that determine whether your account is flagged.
"Item not received" disputes for digital products
Not every dispute comes from a criminal. Some come from real customers who claim they never received the product. In Visa's system these generally fall under merchandise or services not received, reason code 13.1.
Sometimes the claim is honest. The download email went to spam, the license key did not activate, or the customer could not find the login. Sometimes it is friendly fraud, where the buyer received and used the product and disputes anyway. Our guide to friendly fraud explains why it is so common with digital purchases.
Either way, you win or lose these disputes on evidence. Without a shipping carrier to prove delivery, you need to prove it yourself.
What delivery proof looks like for digital goods
Strong digital delivery evidence shows that the product was made available, that the customer accessed it, and that the person accessing it matches the person who paid. Collect it automatically on every order, not only when a dispute arrives.
- Access and download logs: timestamps showing when the file was downloaded, the course was opened, or the license key was activated.
- IP address and device data: captured at purchase and at access, so you can show they match.
- Account history: login records, usage after purchase, and prior orders on the same account.
- Delivery communications: the email that delivered the product or access link, with send time and recipient address.
- Customer acknowledgment: acceptance of terms at checkout, including your refund policy.
Keep logs long enough to cover the dispute window. Card network deadlines for disputes can extend for months after a purchase, and a log that was deleted after 30 days helps nobody.
Visa Compelling Evidence 3.0: the rule built for repeat customers
Visa introduced Compelling Evidence 3.0 in April 2023 to help merchants fight one specific dispute: card-absent fraud, reason code 10.4, where the cardholder says they did not make the purchase.
The idea is simple. If the same cardholder made earlier purchases with you that they never disputed, and those purchases share identifying data with the disputed one, the "I didn't buy this" claim becomes much weaker.
What CE 3.0 requires
Under CE 3.0, the merchant provides at least two qualifying prior undisputed transactions on the same payment credential, generally processed 120 to 365 days before the dispute processing date. At least two core data elements must match across the prior transactions and the disputed transaction: user account ID, IP address, shipping address, or device ID/fingerprint. At least one matching element must be the IP address or device ID/fingerprint. An email address or account login alone does not replace that requirement. Confirm the current eligibility rules and any exceptions with your acquirer before submitting evidence.
When the evidence qualifies, the issuer is expected to accept it and the fraud dispute can be reversed. For digital goods sellers with subscription or repeat-purchase models, this is powerful, but only if you have been storing IP addresses, device data, and account IDs all along.
CE 3.0 does not help with first-time buyers, and it does not apply to "not received" disputes. It is one tool, not a complete strategy.
3-D Secure and the liability shift
3-D Secure is the authentication layer behind Visa Secure and Mastercard Identity Check. The issuer verifies the cardholder, often silently using device and behavior data, and sometimes with a one-time code or app approval.
When a transaction is successfully authenticated with 3-D Secure, liability for most fraud-related chargebacks generally shifts from the merchant to the issuer. That means a stolen-card dispute on an authenticated order is far less likely to cost you.
The trade-off is friction. A challenge step can reduce conversion, and the liability shift does not cover "not received" or quality disputes. Many digital merchants apply 3-D Secure selectively, using it on higher-value orders, new accounts, or risky signals, rather than on every purchase.
Refund policy as a fraud control
Many digital sellers run strict no-refund policies, reasoning that a downloaded file cannot be returned. The logic is understandable, but it often backfires. A customer who cannot get a refund from you will ask their bank instead, and a dispute costs more than a refund in fees, time, and ratio damage.
A clear, limited refund policy gives frustrated customers a cheaper exit. For example, you might allow refunds within a short window when the product has not been accessed or activated. Make the policy visible at checkout, require customers to accept it, and keep a record of that acceptance as part of your evidence.
Watch for refund abuse too
Track refund requests by account, device, and payment method. A small group of repeat requesters often accounts for a large share of refunds. Flag them, limit their purchases, or require additional verification before their next order.
Layering it together
No single control handles everything. A practical stack for digital sellers looks like this:
- Bot and velocity controls to stop card testing at the door
- Risk scoring and 3-D Secure for orders that look unusual
- Automatic logging of IP, device, account, and access data on every order
- Clear delivery emails, an easy help path, and a visible refund policy
- Fast, organized dispute responses that use CE 3.0 where it applies
Each layer reduces a different kind of loss. Together they keep your dispute and fraud ratios low enough that your processor sees a well-run business rather than a target.
Why the right merchant account matters for digital sellers
Mainstream processors often approve digital businesses quickly, then react hard to the first card-testing spike or dispute cluster with a reserve or closure. The issue is usually not your product. It is an account that was never underwritten for how digital goods actually behave.
We work with merchants who need card processing designed for instant-delivery products, with fraud tools and chargeback protection built into the setup.
Start logging before the next dispute arrives
Check today whether your platform records IP address, device data, login ID, and access timestamps for every order, and how long it keeps them. If it does not, that gap is costing you disputes you could win.
When you are ready to move to an account built for digital products and their risk profile, start your application with Karma Card Payments.
Sources and timing
Last reviewed October 5, 2026. Network rules and legal requirements can change; confirm the rules that apply to your account and products.
