Protect Your Business.
Know What To Do Next.
Fraud, scams, payment issues, stolen cards, counterfeit cash and cybersecurity threats can affect businesses of any size. Explore practical resources designed for brick-and-mortar merchants to help recognize risks, protect your business and take action when something happens.
Security Resources Built for Real-World Merchants
Your business does not have to sell online to face fraud. Physical stores can encounter stolen cards, EBT fraud, counterfeit cash, chargebacks, employee-related risks, suspicious transactions and compromised business accounts.
What Should Your Business Watch For?
Understanding common risks can help owners and employees recognize suspicious activity before it becomes a larger problem.
Payment Card Fraud
Watch for suspicious card-present transactions, unusual customer behavior, counterfeit cards and attempts to bypass normal payment procedures.
EBT & SNAP Fraud
EBT cards and benefits can be targeted through skimming, stolen card information, PIN theft and other forms of fraud.
Cash & Counterfeit Fraud
Counterfeit bills, short-changing schemes, altered currency and other cash-handling issues can create losses at the register.
Chargebacks & Disputes
Understand why payment disputes happen and how accurate transaction records, procedures and documentation can help.
Account Takeover
Compromised email, POS administration, payment portal and business credentials can create risks even when a business has no e-commerce operation.
Scams & Impersonation
Criminals may impersonate processors, vendors, banks, employees or government agencies to obtain money, information or access.
Fraud & Loss Prevention for Brick-and-Mortar Merchants
Know what to look for at the register, on your payment terminal and throughout your everyday business operations.
Stolen & Suspicious Cards
Learn how to recognize potentially fraudulent card-present transactions and suspicious activity at the point of sale.
Visa Fraud Prevention for Merchants →Chargebacks & Disputes
Understand common reasons for payment disputes and steps merchants can take to reduce preventable chargebacks.
Visa Chargeback Resources →EBT & SNAP Fraud
Explore retailer resources related to SNAP fraud, EBT security, card theft, skimming and program integrity.
USDA/FNS Retailer Resources →EBT Card Skimming
Criminals can target EBT cards and POS terminals. Learn more about EBT-related fraud and skimming from the U.S. Secret Service.
U.S. Secret Service EBT Fraud Information →Card Skimming
Learn how unauthorized devices can capture card information and how regular inspection of in-store payment terminals can help identify signs of tampering.
Card Skimming Best Practices →Account Takeover Prevention
Protect business email, POS administration, payment portals and other accounts with stronger authentication and access controls.
CISA MFA Guidance →Counterfeit Cash
Give employees practical tools for identifying genuine U.S. currency and recognizing potentially counterfeit notes.
U.S. Currency Cashier Toolkit →Suspicious Cash Transactions
Learn about federal reporting considerations for businesses that receive large amounts of cash.
IRS Form 8300 Reference Guide →Fraudulent IDs & Identity Theft
Understand identity-theft red flags and suspicious customer activity that employees may encounter in a physical store.
FTC Identity Theft Guidance →Protect Your Business From Card Skimming
Card skimming happens when criminals attach or install unauthorized devices on or inside payment terminals to capture card information during transactions. Because skimmers can be difficult to spot, regular inspection of in-store payment equipment is an important part of protecting your business and customers.
What Is a Card Skimmer?
A skimmer is an unauthorized device that can be attached to or installed inside a payment terminal, ATM or POS system. It is designed to capture card information during a transaction and may also be used to capture a PIN. Skimmers can take the form of external attachments, hidden internal components or overlays placed on top of legitimate hardware.
Key point: Skimming devices are often designed to blend in with normal payment equipment. Employees should know what their terminals normally look and feel like.
How to Spot Signs of Tampering
Check for Loose or Misaligned Parts
Card readers or keypads that look loose, bulky, raised or misaligned may warrant closer inspection.
Compare Similar Terminals
If one terminal looks different from other terminals of the same model, investigate the difference before continuing normal use.
