Gift card fraud: draining, cloning and the controls that stop it

Gift card fraud does not look like a heist. It looks like a customer at the register with a stack of $500 cards, a rack of cards that were quietly opened and resealed weeks ago, an e-gift order placed at 3 a.m. from a brand-new account, and a refund that lands on store credit instead of the stolen credit card that paid for the original purchase. Each is a repeatable pattern with a cheap control once understood, and this guide walks through the attacks a retailer actually sees, in the order they hit the business, and lays out the practical gift card fraud prevention controls that shut each one down.

In short

  • Card draining is the dominant physical attack: a fraudster records card data from unactivated cards on the rack, reseals them, then waits for a shopper to load value and empties the balance within minutes of activation.
  • Tampered packaging is the tell that staff can catch: resealed sleeves, exposed PIN panels, mismatched barcode stickers and cards that look “handled” are the physical evidence of a compromised rack.
  • Activation controls at the POS (barcode-to-card matching, per-transaction caps, velocity limits and balance-check throttling) break the attack at the point where money actually enters the card.
  • Online e-gift fraud uses stolen credit card numbers to buy digital cards that are resold in hours; account age, device signals and delayed delivery are the screens that work.
  • Refund-to-gift-card abuse is the loophole most retailers leave open: a purchase on a stolen card becomes a clean store credit that can be sold, so refund tender rules and return velocity tracking matter as much as any rack lock.

Gift cards sit at an unusual intersection of retail. They are a payment instrument, a marketing product and a liability on the balance sheet all at once, which is why the broader mechanics are covered in our guide to how gift cards and stored value programs really work. Fraud is the part of that system that scales fastest, because a gift card is effectively unregistered cash that can be checked, redeemed and resold from anywhere with an internet connection. The US Federal Trade Commission has for several years listed gift cards among the most frequently reported payment methods in scam complaints in its Consumer Sentinel data; current figures should be verified on the FTC’s gift card scam page, since the numbers move every year.

One framing note before the detail. Most of what follows is about attacks against the retailer’s own stored-value program: the cards on the rack, the activation flow, the e-gift storefront and the refund desk. The separate problem of scammers coercing victims into buying gift cards to move stolen money touches the retailer only at the register, where a value-threshold prompt and a friendly cashier question (“Is someone on the phone telling you to buy these?”) are the realistic controls.

How does card draining work from rack to checkout?

Card draining is the attack that most retail loss prevention teams now rank first among gift card losses, and it works because unactivated cards on an open rack carry zero value and therefore attract almost no security. A fraudster takes a handful of cards off the rack, often dozens at a time, and leaves the store without paying for anything. Nothing has been stolen yet in any meaningful sense, since the cards are inert plastic until a cashier activates them.

Away from the store, the fraudster opens each package, records the card number and scratches off the PIN panel, then reseals the package well enough to survive a glance. Some operations replace the scratch-off panel with a new one bought in bulk; others simply reglue the sleeve. The cards go back onto the rack on the next visit, mixed in with untouched stock. From that point the fraudster owns the credentials of a card that a real customer will eventually load with money.

The activation trigger

The attacker’s remaining task is to know when a specific card has been activated. Retailers expose a balance check endpoint, on a website, in an app or through an IVR phone line, and the fraudster polls it in a loop using scripts that check hundreds of card numbers many times a day. The moment a balance appears, the number and PIN are used online, redeemed for high-resale merchandise, converted into another gift card, or sold on a secondary market. In documented cases the drain happens within minutes of the register beep.

The shopper discovers the loss only when the recipient tries to use the card, sometimes weeks later, by which point the redemption has cleared and the retailer holds both an unhappy customer and a liability it has already honored once. This is the whole reason activation-time and balance-check controls carry so much weight: the physical rack cannot be fully secured, so the process has to be.

Cloning and the barcode swap

A second variant, sometimes called cloning or card swapping, targets the barcode rather than the PIN. The fraudster peels the barcode sticker off a card they already hold and applies it over the barcode on a rack card. When a customer buys the tampered card, the cashier scans the fraudster’s barcode, and the activation loads value onto the card in the fraudster’s pocket, not the one the customer walks out with. The customer’s card was never activated at all.

