Cut Virtual Terminal Fraud Without Killing Your Approval Rate

Cut Virtual Terminal Fraud Without Killing Your Approval Rate

Get started with SeamlessChex
Written by
Lily Flanigan
A business professional reviewing virtual terminal transaction data on a secure payment dashboard, with visual security indicators, clean modern office environment, blue and white color scheme

Key Points

  • Blanket 3-D Secure drops virtual terminal approval rates 8-12%; risk-based routing that applies 3DS only to flagged transactions cuts that impact to 1-3%.
  • CVV requirements eliminate card-testing and breach-data fraud with near-zero impact on legitimate customers, because PCI rules prevent merchants from storing CVV data.
  • ClearSale research finds every $1 in false declines costs $13 in customer lifetime value, making targeted fraud controls more valuable than blanket rules.
Three things virtual terminal merchants believe. Myth or fact?
Call each one, then see how other readers called it.
1 Enabling 3-D Secure on all virtual terminal transactions is the safest fraud strategy.
2 Risk-based 3DS routing typically reduces the approval-rate drop to just 1-3%, versus 8-12% for blanket 3DS.
3 Requiring CVV on keyed virtual terminal transactions creates friction and hurts approval rates.
A business professional reviewing virtual terminal transaction data on a secure payment dashboard, with visual security indicators, clean modern office environment, blue and white color scheme

Quick Answer

Enable AVS and CVV matching on your virtual terminal as your baseline, then apply 3-D Secure only to transactions that show specific fraud signals. That combination cuts card-not-present chargebacks substantially without the 8-12% approval-rate drop that blanket 3DS controls produce.

Did this answer your question?

Virtual terminals are built for card-not-present transactions, which means they carry inherently higher fraud risk than swipe-and-dip processing. Most merchants respond one of two ways: they ignore fraud controls until chargebacks accumulate, or they enable every available security layer and watch approval rates slide. Neither approach works. As one fintech analysis put it, "fraud is no longer an occasional problem. It is now a business expense." The real play is targeted controls: AVS and CVV as your baseline, and 3-D Secure reserved for transactions that already show fraud signals. Merchants who configure this stack correctly see chargeback rates drop sharply without the approval-rate hit they feared. This piece walks through exactly how to set it up and what to expect from each layer.

Card-not-present fraud costs merchants more per dollar than any other fraud type, and virtual terminal transactions sit squarely in that category. Every time an order is keyed in manually, the cardholder is not physically present to verify. That gap is where fraud enters, and the U.S. CNP fraud rate has increased gradually over the past decade, per research from the Kansas City Federal Reserve. Merchant fraud losses are projected to climb from $38 billion in 2023 to $91 billion by 2028. Fortunately, the tools to close the virtual terminal fraud gap exist inside most payment gateways. The challenge is configuring them in a way that stops bad transactions without blocking the good ones.

Diagram showing virtual terminal transaction risk routing: clean transactions proceeding to authorization, flagged transactions routing through 3-D Secure step-up authentication

AVS and CVV Are Your Zero-Friction Starting Point

Address Verification Service (AVS) and CVV matching are the two controls that add the most fraud protection with the least impact on legitimate customers.

I would recommend enabling both before reaching for anything else on a virtual terminal.

AVS checks the billing address a customer provides against what the card issuer has on file. A full match, street number and ZIP code, is a strong signal that the person entering the card is the actual cardholder. A no-match is a meaningful red flag worth acting on.

CVV is the three- or four-digit code printed on the physical card. It cannot be stored by merchants under PCI rules, so card numbers stolen in a data breach typically come without it. Requiring CVV on every virtual terminal transaction eliminates a significant share of card-testing fraud automatically, because most stolen card data simply does not include the CVV.

  • Set AVS to decline on full ZIP-code mismatches for higher-risk order profiles
  • Flag AVS no-match for manual review rather than automatic decline on lower-value orders
  • Require CVV on every transaction with no exceptions
  • Track AVS decline rates weekly to catch emerging fraud pattern shifts early

Research from ClearSale finds that up to 70% of declined transactions come from legitimate customers, which is why blanket declines on partial AVS mismatches hurt more than they help. Configure these tools to flag, not just block, and your false-decline rate stays low while you still catch meaningful fraud.

3-D Secure Works When You Use It Selectively

3-D Secure (3DS) shifts liability for fraudulent chargebacks to the card issuer when authentication succeeds.

That is a meaningful financial protection. The reason many merchants avoid it comes down to one number: blanket 3DS deployment typically drops approval rates by 8-12% because some customers abandon or fail the step-up authentication prompt.

The solution is risk-based routing. Instead of requiring 3DS on every transaction, configure your gateway or fraud tool to trigger step-up authentication only when specific risk signals appear:

  • Transaction value above a defined threshold (typically 3x your average order value)
  • Billing and shipping address mismatch on a digital product or recurring order
  • Multiple failed card attempts within the same session
  • First-time customer placing a high-value order
  • IP address flagged in fraud intelligence databases

When 3DS applies only to this flagged segment, the approval-rate impact typically falls to 1-3%. Most legitimate customers never see the authentication step. The transactions that route through 3DS are exactly the ones that warranted the extra scrutiny.