Look for Damaged or Missing Seals
Broken or missing security seals, panels or stickers can be a warning sign of possible tampering.
Watch for Unusual Behavior
Freezing, unexpected behavior or changes in how a terminal operates should be reported and investigated through your normal procedures.
Simple Steps to Keep Payment Devices Secure
Inspect Devices Regularly
Make payment-terminal inspection part of routine store procedures and look for physical changes or damage.
Limit Access
Restrict access to payment terminals to authorized employees and make staff aware of what normal equipment should look like.
Keep a Reference
Maintain a photo or other record of how each payment device normally looks so employees can quickly compare equipment.
Report Suspicious Equipment
If equipment appears tampered with, follow your established procedures and contact the appropriate payment, terminal or security support team.
Make Skimming Awareness Part of Store Operations
Fraud prevention is strongest when merchants and employees stay attentive to changes in payment equipment. Familiarity with the normal appearance and operation of each terminal makes unusual physical changes easier to recognize.
Include terminal checks in routine employee training and store procedures, especially when equipment is serviced, moved or replaced.
Learn More About Payment Card Skimming →
Keep Payment Security Top of Mind
For brick-and-mortar merchants, payment security starts at the point of sale. Employees should understand normal transaction procedures, know how to recognize suspicious activity and know when to involve a manager.
Keep payment terminals secure, restrict administrative access, train employees on fraud indicators and maintain consistent transaction procedures.
Learn About Payment Security →Protect Your Business From Cyber Threats
Even merchants that never accept an online order rely on email, payment systems, POS systems, vendor portals and other connected accounts.
Protect administrative accounts, use multifactor authentication where available, limit access and make sure former employees no longer have access to business systems.
Explore Cybersecurity Resources →
What to Do If Something Happens
The right response can help limit damage. Start by documenting what happened, securing affected systems or devices and contacting the appropriate organization.
Stop the transaction or communication if possible. Do not provide passwords, payment credentials or sensitive information. Document what happened and contact the company or financial institution being impersonated through a verified phone number or website.
Change the affected password immediately from a trusted device. Enable multifactor authentication and review recent account activity. If the account provides access to payment systems, POS administration or sensitive business information, notify the appropriate provider.
Follow your established transaction procedures, involve a manager and contact your payment provider when appropriate. Preserve transaction records and do not attempt to confront or investigate suspected criminals yourself.
Follow your normal store and transaction procedures. If a terminal appears tampered with, stop using it and contact the appropriate support organization. For SNAP-related concerns, consult USDA/FNS retailer guidance.
Follow your cash-handling procedures and avoid returning a suspected counterfeit note to circulation. Employees should use established escalation procedures and consult official currency guidance.
Secure the affected account, change credentials, enable multifactor authentication and contact the relevant provider. Review recent account activity and check whether unauthorized changes were made.
Secure affected systems, preserve relevant records and contact the appropriate technology, payment or security provider. Depending on the circumstances, legal, regulatory or law-enforcement assistance may also be appropriate.
Think Your Information Has Been Compromised?
If personal or business information has been stolen, act quickly and document what happened.
1. Secure Accounts
Change affected passwords and enable multifactor authentication.
2. Review Activity
Look for unauthorized transactions, account changes or new activity.
3. Document
Keep records of suspicious transactions, communications and affected systems.
4. Report
Contact appropriate financial institutions, providers or government agencies.
5. Monitor
Continue monitoring affected accounts and systems for additional activity.
Protect Payment Data With PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) provides a baseline of technical and operational requirements designed to protect payment account data.
PCI DSS applies across the payment ecosystem, including merchants and other organizations that store, process or transmit cardholder data, or that could impact the security of the cardholder data environment.
- Protect payment and cardholder data.
- Use secure systems and configurations.
- Control access to systems and sensitive information.
- Monitor and test security controls regularly.
- Maintain appropriate information security policies.
PCI compliance and validation requirements can vary depending on the merchant's payment environment and the organizations managing its compliance program. Merchants should confirm their specific requirements with their acquirer or applicable payment brands.