This variant is nastier because no balance check is required and no resealing of the PIN panel is needed. It is also the one most readily defeated by a POS-side control, since the register can compare the scanned barcode against the card number encoded in the magnetic stripe or the printed serial before it allows activation. Where that check exists, a swapped barcode fails at the register and the transaction stops before money moves.

What should staff look for on tampered packaging?

The physical rack is the first line of defense, and it costs nothing beyond training time. Staff who stock and face the gift card display are the people most likely to notice that something is off, provided they know what “off” looks like. The signals below are consistent across the tamper cases that retailers and card issuers have described publicly, and they hold regardless of the specific brand on the rack.

Signs of resealing

A resealed sleeve tends to show a glue line that is thicker or glossier than the factory seal, a slight misalignment between the front and back panels, or a card that sits loosely inside packaging that was originally tight. Cards that have been handled repeatedly pick up fingerprints and creases that factory-fresh cards do not have.

PIN panel and barcode checks

An exposed or partially scratched PIN panel is the clearest tell, and any card where the silver scratch-off looks replaced, sits unevenly or shows a slightly different shade should come off the rack. Barcode stickers that overlap the printed edge, lift at the corners or show a second layer underneath are the signature of a barcode swap. A useful habit for stocking staff is to tilt the card under the store lights; a stuck-on barcode catches the light differently from one printed into the card.

Rack behavior that indicates a return visit

Tampered cards do not appear on their own. Someone had to bring them back, and the behavior that goes with that is fairly consistent: a customer who lingers at the gift card rack without buying, who appears to sort cards rather than pick one, or who was previously seen leaving with cards without checking out. Correlating those observations with rack CCTV is what gives a regional loss prevention team something to escalate.

Retailers who already run a shrink program will recognize this as an extension of the same discipline, and the broader operational context is covered in our piece on theft, shrink and loss prevention without scaring shoppers. The distinction is that gift card tampering leaves no gap on the shelf and no inventory variance, so it never surfaces in a stock count. It has to be caught by eye or by process.

Attack pattern Where it happens What the retailer sees Control that stops it
Card draining (PIN capture) Rack, then balance check endpoint Customer complaint weeks later; balance used online minutes after activation Balance-check throttling and bot detection; tamper-evident packaging; behind-counter high denominations
Barcode swap / cloning Rack, then register Customer card shows zero balance; value went to a different card Barcode-to-serial match at activation; scan both codes before loading
Bulk activation on stolen cards Register Many high-value cards on one tender; later chargeback Per-transaction caps; velocity limits per tender and per cashier
E-gift purchase with stolen card Online storefront Chargeback 30–90 days later; card already redeemed Account age, device and AVS screening; delayed delivery for new accounts
Refund-to-gift-card laundering Returns desk Return of fraudulently bought goods; store credit resold Refund to original tender; hold on store credit issued against disputed purchases
Coerced purchase (scam victim) Register Distressed customer buying many cards while on the phone Cashier prompts and purchase caps; signage at the rack and register

Which activation controls and velocity limits belong at the POS?

Everything on the rack can be tampered with given enough patience, so the durable controls live in the activation flow. Activation is the single moment where a card goes from worthless to valuable, and it happens on a system the retailer fully controls. A modern register can enforce several checks in the fraction of a second before it sends the load request to the stored-value processor, and most of them are configuration rather than development work.

Barcode-to-serial matching

The most effective single control against cloning is requiring the register to read two identifiers from the card and refusing activation if they disagree. Depending on the card stock, the second identifier may be the magnetic stripe, an embedded chip, a printed serial or a second barcode under the packaging. When the scanned barcode belongs to a different card than the one physically present, the activation is declined and the cashier gets a message to pull the card from sale. Retailers evaluating a platform upgrade will find this feature on the checklist in our overview of what to look for in a modern POS system in 2026.

Per-transaction and per-tender caps

Caps limit the damage from any single event. A common configuration is a maximum load per card, a maximum number of gift cards per transaction and a maximum total gift card value per tender type, with credit card tenders set lower than cash. Many retailers also cap the number of gift card activations a single cashier can process in an hour, which surfaces both external fraud and internal collusion.

