Dictionary
192 terms · search below
1st Party Fraud
Fraud committed by a customer against a financial institution or merchant, such as disputing valid charges with no intent to pay (see also Chargeback Fraud).
3DS
3D Secure
An authentication protocol (e.g., VBV, MCSC, AMEX Safe) adding extra verification for online card payments.
3rd Party Fraud
Fraud committed by an unrelated or unknown party against a financial institution or merchant, often involving stolen identities or credentials.
419 Fraud
Nigerian Letter Fraud
An advance-fee scam where victims are promised a share of a large sum in exchange for upfront payments, often originating from West Africa.
Account Takeover Fraud
ATO
Gaining control of a victim’s account (bank, social media, etc.) to change settings or steal funds (already in your list but emphasized here for clarity).
ACH Fraud
Manipulating Automated Clearing House transactions to siphon funds using stolen credentials or fake identities.
Active Authentication
Challenging a user with knowledge-based (e.g., password), possession-based (e.g., token), or biometric-based (e.g., fingerprint) verification.
Advance-Fee Fraud
A scam where victims pay an upfront fee for a promised larger reward that never materializes.
AMEX Safe
American Express SafeKey
A 3D Secure verification system for American Express online transactions.
Antidetect
Browser software generating unique fingerprints to evade detection by spoofing browser settings.
Antifraud
Security systems using AI and risk scoring to detect and block fraudulent transactions.
Arbers
Individuals exploiting betting site odds discrepancies to guarantee profits, often in online gambling.
ARP Spoofing
Binding a spoofer’s MAC address to a legitimate IP to gain access to a network and steal data.
Auth
Authorization Code
A code proving a transaction was approved, with different codes indicating specific outcomes.
Auth Check
A small test charge (e.g., $1-2) to verify a card’s validity, often refunded.
AVS
Address Verification System
A system comparing billing/shipping address numbers with card issuer records to verify transactions, used in the US, CA, UK, etc.
Back Door
A method to bypass security systems to access data, contrasting with front-door attacks like infected email attachments.
Balance
The amount of money available on a card, checked before use to avoid declines.
Bank Drop
A bank account opened with stolen or fake identities to receive fraudulent transfers.
Bank Logs
Stolen online banking credentials providing account access, more valuable with high balances.
Bank Method
A specific technique for extracting money from bank accounts, varying by bank and account type.
BIN
Bank Identification Number
The first six digits of a credit/debit card, identifying the issuing bank (e.g., 473702 for Wells Fargo).
BIN Attack Fraud
Using software to generate card numbers from a BIN and testing them with small transactions to find valid cards.
Bitcoin
BTC
A pseudonymous cryptocurrency used in dark web transactions, traceable if linked to a real identity.
Blacklist
A list of blocked IPs or domains known for spam or fraud, halting campaigns.
BLANK CPN
A real identity created with a real credit karma and Experian login. It’s in the credit system but it has a zero credit score or activity.
Blast
A large-scale spam campaign targeting many victims with phishing or scam messages.
Botnet
A network of compromised computers controlled remotely for fraud, data theft, or DDoS attacks.
Brute Force Attack
Using automated tools to try numerous username/password combinations to access accounts.
Burn
When a fraud method or card becomes unusable due to detection or patches.
Burner Phone
A temporary, disposable phone number or device used for fraud to bypass 2FA or account verification.
Caller ID Spoofing
Forging caller ID information to impersonate legitimate entities and extract sensitive data.
Card Cracking
Testing stolen or partial card details on websites to identify valid card numbers, often via small transactions.
Carder
An individual who engages in carding activities.
Cardholder
The owner of a credit or debit card.
Carding
Trafficking stolen credit card data to make direct purchases or charge prepaid/gift cards for resale, targeting sites like Amazon or Nike.
Cash Out
Converting a card’s balance (e.g., prepaid or gift card) into cash.
Catfishing
Creating fake online identities to lure victims into emotional or romantic relationships for financial or personal gain.
CC
Credit Card
Stolen credit card data, including cardholder name, address, expiration date, and CVV; becomes Fullz with additional personal data.
Chargeback Fraud
Friendly Fraud
When a legitimate cardholder disputes a valid transaction to receive a refund while keeping goods or services.
Checker
A tool testing if cards are valid and active before use.
Clean
An unused card or method with no fraud history, offering high success rates.
Click Fraud
Illegally clicking pay-per-click ads to boost revenue or exhaust budgets, often using bots or scripts.
Cloning
Copying card data onto blank cards to create physical duplicates, requiring dumps and MSR devices.
Computer Fraud
Using a computer to manipulate or illegally access electronic information, prohibited under laws like the Computer Fraud and Abuse Act.
Consumer Authentication
Devices or methods verifying a user’s identity for transactions, both online and in-person.
Conventional CC
Basic stolen credit card data (name, address, card number, etc.), less expensive but limited to weaker websites.
Cookies
Small browser files storing login sessions or preferences, stealable to bypass 2FA.
Corporate Fraud
Falsifying a company’s financial data to mislead the public or increase profits, often a white-collar crime.