This configuration is what makes the fraud/approval tradeoff work in your favor. As Redbridge's payment consulting practice notes, merchants often rely on provider claims about their fraud tools rather than independently measuring false declines against actual fraud caught. That gap is where approval rates quietly erode.

Questions this article answers

  • Does enabling 3-D Secure on a virtual terminal hurt approval rates?
  • What fraud controls should I enable first on a virtual terminal?
  • How does risk-based 3DS routing actually work in practice?

What Changes in the Next 12-24 Months

The card networks are tightening CNP fraud rules, and enforcement on high-risk merchant categories is accelerating. Two shifts stand out for virtual terminal operators.

First, 3-D Secure 2.x is replacing the original 3DS protocol across most major gateways. The newer version passes significantly more contextual data to the card issuer, including device fingerprint, prior transaction history, and behavioral signals. That richer data set enables frictionless authentication on a higher share of legitimate transactions. The approval-rate cost of 3DS is shrinking as a result, which removes the main argument against enabling it on flagged transactions.

Second, fraud is growing more sophisticated rather than more voluminous. Recorded Future's 2025 Payment Fraud Intelligence Report, published in partnership with Mastercard, found that 10,500 Magecart-style attacks were active in 2025, compromising over 23 million online transactions. Criminals are also deploying tools that steal one-time passwords used in step-up authentication, meaning static fraud rules become stale faster than they used to.

For virtual terminal merchants, this means the configuration you set up today needs a review cadence, not just a one-time setup. Chargeback thresholds under Visa's Acquirer Monitoring Program and Mastercard's Excessive Chargeback Program are tightening for CNP-heavy categories. Merchants running proper AVS, CVV, and risk-based 3DS controls now are building a defense posture ahead of those thresholds, not scrambling to meet them after the fact.

Running a virtual terminal for high-risk credit card processing? SeamlessChex builds merchant accounts with fraud controls calibrated to your transaction profile. Get approved today and keep more of what you process.

What 12-24 months May Bring

Where Virtual Terminal Fraud Controls Are Headed

Three data-backed forecasts on how merchants will balance fraud filters and approval rates over the next two years.

26 sources analyzed8 industry publications3 community discussions3 video sources1 government source
A

What Merchants Should Expect Next

Use these forecasts to gauge which fraud-control investments are likely to pay off before you tighten or loosen your rules.

70/100
High confidence 12-24 months

Virtual card usage for B2B and recurring payments will keep growing toward the projected $175 billion in transaction volume by 2028 (up from $36 billion in 2023), pulling spend away from checks, which account for more than 60% of fraud losses despite their shrinking payment share.

The Contrarian Call
64/100
Medium confidence 12-24 months

Rather than fraud rising uniformly across all card-not-present transactions, growth will keep concentrating in specific vectors - Magecart-style skimming and automated fake-account creation - while broad CNP fraud loss rates continue their decade-long gradual climb rather than spiking.

Weak Signals Worth Watching Build.com automated 100% of fraud decisioning with Signifyd, maintaining a 98% approval rate while cutting chargebacks 96%, and Redbridge reports a 2% average net revenue uplift from approval-rate optimization without compromising fraud control. Stolen credit card records available for sale fell nearly 20% in 2025 even as 10,500 Magecart-style skimming operations compromised over 23 million transactions, and U.S. non-prepaid debit card CNP fraud loss rates have only increased gradually over the past decade rather than surging. Virtual cards account for just 9% of fraudulent transactions while checks account for more than 60% of all fraud payments, per Mastercard's Cindy Finley, and virtual card transaction volume is projected to nearly quintuple by 2028.

B

Supporting and Contrary Evidence

Each forecast is paired with the market data that supports it and the data that could undercut it.

Guaranteed fraud decisioning displaces rules-only filtering 82
Supporting evidence
  • Backing it: How Build with Ferguson reduced ecommerce fraud with Signifyd. [Video]Build.com (referred to as "bill.com" in the transcript audio) and Signifyd have been partners for over 10 years. “They involve their customers in making new products or new features within their product, and you really feel like you're part of their team.”
  • Fraud and Approval Rates - Redbridge is the strongest public backing for this call. [Industry Publication]“Redbridge helps clients unlock millions in lost revenue by maximizing acceptance rates without compromising on fraud control.”
  • Backing it: The Impact of Ecommerce Fraud Prevention Rules on Approval Rates. [Industry Publication]Fraud prevention rules/filters include five common types: Daily/Hourly Velocity Filter, Address Verification System (AVS), Card Verification Value (CVV) Filter, Purchase Amount Filter, and Geolocation Filter. “As a first line of defense, many businesses rely on fraud prevention rules or fraud filters to protect their bottom line and customers.”
Virtual cards keep displacing checks and static card numbers 70
Supporting evidence
Fraud growth concentrates in specific vectors, not broad CNP volume 64
Supporting evidence
  • The case rests on Payments fraud is growing in scale and sophistication | Mastercard US. [Industry Publication]Number of stolen credit card records accessible for sale dropped by almost 20% in 2025 vs. the prior year (Recorded Future). “Fraud that targets payments is growing more complex and sophisticated.”
  • Card-Not-Present Fraud Rates in the United States After the points the same way. [Industry Publication]Unlike many other countries, the U.S. did not see a surge in card-not-present (CNP) fraud rate immediately after migrating to EMV chip-card technology. “As consumers have shifted more of their economic activities online, their use of payment cards has also shifted from a 'card-present' (in-person) to a…”
C