Velocity limits and activation delays

Velocity rules count events over time rather than per transaction: activations per card range, per store, per tender, per hour. A burst of activations on consecutive card numbers, or a series of high-value loads across several stores in one afternoon, is the pattern of a bulk fraud run. Some programs add a short activation delay, meaning the card is loaded but cannot be redeemed online for a set number of minutes or hours. That window costs the honest gift buyer nothing and gives the balance-check throttle time to work.

Balance-check throttling

The balance check endpoint deserves specific attention because it is the fraudster’s trigger for card draining. Rate limiting by IP, requiring a CAPTCHA after a small number of checks, requiring the PIN for a balance check, and alerting on card numbers that are checked repeatedly while still at zero balance all raise the cost of the attack. A card that has been polled fifty times before activation is a card that has been tampered with, and the system can flag it for hold before the shopper even reaches the register.

Smaller merchants running hosted platforms do not need to build any of this. The gift card modules in the major SMB systems already expose activation and balance-check settings, and the comparison in our piece on Square versus Shopify POS versus Clover for SMB retail notes which features each one surfaces. The gap is usually that the defaults are permissive and nobody has looked at them since the program launched.

Self-checkout as an activation surface

Self-checkout deserves a specific policy. Some retailers block gift card activation entirely at unattended lanes and route those transactions to a staffed register, precisely because there is no cashier to notice the coerced buyer or the stack of $500 cards. Others allow it with tighter caps. The tradeoff between friction and control is the same one that runs through the wider debate on when self-checkout pays and when it kills morale; for gift cards, most operators land on the side of routing the transaction to a person.

How are stolen card numbers used online, and how do you screen them?

The e-gift channel removes the rack entirely, and with it every physical control. A fraudster with a stolen credit card number does not need to visit a store, tamper with packaging or wait for a shopper. They buy a digital gift card, receive the code by email within minutes, and redeem or resell it before the cardholder notices the charge. When the chargeback arrives 30 to 90 days later, the retailer loses the merchandise, the card value and the chargeback fee.

This is the fraud pattern most similar to standard card-not-present fraud, and the tools overlap with the ones covered in our broader guide to payment fraud and chargeback prevention for online retailers. The difference is liquidity: a stolen sweater has to be resold, while a stolen $200 gift card code already is money. That shifts the risk model toward speed and account signals rather than shipping-address checks.

Account age and order history

The strongest single signal is how new the buyer is. A first order from an account created minutes earlier, buying only digital gift cards, at the maximum allowed denomination, is the profile of nearly every e-gift fraud case a retailer will see. Legitimate e-gift buyers tend to be existing customers sending one card to a named recipient. Rules that cap first-order e-gift value and require an account to be more than a day old for high denominations remove a large share of the loss with almost no effect on real customers.

Device, email and address signals

Device fingerprinting catches the same device cycling through many accounts. Email address patterns, such as a recipient address that matches the sender, a disposable email domain or a string of near-identical addresses, are cheap to check. AVS and CVV checks still matter for a product that is never shipped, because a mismatch on a digital purchase has no plausible “sending to my office” explanation.

Delayed delivery and manual review queues

A delivery delay of a few hours for orders that trip a risk score gives the retailer time to run a review or to let the issuer’s fraud system flag the card. Publishing a delivery time of “within 24 hours” costs almost nothing in conversion and buys a review window.

Redemption-side screening

Screening can also happen when a gift card is spent rather than when it is bought. A card redeemed within minutes of purchase, from a different country than the buyer, on a high-resale item shipped to a freight forwarder, is a card that was bought on a stolen number. Linking purchase and redemption records, which many processors support, lets the retailer hold one suspicious redemption without freezing the program.

What is refund-to-gift-card abuse, and which loophole does it exploit?

The returns desk is where gift card fraud hides in plain sight, because the loss shows up in a different ledger from the one loss prevention watches. The basic scheme is laundering: a fraudster buys merchandise with a stolen credit card, returns it for a gift card or store credit, and sells that card on the secondary market for cash. The retailer refunds the value twice, once as the chargeback on the original stolen-card purchase and once as the gift card it honors when the buyer of that card redeems it.

