Home / Resources

California

Fraud Detection for California Online Sellers

How card-testing, stolen-card orders and friendly fraud hit California ecommerce, what the network monitoring programs measure, and which controls actually work.

Flux PaymentsApril 4, 20244 min read

Key takeaways

  • Fraud disputes and non-fraud disputes both count toward network thresholds around 0.9 percent to 1 percent, so prevention and evidence both matter.
  • Layered controls (AVS, CVV, velocity, device and address signals, 3-D Secure on risky orders) stop most fraud before it posts.
  • California's CCPA/CPRA shapes how you collect and retain the data your fraud tools rely on.

Fraud detection for California ecommerce is not one tool; it is a set of controls at different points in the order. California sellers see more of every fraud type because of scale: direct-to-consumer brands in Los Angeles and the Bay Area, Inland Empire fulfillment operations shipping nationwide, San Diego and Orange County apparel and supplement companies, and thousands of Shopify and WooCommerce stores run from home. Fraudsters target the state's sellers for the same reason customers do: high volume, high-value goods, and fast shipping. This guide covers what attacks look like, what the networks measure, and what actually reduces losses.

The three kinds of fraud you will see

What the networks measure

Visa and Mastercard each run monitoring programs that count your disputes against your transactions monthly. Practically, a ratio approaching 0.9 percent to 1 percent puts you on a watch list, and sustained excess brings fines and, eventually, termination and a MATCH listing. Visa's current program combines fraud and non-fraud disputes into one measure, so friendly fraud counts as much as stolen-card fraud. This is why prevention and dispute response are both required.

Layered controls at checkout

No single check stops fraud. A reasonable stack for a California seller:

  1. Address Verification (AVS) and CVV on every order; decline full mismatches, review partial ones.
  2. Velocity rules: limit attempts per card, per IP, per device and per email over a window. This alone shuts down most card-testing.
  3. Order signals: billing-shipping mismatch, new customer plus expedited shipping plus high ticket, freight-forwarder addresses, disposable email domains.
  4. 3-D Secure (Verified by Visa, Mastercard Identity Check) on orders that score as risky. It shifts fraud liability to the issuer on authenticated transactions, at the cost of some friction, so apply it selectively rather than to every order.
  5. Manual review for a small slice of high-value orders, with a rule that review happens before shipping, not after.

A gateway with built-in fraud detection can run these rules in real time and score each order, which is far more reliable than your fulfillment team eyeballing addresses. Pair it with tokenization so card numbers never touch your servers; a breach of stored cards is a worse outcome than any single fraud loss.

Fighting friendly fraud with evidence

For disputes from real customers, your defense is documentation the networks recognize as compelling: delivery confirmation to the verified address, the customer's IP and device matching prior undisputed orders, order confirmation emails, customer service transcripts, and, for digital goods, access logs. Visa's compelling-evidence rules allow a merchant to show a prior undisputed transaction from the same customer with matching data points to defeat a fraud claim. Build the habit of capturing and storing these signals on every order so the evidence exists when you need it. Respond to every dispute within the deadline; unanswered disputes are lost disputes.

California data rules and your fraud program

Fraud tools run on data: IP addresses, device fingerprints, order history. If your business meets CCPA/CPRA thresholds, that data is personal information subject to disclosure and deletion rights, though the law includes exceptions for security and fraud prevention. Write your privacy policy to reflect what you actually collect and why, set a retention period, and confirm the fraud-prevention exception with counsel rather than assuming it covers everything. Store card data as tokens and you reduce both your PCI scope and your CCPA exposure.

Subscriptions and the dispute they create

Many California ecommerce brands run subscriptions or auto-ship. The most common dispute there is not fraud; it is "I did not know I would be charged again." California's Automatic Renewal Law requires affirmative consent and easy online cancellation, and the card networks require pre-billing reminders and clear terms. A seller who gets that right removes a large slice of disputes from the ratio before any fraud tool runs. See how to bill free-trial offers without getting shut down for the flow.

Fraud detection for a California online seller comes down to three habits: stop bad orders at checkout with layered rules, capture evidence on every good order so friendly fraud can be fought, and run subscriptions cleanly so honest customers do not become disputes. The ratio the networks watch is the sum of all three.

Ready to get set up with Flux?

Cards, ACH, and stablecoins in one platform, with volume-based pricing. No setup fees or contracts.

Get Started
← Back to all posts