Digital wallets are generally considered highly secure because they protect the user’s payment details with tokenization, an added layer of security that helps reduce the risk of fraud. But even with that added protection, digital wallet fraud is still possible. A bad actor might add stolen card information to their own mobile wallet, exploit tokenized card credentials, or take over a digital wallet account to access a victim’s stored payment methods. And fraudulent transactions can be tricky for businesses to spot since they look identical to legitimate purchases.
Below, we’ll explore digital wallet fraud, including the most common types. We’ll look at how tokenization helps secure digital wallet payments, why businesses can still be vulnerable despite the added security, and what kind of preventative solutions can help.
Key takeaways
Digital wallet fraud is a type of payment fraud where bad actors use tactics such as social engineering and phishing to gain access to accounts stored in a digital wallet.
Tokenization encrypts debit and credit card details, but it doesn’t confirm that the person using the digital wallet is the true account holder.
Businesses can still absorb the cost of digital wallet fraud through lost goods and disputes, even when the fraudulent actor gained access elsewhere.
Taking steps to prevent digital wallet fraud, including adopting fraud protection solutions and understanding how common types of digital wallet scams work, can reduce the likelihood of exposure.
What is digital wallet fraud?
Digital wallet fraud is a type of payment fraud. It occurs when someone uses a mobile wallet to make payments with credentials they don’t have permission to use. A fraudulent actor might steal card details—including the card number, card verification value (CVV) code, and expiration date—and add them to a new digital wallet, similar to card-not-present (CNP) fraud. Or they might take over an existing digital wallet account and the account owner’s stored payment methods (e.g., Apple Pay, Google Pay) to make fraudulent purchases.
Since transactions made by fraudulent actors pass through a legitimate security process, it might be hard for your business to notice an unauthorized digital wallet payment. By the time the payment reaches you, it usually comes with a valid token (i.e., a static, secure substitute card number), transaction cryptogram (i.e., a dynamic, one-time code to verify the payment), and passcode or biometric authentication.
However, despite some risk of fraud, payments made with digital wallets are generally considered more secure than credit card transactions.
What are the most common types of digital wallet fraud?
Here are the most common types of digital wallet fraud.
Phishing attacks
Phishing attacks happen when fraudulent actors use deceptive emails or messages that mimic legitimate institutions to trick account holders into sharing sensitive information. These attacks target credit card details, account numbers, personal information, and passwords.
Social engineering
Social engineering happens when bad actors use manipulative tactics that play on human emotions in order to trick victims into sharing sensitive login information. For example, a bad actor might call a person, posing as a representative from their financial institution, and claim that the person’s digital wallet has been hacked. They might create a false sense of urgency to provide passwords, verification codes, etc.
Subscriber Identity Module (SIM) swapping
SIM swapping is when a fraudulent actor obtains a SIM card and tricks a mobile carrier into moving the targeted person’s phone number to it. By intercepting calls and texts containing sensitive information (e.g., one-time passwords), the fraudulent actor can get control of the victim’s digital wallet.
Exploiting a Device Primary Account Number (DPAN)
If your business’s payment system is hacked, a fraudulent actor might be able to expose your customer’s DPAN (i.e., their device-specific token), but they won’t be able to access the real card number behind it. If the fraudulent actor also stole the associated device, however, they might be able to exploit the DPAN to make fraudulent payments from the customer’s digital wallet.
How does tokenization prevent digital wallet fraud?
During payment tokenization, digital wallets replace sensitive card numbers with randomly generated codes, or tokens. While tokens behave like real numbers, they’re worthless when stolen. After a customer makes a payment, your business stores only the token, while the actual card details are sent to a Token Service Provider (TSP)—usually your payment provider—and stored in a centralized database known as a “vault.”
For added security, each digital wallet transaction also uses a dynamic, unique code, or cryptogram. If a fraudulent actor captures the transaction data, it’s unusable since the cryptogram is a one-time-use code and will have already expired.
Many digital wallets also use biometric authentication such as facial or fingerprint recognition. This adds a layer of protection beyond a personal identification number (PIN) for the user and makes it hard for anyone but the account owner to authorize a payment.
Are there gaps in digital wallet security?
Digital wallets are generally considered less prone to fraud than card payments, but security gaps are still possible. For example, fraudulent actors might use social engineering during the provisioning process to obtain login credentials and set up accounts in new digital wallets. And customer devices can also be compromised if a fraudulent actor knows a device passcode or manages to add their own biometrics.
How are businesses exposed to digital wallet fraud?
Your business can be exposed to digital wallet fraud before checkout as soon as a fraudulent actor manages to bypass standard security measures in the provisioning layer. And if someone uses the stolen digital wallet to pay for a purchase, the transaction is often indistinguishable from legitimate digital wallet transactions. That can make it challenging for your business to notice suspicious payments. You might also need to manage dispute claims and chargebacks, which can result in lost revenue.
How Stripe Radar can help
Stripe Radar helps detect fraud and unlock growth, using AI trained on data from Stripe’s global network. Radar helps protect your business from fraud throughout the customer lifecycle before it affects your bottom line, while helping you approve more legitimate customers and payments.
Radar can help your business:
Prevent fraud losses: Radar’s AI learns from more than $1.9 trillion in annual transactions across Stripe’s global network, helping it identify and block fraud patterns that individual businesses might not catch on their own.
Unify protection across evolving fraud attacks: Radar brings protection against transaction fraud, account fraud, and customer abuse all into one solution, so you gain unified protection across major fraud types.
Adapt as fraud evolves: Radar continuously adapts to changing fraud patterns, from first-party abuse to agentic transactions, helping protect your business against emerging threats.
Work with your existing tech stack: Use Radar with Stripe payments with no integration required, or access Radar’s intelligence through programmable APIs, whether you process payments on Stripe or not.
Learn more about Stripe Radar, or get started today.
FAQs about digital wallet fraud
The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accurateness, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent attorney or accountant licensed to practice in your jurisdiction for advice on your particular situation.