The loophole is any policy that lets a refund land on a tender other than the one used for the original purchase. Refund-to-gift-card is often offered as a convenience, especially for receiptless returns, gift returns or returns after the original card has expired. Each case is legitimate on its own and each is also the fraudster’s route. The mechanics of the broader problem are set out in our article on return fraud and how retailers actually fight it; what follows is the gift card specific slice.

The receiptless return

Receiptless returns are the most exposed case, because there is no purchase record to refund against, so the retailer defaults to store credit. Shoplifted merchandise and merchandise bought on a stolen card both arrive at the desk this way. The standard controls are a cap on the number and value of receiptless returns per customer over a rolling period, identity capture at the desk within applicable privacy law, and a return authorization system that scores the return before the associate issues credit.

Holding credit against disputed tenders

Where the original purchase can be identified, the more precise control is to link the store credit to the original tender and place a hold on it if that tender is later charged back. If the chargeback arrives before the store credit is spent, the credit is voided. Some processors support this natively; others require the retailer to run a nightly match between chargeback files and open store credits.

Refund to original tender as the default

The simplest policy is also the most effective: refunds go back to the tender that paid, and store credit is the exception rather than the default. This does not eliminate the receiptless case, but it removes the incentive to return legitimately purchased goods for a more liquid instrument. Several US states have rules about cash-back on small gift card balances and about the expiry of stored value, so any policy change here should be checked against current state law and the federal Credit CARD Act provisions administered by the Consumer Financial Protection Bureau; this article is general information and not legal advice, and a retailer changing refund policy should confirm the specifics with counsel.

What should a retailer tell a customer whose card was drained?

The conversation with a drained-card victim is the part of gift card fraud prevention that most directly shapes brand trust, and it is often the part with the least preparation. The customer bought a card in good faith, gave it to someone, and that person was told at the register that the balance is zero. From their perspective the retailer sold them nothing. How the associate handles the next five minutes determines whether the customer becomes a complaint on social media or a returning shopper.

What to establish first

The associate should ask for the physical card and any receipt, then pull the card’s transaction history from the stored-value system. The history shows the activation time and location and every redemption since, and it usually makes the pattern obvious: activated at 2:14 p.m. on a Saturday, drained online at 2:31 p.m. in a different state. That record is what the retailer’s fraud team needs and what the customer needs to feel that the problem is being taken seriously rather than doubted.

What the retailer can offer

Policies vary and are a business decision rather than a legal obligation in most cases. Many large retailers will reissue a card when the transaction history clearly shows draining shortly after activation and the customer has the receipt, on the reasoning that the loss was caused by tampering on their rack. Whatever the policy, the associate should be able to state it clearly and escalate to a named team rather than telling the customer that nothing can be done.

Where to point the customer

Customers who have lost money to a gift card scam or tampered card can report it to the FTC through its fraud reporting portal, and the FTC’s consumer guidance also lists the contact points for major card brands. If the loss came from a phone scam rather than a tampered rack, the reporting path is the same but the retailer’s exposure is very different, and the associate should not promise a refund.

What does a control checklist look like for a small retail chain?

A ten-store chain does not need an enterprise loss prevention department to close most of these gaps. The controls below are grouped by cost and effort, and most of them are configuration changes or training rather than capital spend. The pattern in practice is that the cheap tier removes the majority of the loss, the middle tier catches the persistent attackers, and the top tier is worth it only when gift card volume justifies it.

Control Attack it addresses Typical cost Effort to deploy Priority for a small chain
Staff training on tamper signs and coerced buyers Draining, cloning, scam purchases Near zero Low: one training module plus a rack-check routine Do first
Behind-counter storage for high denominations Draining, cloning Near zero Low: fixture change Do first
Per-transaction caps and refund-to-original-tender policy Bulk activation, refund laundering Near zero Low: POS settings and policy update Do first
Barcode-to-serial match at activation Cloning / barcode swap Low to moderate Medium: depends on card stock and POS support Second wave
Balance-check throttling and CAPTCHA Draining Low Medium: web and IVR configuration Second wave
E-gift rules on account age, device and delivery delay Online stolen-card purchases Low Medium: risk rules on the storefront Second wave
Return authorization scoring and receiptless caps Refund laundering Moderate Medium: vendor integration When return volume justifies it
Chargeback-to-store-credit matching Refund laundering Moderate High: nightly data match or processor feature When chargeback volume justifies it
Tamper-evident card packaging redesign Draining, cloning Moderate to high High: supplier change When private-label card volume is large

Sequencing the rollout

The first-wave items can be live within a month and require no budget approval beyond training time. A rack-check routine at each shift change, high denominations behind the counter, a per-transaction cap and a refund policy change together remove the easiest wins for a fraudster and make the chain a less attractive target than the competitor down the road.