Corporate Identity Theft
CIT
Falsifying a company’s identity, typically in a cyber setting, to commit fraud.
Counterfeiting
Duplicating authentic items (e.g., money, trademarks) to deceive recipients.
CPN
Credit Privacy Number
A nine-digit number falsely marketed to hide or repair bad credit, used instead of an SSN.
Crawler
Web Crawler
Automated software that browses the web to duplicate content, often used for data scraping.
Credential Harvesting
Collecting login credentials (usernames, passwords) through phishing, keylogging, or other malicious methods.
Credential Stuffing
Using stolen credentials to gain unauthorized access to accounts via large-scale automated login attempts.
Credit Card Fraud
Any fraudulent transaction using a credit card, including identity theft or chargeback fraud.
Crypto Flashing
Flash Transactions
A fake blockchain exploit claiming to multiply cryptocurrency, a common ripper scam.
Crypto Jacking
Unauthorized use of a victim’s computing resources to mine cryptocurrency via malware.
CVV
Card Verification Value
A 3- or 4-digit code on a card’s front or back, used to verify physical possession during transactions.
Dark Pool
Underground dark web marketplaces trading stolen data, tools, or services.
Data Breach
Illegal access or retrieval of data, often to steal or publish sensitive information.
Data Capture
Extracting information from documents and converting it into digital data for fraud.
Data Set
A collection of data, often stolen, used for fraud or analysis.
Dead CC
A credit card with invalid or retired details, unusable for transactions.
Dead
A card or method that no longer works due to invalid details or detection.
Debit Card Fraud
Unauthorized access to debit card accounts to drain funds, often easier due to accessible card information.
Decline
A failed transaction due to insufficient funds, fraud detection, or other issues.
Dedicated Hosting
Leasing an entire server for hosting phishing pages or malicious content.
Deep Fake
Technology overlaying audio or video to create authentic-looking but fake content, used for fraud or deception.
Device Cloning
Creating an exact copy of a device or application to mimic its behavior for fraudulent purposes.
Digital Wallets
Software for e-commerce transactions, often linked to bank accounts, vulnerable to fraud if credentials are stolen.
Dipping
Using a cloned card multiple times to force a terminal to read the magnetic stripe instead of the chip.
DNS Spoofing
Redirecting users to fake websites by exploiting DNS server flaws, often for phishing.
Domain Name
A network identifier (e.g., website URL) that can be spoofed for fraud.
Doxx
Publicly sharing someone’s private information without consent, often with malicious intent.
Drop Address
An address (e.g., abandoned house, P.O. box) used to receive fraudulently purchased goods, often disguised to appear legitimate.
Drop
A location where carded goods are sent, or an account registered with someone else’s information.
Dump
Raw magnetic stripe data (track1/track2) used to create cloned cards.
Dumpster Diving
Rummaging through garbage to find personal information (account numbers, PINs) for fraud.
Email Spam
Unsolicited emails sent to trick recipients into visiting malicious sites or sharing data.
Email Spoofing
Falsifying the “From” field in emails to hide the sender’s origin and trick recipients.
Employment Scam
Fake job listings designed to collect applicants’ personal information for fraud or blackmail.
EMT
Electronic Money Transfer
A bank transfer system that can be exploited to bypass recipient verification.
Emulator
A bot mimicking human activity to purchase limited-quantity items or exploit sales.
EMV
Chip card technology (Europay, Mastercard, Visa) that enhances in-person transaction security but increases card-not-present fraud risk.
Enroll
Cards with online banking access that can be registered to accounts, requiring SSN and specific BINs.
Escrow
A third-party service holding funds until a transaction is complete, protecting against scams but vulnerable to exit scams.
EV SSL
Extended Validation SSL
A certificate providing high trust for websites, often spoofed in fraud.
Exit Scam
When a marketplace or vendor disappears with users’ money, common in dark web markets.
Facial Recognition
Biometric technology identifying users by facial structure, used in security but vulnerable to deep fakes.
False Identity Fraud
Creating a fake identity to commit crimes like applying for credit, loans, or opening bank accounts.
False Vendors
Creating fake vendor accounts to send fraudulent invoices or duplicate payment systems.
FIDO
Fast Identity Online
Authentication standards using device security to reduce reliance on passwords.
Fingerprint
Unique browser settings (canvas, fonts, plugins) used to identify users, spoofed by antidetect software.
Fraud Rings
Managing thousands of fake accounts for large-scale fraud, like bust-outs or application fraud.
Fraud Score
A numerical value assessing the risk of a transaction based on patterns of suspicious behavior, used in banking, insurance, and e-commerce.
Fresh
New, unused cards or methods with no fraud history, ideal for success.
Full CC
CC Fullz
Expensive credit card data with comprehensive details (bank name, account/routing numbers, DL, PIN), usable on any platform.
Fullz
A complete set of personal information (name, address, SSN, driver’s license, bank details, etc.) used for identity theft or fraud.
Geolocation Detection
Identifying a user’s location via network or GPS data, often spoofed to bypass restrictions.
Showing the first 100 matches. Keep typing to narrow results.