Key takeaways
- Fraud disputes and non-fraud disputes both count toward network thresholds around 0.9 percent to 1 percent, so prevention and evidence both matter.
- Layered controls (AVS, CVV, velocity, device and address signals, 3-D Secure on risky orders) stop most fraud before it posts.
- California's CCPA/CPRA shapes how you collect and retain the data your fraud tools rely on.
Fraud detection for California ecommerce is not one tool; it is a set of controls at different points in the order. California sellers see more of every fraud type because of scale: direct-to-consumer brands in Los Angeles and the Bay Area, Inland Empire fulfillment operations shipping nationwide, San Diego and Orange County apparel and supplement companies, and thousands of Shopify and WooCommerce stores run from home. Fraudsters target the state's sellers for the same reason customers do: high volume, high-value goods, and fast shipping. This guide covers what attacks look like, what the networks measure, and what actually reduces losses.
The three kinds of fraud you will see
- Card testing: a bot runs hundreds of small transactions with stolen card numbers to find the ones that work. You see a burst of $1-$5 orders, many declines, and then chargebacks on the ones that succeeded, plus per-transaction fees on all of them.
- Stolen-card orders: a real order with a stolen card, usually shipped to a different address than the billing address, often expedited. The cardholder disputes it weeks later and you lose the goods and the sale.
- Friendly fraud (first-party misuse): the real cardholder places the order, receives it, and disputes it anyway. This is now the largest category for many sellers and cannot be stopped at checkout; it is fought with evidence.
What the networks measure
Visa and Mastercard each run monitoring programs that count your disputes against your transactions monthly. Practically, a ratio approaching 0.9 percent to 1 percent puts you on a watch list, and sustained excess brings fines and, eventually, termination and a MATCH listing. Visa's current program combines fraud and non-fraud disputes into one measure, so friendly fraud counts as much as stolen-card fraud. This is why prevention and dispute response are both required.
Layered controls at checkout
No single check stops fraud. A reasonable stack for a California seller:
- Address Verification (AVS) and CVV on every order; decline full mismatches, review partial ones.
- Velocity rules: limit attempts per card, per IP, per device and per email over a window. This alone shuts down most card-testing.
- Order signals: billing-shipping mismatch, new customer plus expedited shipping plus high ticket, freight-forwarder addresses, disposable email domains.
- 3-D Secure (Verified by Visa, Mastercard Identity Check) on orders that score as risky. It shifts fraud liability to the issuer on authenticated transactions, at the cost of some friction, so apply it selectively rather than to every order.
- Manual review for a small slice of high-value orders, with a rule that review happens before shipping, not after.
A gateway with built-in fraud detection can run these rules in real time and score each order, which is far more reliable than your fulfillment team eyeballing addresses. Pair it with tokenization so card numbers never touch your servers; a breach of stored cards is a worse outcome than any single fraud loss.
Fighting friendly fraud with evidence
For disputes from real customers, your defense is documentation the networks recognize as compelling: delivery confirmation to the verified address, the customer's IP and device matching prior undisputed orders, order confirmation emails, customer service transcripts, and, for digital goods, access logs. Visa's compelling-evidence rules allow a merchant to show a prior undisputed transaction from the same customer with matching data points to defeat a fraud claim. Build the habit of capturing and storing these signals on every order so the evidence exists when you need it. Respond to every dispute within the deadline; unanswered disputes are lost disputes.
California data rules and your fraud program
Fraud tools run on data: IP addresses, device fingerprints, order history. If your business meets CCPA/CPRA thresholds, that data is personal information subject to disclosure and deletion rights, though the law includes exceptions for security and fraud prevention. Write your privacy policy to reflect what you actually collect and why, set a retention period, and confirm the fraud-prevention exception with counsel rather than assuming it covers everything. Store card data as tokens and you reduce both your PCI scope and your CCPA exposure.
Subscriptions and the dispute they create
Many California ecommerce brands run subscriptions or auto-ship. The most common dispute there is not fraud; it is "I did not know I would be charged again." California's Automatic Renewal Law requires affirmative consent and easy online cancellation, and the card networks require pre-billing reminders and clear terms. A seller who gets that right removes a large slice of disputes from the ratio before any fraud tool runs. See how to bill free-trial offers without getting shut down for the flow.
Fraud detection for a California online seller comes down to three habits: stop bad orders at checkout with layered rules, capture evidence on every good order so friendly fraud can be fought, and run subscriptions cleanly so honest customers do not become disputes. The ratio the networks watch is the sum of all three.
Ready to get set up with Flux?
Cards, ACH, and stablecoins in one platform, with volume-based pricing. No setup fees or contracts.
Get Started