The second wave is where POS and web configuration comes in, and the sequencing usually follows the loss data. If drained-card complaints dominate, balance-check throttling and behind-counter storage come first. If chargebacks on e-gift orders dominate, the storefront rules come first. The stored-value processor’s reporting will show which pattern is costing more, and the wider payments landscape in our guide to how retail payments are changing across cards, BNPL and crypto gives the context for why e-gift volume, and with it e-gift fraud, keeps growing.

Measuring whether it worked

Three numbers tell the story: drained-card complaints per thousand cards activated, e-gift chargebacks as a share of e-gift revenue, and store credit issued against purchases later charged back. Each should fall within a quarter of the relevant control going live.

Gift card fraud is not going away, because the product is designed to be liquid and anonymous and that is exactly what makes it useful to both customers and criminals. What changes is the ratio of effort to reward for the attacker. A retailer that understands the handful of patterns above, and that has read through how the whole stored-value program fits together in our gift cards and stored value guide, can shift that ratio decisively with controls that cost far less than the losses they prevent. The general background on the instrument itself is well summarized on Wikipedia’s gift card entry.

FAQ on gift card fraud

What is gift card draining?

Draining is the theft of a gift card’s balance by someone who captured the card number and PIN before the card was sold. The fraudster tampers with unactivated cards on the rack, records the credentials, reseals the packaging and returns the cards to the shelf. When a shopper buys and activates one, the fraudster’s balance-check script detects the value and spends it online, often within minutes.

How can a shopper tell if a gift card has been tampered with?

Look for a PIN panel that is exposed, scratched or looks replaced, a barcode sticker that lifts at the edges or sits on top of a printed code, and packaging that has been reglued or does not sit tightly. Cards from the back of the rack or from behind the counter are less likely to have been handled. If anything looks off, ask the cashier for a different card.

Is a retailer obliged to refund a drained gift card?

In most US cases it is a matter of retailer policy rather than a legal obligation, and policies vary widely. Many large retailers will reissue a card when their own records show it was drained shortly after activation and the customer has the receipt. Rules on stored value differ by state and are subject to the federal Credit CARD Act; this is general information rather than legal advice, and a consumer or retailer with a specific dispute should check the current rules with the relevant regulator or a qualified professional.

What is the single most effective gift card fraud prevention control for a store?

For physical cards, matching the scanned barcode against a second identifier on the card at activation stops barcode swaps outright, and throttling the balance-check endpoint removes the trigger that draining depends on. For a store with limited technical resources, moving high-denomination cards behind the counter and training staff to spot tampering delivers most of the benefit at almost no cost.

Why are e-gift cards a fraud target?

A digital gift card bought with a stolen credit card number is delivered instantly and is effectively cash. The fraudster redeems or resells the code long before the cardholder disputes the charge, and the retailer absorbs both the chargeback and the value already spent. Account age, device fingerprinting and a short delivery delay on risky orders are the controls that work.

What is refund-to-gift-card abuse?

It is the laundering of stolen-card purchases or shoplifted goods into clean store credit. Merchandise is returned for a gift card, which is then sold for cash. The control is to refund to the original tender by default, cap receiptless returns, and place a hold on store credit that was issued against a purchase later charged back.

Where should a victim report gift card fraud?

In the United States, consumers can report gift card scams and tampered cards to the Federal Trade Commission through its online fraud reporting portal, and should also contact the card issuer or retailer immediately, since some balances can be frozen if the report is fast enough. The FTC’s consumer site lists the contact points for the major card brands.

Does gift card fraud show up in shrink numbers?

Usually not, which is why it is under-counted. Tampered cards leave no gap on the shelf, drained balances show up as customer complaints or reissued cards, and refund laundering shows up as chargebacks and store credit. A retailer that wants to measure the real cost has to pull those three streams together rather than relying on the inventory count.