What Could Change These Forecasts

Shifts in fraud loss trends or chargeback guarantee pricing could shift these projections.

Confidence, With Limits

Of everything here, 82 rests on the firmest ground, and 64 carries the most open questions.

  • Guaranteed fraud decisioning displaces rules-only filtering. That is the first forecast to break if the regulatory or buying picture flips.
  • Fraud growth concentrates in specific vectors, not broad CNP volume. Mounting evidence on the other side would move that one to the front.
Methodology Our forecasts are built from real-time payment data, direct conversations with businesses, and patterns we track across high-risk industries.

What the Full Stack Looks Like in Practice

Merchants who layer AVS, CVV, and risk-based 3DS see measurable results quickly. In my experience working with high-risk credit card processing clients at SeamlessChex, chargeback rates tend to move within the first billing cycle once controls are properly configured.

Here is how each layer performs against fraud and approval rates:

Control What It Stops Approval Rate Impact
CVV required Card-testing and breach-data fraud Minimal (legitimate cardholders have it)
AVS matching Flags a meaningful share of fraudulent CNP attempts Under 2% on genuine customers
Blanket 3DS 60-80% chargeback reduction 8-12% approval drop
Risk-based 3DS 50-70% chargeback reduction 1-3% approval drop

The Build.com / Signifyd case illustrates what is possible at scale: 98% approval rate maintained while reducing chargebacks by 96% through automated, pre-authorization fraud decisioning. That result is not achievable with blanket controls. It comes from routing decisions that match the risk profile of each transaction.

ClearSale's research puts the cost of a false decline at $13 in lost customer lifetime value for every $1 blocked. Risk-based 3DS consistently outperforms blanket 3DS on that metric. Fewer false positives means less revenue lost to unnecessary friction, and your legitimate customers keep a clean path to checkout.

The fraud/approval tradeoff on virtual terminals is a false choice once you move beyond blanket controls. AVS and CVV add meaningful protection at essentially no cost to legitimate customers. Risk-based 3DS applies friction only where the transaction profile calls for it. Merchants who build this stack correctly stop losing revenue to fraud and stop losing revenue to unnecessary declines. The configuration is the job. If you are running a virtual terminal for credit card processing and still relying on gateway defaults, now is the time to review those settings.

Written by

Lily Flanigan

Operations Manager, SeamlessChex

Lily Flanigan is Operations Manager at SeamlessChex, a credit card processing and fintech payments platform recognized on the Inc. 5000, where she focuses on operations and process optimization.

Connect on LinkedIn

Summarize This Article With AI

Open this article in your preferred AI engine for an instant summary.

Frequently Asked Questions

Does requiring CVV on virtual terminal transactions actually reduce fraud?

Yes. CVV data is not stored on card databases or in data breach dumps, because PCI rules prohibit merchants from retaining it post-authorization. Card numbers stolen in breaches typically come without the CVV, so requiring it on virtual terminal transactions eliminates a substantial share of card-testing attacks automatically.

What is the approval-rate impact of enabling 3-D Secure on a virtual terminal?

Blanket 3DS applied to every transaction typically drops approval rates 8-12% because some customers abandon or fail the step-up authentication prompt. Risk-based routing that sends only flagged transactions through 3DS reduces that impact to 1-3%, since most legitimate customers never reach the authentication step.

Can I use AVS on manually keyed virtual terminal transactions?

Yes. AVS works on keyed-entry transactions. The customer provides their billing ZIP code and street number when the order is placed, and the gateway checks it against what the card issuer has on file. It is one of the simplest controls to enable and costs nothing in additional fees.

What risk signals should trigger 3-D Secure on a virtual terminal?

High transaction value relative to your average order, billing and shipping address mismatch on digital product orders, multiple failed card attempts in the same session, first-time customers placing large orders, and IP addresses flagged in fraud intelligence databases are the most reliable triggers.

Does 3-D Secure protect against all types of chargebacks?

No. When 3DS authentication succeeds, liability for fraudulent chargebacks shifts from the merchant to the card issuer. That protection applies only to authenticated transactions, and it does not cover chargebacks filed for reasons such as "merchandise not received" or "service not as described."

To qualify for a SeamlessChex account, a business needs an established operating history and $25,000+ in monthly processing volume.