Build Security Into Everyday Business Practices
Payment security is more than a compliance exercise. It involves the technology you use, how employees access systems, how payment devices are protected and how sensitive information is handled.
Make security part of everyday operations by limiting access, protecting credentials, keeping systems updated and training employees on suspicious activity.
Explore PCI Security Standards →Simple Steps to Strengthen Your Business
Good security practices should be part of normal store operations—not something you only think about after a problem occurs.
Secure Your Payments
Keep payment terminals secure and make sure employees follow consistent transaction procedures.
Protect Your Data
Limit access to sensitive information and avoid storing information that your business does not need.
Train Your Employees
Teach employees what suspicious cards, cash, requests, calls and messages can look like.
Secure Your Accounts
Use strong passwords, multifactor authentication and appropriate access controls for business systems.
What Should Your Business Watch For?
Train employees to pause when a transaction, request or situation does not look or feel normal.
Unexpected Urgency
Someone demands immediate payment, account access or sensitive information.
Unusual Payment Instructions
A caller or customer asks employees to bypass normal procedures or use an unfamiliar payment method.
Suspicious Cards
A card appears damaged, altered or inconsistent with normal transaction behavior.
Unusual EBT Activity
Employees notice suspicious behavior involving EBT cards, PINs or payment equipment.
Counterfeit Cash
A bill does not appear to have normal security features or feels different from genuine currency.
Impersonation
Someone claims to be a processor, bank, vendor, employee or government representative and requests sensitive information.
Security Is an Ongoing Business Practice
Fraud prevention works best when everyone understands their role. Owners, managers and employees should know how to recognize suspicious activity, follow established procedures and escalate concerns.
Review your procedures regularly and update employee training when your payment technology, products or business processes change.
Government & Official Security Resources
These resources provide additional information from government agencies, payment networks and industry organizations.
U.S. Currency Education Program
Official tools for cashiers and businesses to learn about U.S. currency security features and counterfeit detection.
Cashier Toolkit →USDA / FNS SNAP Resources
Retailer resources covering SNAP, EBT, program integrity and related retailer responsibilities.
Explore SNAP Resources →U.S. Secret Service
Information on financial crimes, EBT fraud, counterfeit currency and related investigations.
EBT Fraud Information →IRS Form 8300
Information for businesses regarding reporting requirements for qualifying large cash transactions.
IRS Form 8300 Guide →CISA Small Business Security
Practical cybersecurity guidance for small and medium-sized businesses, including account protection and multifactor authentication.
Explore CISA Resources →FTC Business Resources
Business guidance covering scams, identity theft, fraud, data security and other consumer-protection issues.
Explore FTC Resources →PCI Security Standards Council
Official information about PCI DSS and payment account data security.
Visit PCI SSC →Visa Merchant Fraud Prevention
Merchant-focused guidance for recognizing and preventing payment fraud.
Visa Fraud Prevention →Mastercard Dispute Management
Resources covering disputes, chargebacks and payment fraud prevention.
Mastercard Resources →CDE Resources
Continue learning with CDE's resources covering payment security, fraud prevention and merchant protection.
Best Ways to Help Small Merchants Fight Fraud
Practical considerations for helping small businesses recognize and respond to common fraud risks.
Read the Article →Payment Security Should Come First
Learn why payment security should remain a priority as merchants manage their day-to-day operations.
Read the Article →Build Security Into Everyday Operations
Use this checklist as a starting point for reviewing your everyday fraud and payment-security practices.
Have a Payment or Security Concern?
If you have questions about your CDE payment environment or need assistance, our team is here to help.
The information provided on this page is for general educational purposes only and is not legal, financial, regulatory, cybersecurity or professional advice. Fraud prevention, PCI DSS compliance and validation requirements may vary based on a merchant's business, payment environment, applicable payment brands, acquirer and other circumstances. Merchants should consult the appropriate organizations for guidance specific to their situation. External websites and resources are independently operated and are not controlled by CDE Solutions.