How to shop online safely and avoid card fraud

Most online shopping fraud does not happen because someone “hacks” a bank, but because the buyer misses specific details: a URL that is not the official one, a store that asks for card details by email, a payment method without strong authentication or a card that directly exposes the current account.

Changing a few habits and choosing the right card to pay with reduces the risk to a minimum.

The most common types of online shopping fraud

Before learning how to avoid them, it is worth knowing what they are. Online shopping fraud is usually concentrated in four scenarios.

The first is phishing: you receive an email or SMS that imitates a store or your bank, takes you to a fake website that looks identical to the real one, and you enter your card or login details there. The second is fraudulent stores and fake profiles on buying and selling platforms, with offers far below market price that take payment and never send the product. The third is duplicate or unrecognised charges, which appear when your card details have been leaked in a security breach at another merchant. And the fourth is card cloning, when someone copies your card details to make payments elsewhere, usually starting with small charges to avoid being noticed. In this guide on how to avoid scams and fraud, you will find specific examples of each scenario and what to do step by step.

In all these cases, protection does not depend only on the bank. It depends on how you shop, where you shop and which card you use.

How to check whether an online store is trustworthy

Before entering your card details on a website, check a few quick points.

The URL should start with https and show the browser padlock. Without that minimum, do not continue. Also check that the domain is the brand’s official one, because phishing sites use subtle variations with changed letters, extra hyphens or different extensions (.shop instead of .com).

Check whether the website has a legal notice, returns policy, purchase terms and real contact details (physical address and phone number or email, not just a form). Look for reviews outside the website itself, on Google, Trustpilot or forums. If a store leaves no trace anywhere and has only been active for a week, that is suspicious.

Be wary of prices far below market value. An iPhone at 60% off is usually not a real promotion, but a scam designed to collect data. If the store fails any of these checks, close the tab.

Which payment method reduces risk the most

When you pay with a debit card, any fraudulent charge comes directly out of your current account and does not return until the bank resolves the claim. The law protects you, but in the meantime you may be left without liquidity. With a credit card, the charge is first assumed by the bank, so your account is not affected during the investigation and many cards include purchase protection for products that never arrive or arrive damaged.

Prepaid cards reduce exposure even further: they are not linked to any bank account, so if a merchant leaks your details or someone clones the card, the maximum loss is the balance you had loaded at that moment. Nobody can take more because there is no account behind it. Many prepaid cards also allow you to issue virtual cards for online shopping that you can use for a single purchase and block afterwards, making them especially useful for paying in online stores you do not know. With Bitsa, the virtual card is issued instantly from the app after completing identity verification, and you can block or hide it whenever you want.

Good practices when paying online

Beyond the card itself, there are behaviours that significantly reduce the margin for error.

Never send your card details by email, WhatsApp or social media. No legitimate merchant will ask you for them that way. Only enter them within the store’s own checkout process.

Do not save your card details on merchant websites or in your browser. If that store suffers a data breach, your details will be part of the leaked package. It is worth entering them manually each time.

Activate instant notifications for every movement. Most card providers, Bitsa included, notify you immediately of each transaction. If you receive a notification for a payment you do not recognise, you can act in seconds, not days.

Use strong authentication whenever possible. For online purchases within the European Union, PSD2 regulation requires most payments to be confirmed with two-factor authentication, whether by SMS, biometrics or banking app. If a merchant allows you to make a large purchase without any confirmation, that is a signal worth checking.

And if you receive an email or SMS with a link saying “verify your card” or “resolve a problem with your account”, do not click it. Go directly through the official app or website by typing the URL manually. The most active phishing and online fraud campaigns in Europe are covered in Europol’s prevention guides.

What to do if you detect an unauthorised charge

If a charge does not add up, act in this order.

  1. Block the card from the app as soon as you see it. Almost all providers allow you to freeze the card instantly without fully cancelling it, so you can reactivate it if it turns out to be a legitimate charge you did not recognise at first glance.
  2. Contact the issuer and dispute the charge. You have the right to request a refund for unauthorised transactions, and under the regulations the entity must refund the amount unless it proves gross negligence on your part.
  3. Report it if you suspect organised fraud. If you detect phishing, a fraudulent store or card cloning, file a report with the police and keep all evidence: screenshots, emails and the charge reference. Without a report, the bank may reject the claim in some cases.

Shopping online safely does not depend on a single tool or one specific trick. It depends on checking the store before paying, choosing a method that limits your exposure and acting quickly when something does not add up. With those three fronts covered, the risk of nasty surprises is reduced to a minimum.

FAQs

Does the browser padlock guarantee that the store is safe?
Not entirely. The padlock (https) only means that the connection between your browser and that website is encrypted, but it does not prove that the store is legitimate. A phishing site can also have https. The padlock is a necessary minimum, not proof of trustworthiness.

Is it safer to pay with PayPal, Bizum or a virtual card?
Intermediaries such as PayPal add a layer of protection: the merchant does not receive your card details, only the payment. A disposable virtual card works in a similar way, since you use different card numbers for each purchase and deactivate them afterwards. Bizum only works between Spanish accounts, so it is not suitable for international purchases. The decision depends on where you are buying, but all three reduce exposure compared with entering the details of your main card directly.

Can I shop online from a public WiFi network?
It is better not to. Open WiFi networks in airports, cafés or hotels are vulnerable to someone intercepting what you send. If you need to buy something away from home, use mobile data or a VPN. If you cannot wait, double-check that the URL is the official one and do not leave sessions open afterwards.

What happens if I buy from a foreign store and the product never arrives?
First, contact the merchant. If they do not respond, contact your card issuer to request a chargeback, a process through which the entity reverses the payment if the product was not delivered or does not match what you bought. The deadline is usually between 60 and 120 days from the charge, depending on the issuer. If your purchase was made on a peer-to-peer or second-hand marketplace, this article on buying in second-hand stores with a wallet card explains how to limit the risk before paying.

Can a virtual prepaid card be used for subscriptions?
Yes, and it is one of its best uses. You load the card with the exact amount of the subscription and, if the merchant tries to charge more or renew without warning, the payment is declined due to insufficient balance. It is also useful for trial periods: when the trial ends, if the balance is not enough, you avoid the automatic charge.