Gift card fraud against sellers comes in a handful of repeatable patterns: purchases made with stolen payment cards, takeover of genuine customer accounts, triangulation schemes that use your shop as a fulfilment step, leaks of codes by insiders or through systems, and codes that were drained before the customer used them. Distributors and resellers prevent it by screening orders before the code is shown, limiting who and what can see codes, and keeping records that make every unit traceable.
The reason sellers have to care more than most merchants is simple: a code is bearer value delivered in seconds. Once redeemed it cannot be recalled, so controls only work if they act before delivery.
Why gift cards attract fraud
Consumer protection bodies describe gift cards in the same terms fraudsters think of them. The US Federal Trade Commission warns that the card number and PIN let a scammer take the value loaded on a card “even if you still have the card itself”, and Apple’s support pages warn that once scammers obtain the numbers on the back, “the funds on the card might be spent” before the victim can contact Apple Support.
For a seller, three properties combine into risk:
- Instant delivery. There is no shipping window in which to spot a bad order.
- Anonymous redemption. The person who redeems need not be the person who paid.
- Easy resale. Codes can be turned into cash or goods quickly, which makes them attractive to anyone holding stolen payment credentials.
The five patterns sellers face
1. Purchases with stolen payment cards
The most familiar pattern. A fraudster uses stolen card details on your storefront, receives codes, and redeems or resells them. Weeks later the genuine cardholder disputes the charge, and you lose both the code and the payment. How that dispute process works, and how to respond, is covered in gift card chargebacks.
Signals worth scoring: a new account placing a large first order, many high-denomination items, mismatches between the card’s country, the IP location and the product region, several cards tried on one account, and repeat attempts after declines.
2. Account takeover
A fraudster logs in to a genuine customer’s account, often with credentials leaked elsewhere, and spends the stored card or wallet balance on codes sent to a new email. The payment looks legitimate because it is the customer’s own saved method.
Signals: login from a new device or location followed quickly by a purchase, changes to email, password or delivery address just before ordering, and an unusual product mix for that customer.
3. Triangulation
The fraudster runs or poses as a seller elsewhere, takes a real customer’s order and payment, then buys the same item from your shop with stolen card details and has it delivered to that customer. The end customer receives a working code and has no idea; you receive the chargeback. Because the recipient is genuine, the order can look clean.
Signals: delivery email different from the account email, many orders from one account to many different recipients, and recipients who later contact you confused about a purchase they never made from you.
4. Insider and system leaks
Codes held in a database, spreadsheet or support tool can be read and redeemed by staff, contractors or anyone who gains access. Leaks also happen through logs, error reports and exports that were never meant to carry codes. Unlike payment fraud, there is no chargeback to recover anything: the value is simply gone. The design choices that remove most of this risk are in storing gift card codes securely; the API connection itself, where a stolen key can buy codes directly, is covered in gift card API security.
5. Drained or pre-recorded codes
On physical cards, the FTC describes tampering in shops: fraudsters remove protective stickers or scratch off the back to record the numbers, then wait for the card to be loaded. In digital supply the equivalent is stock that was copied or redeemed somewhere upstream before it reached you, which customers experience as “already redeemed” on first use. The investigation and the evidence trail are set out in already-redeemed code disputes, and the upstream risk is the main reason to vet a gift card supplier before the first order.
Controls by pattern
| Pattern | Who carries the loss | Controls that work |
|---|---|---|
| Stolen-card purchases | The seller, through chargebacks | Pre-delivery scoring, cardholder authentication, velocity limits, delayed delivery for risky orders |
| Account takeover | The seller, and the customer’s trust | Login risk checks, step-up verification on new devices, cooling-off after account changes |
| Triangulation | The seller, through chargebacks | Recipient-versus-buyer checks, limits on distinct recipients per account, review of reseller-like patterns |
| Insider and system leaks | The business holding the codes | Fetch at sale or encrypt at rest, masked views, access logs, no codes in logs or exports |
| Drained or pre-recorded codes | Depends on supplier terms | Authorised sourcing, written replacement policy, first-use logging, test redemptions |
Building the controls into the order flow
The order of checks matters as much as the checks themselves.
- Before payment. Account age, login risk and basket composition. Block obviously bad orders before they reach the payment processor, which also protects your standing with it.
- At payment. Use the authentication your processor offers for card payments. Card networks shift some fraud liability for authenticated transactions; check the current rules with your acquirer.
- Before delivery. Score the whole order. For orders above your risk threshold, hold delivery for manual review rather than declining outright; a short delay is cheaper than a chargeback.
- At delivery. Fetch or decrypt the code only now, send it to the verified address, and record the identifier, time and recipient.
- After delivery. Watch for clusters: many disputes on one product, bursts of new accounts, repeated recipient addresses. Feed what you learn back into the scoring rules.
Limits, not just screens
Scoring catches patterns; limits cap the damage when scoring misses.
- Daily value limits per new account, lifted gradually with history
- Caps on distinct recipients per account per day
- Ceiling on high-denomination items for unverified buyers
- Spend limits on API keys and alerts on unusual order volume
- Separate staff roles: those who see codes do not handle refunds
- Prepaid balance with your supplier sized to normal trading, not the year
The last point is a supplier-side control. A funded balance is what a stolen API key or a compromised admin can spend, so keeping it close to actual need limits the worst case.
What distributors do upstream
Fraud control is shared along the chain. Distributors typically verify the businesses they supply through KYB checks and may screen transactions; some can investigate and block units when given identifiers. Giftoro, for example, runs KYB checks on business clients and supplies codes through an API and bulk files; the commercial setup is described on the gift card distributor page. Upstream checks do not replace your own screening, because only the seller sees the end customer.
Frequently asked questions
What are the most common types of gift card fraud for online sellers?
The main patterns are purchases made with stolen payment cards and account takeover, where a fraudster spends a genuine customer’s saved payment method. Triangulation, where your shop unknowingly fulfils another seller’s orders paid with stolen cards, is harder to spot. Sellers holding codes also face insider and system leaks, and occasionally codes that were drained before delivery.
How do resellers prevent gift card fraud?
By acting before the code is shown. That means scoring each order on account, device, payment and basket signals; authenticating card payments where the processor supports it; holding risky orders for review; capping value per new account and per recipient; and keeping codes encrypted or fetched only at the moment of sale. Records of every delivery make disputes and investigations possible afterwards.
Can a stolen gift card code be recovered?
Usually not once it is redeemed, because the value has moved to another account. If the code has not yet been used, the brand or the supplier may be able to block it, which is why sellers should record identifiers for every unit and report suspected exposure quickly. The FTC advises consumers who paid a scammer with a gift card to contact the card’s issuer right away.
What is triangulation fraud with gift cards?
A fraudster takes an order and payment from a real customer, often on a marketplace or social channel, then buys the same item from another shop using stolen card details and has it delivered to that customer. The customer receives a working code, the fraudster keeps the payment, and the shop that fulfilled the order absorbs the chargeback when the real cardholder disputes it.
Who pays when a gift card is bought with a stolen credit card?
In most cases the seller. When the genuine cardholder disputes the charge, the payment is reversed through the card network, while the code has already been delivered and usually redeemed. Card networks can shift liability for some fraud disputes on transactions authenticated with their schemes, so check the current rules with your acquirer and use authentication on higher-risk orders.