Network Tokens and Passkeys: The Pincer Movement on Card-Not-Present Fraud
Card-not-present fraud thrives on two stolen things: card numbers and passwords. Network tokenization makes the first far less useful. Passkeys eliminate the second. Together they change the game.
31 Mar 2025
Date PCI DSS v4.0's future-dated requirements became mandatory
1
Unique cryptogram generated for each network-token transaction
0
Shared secrets transmitted to the server during a passkey sign-in
When chip cards spread through physical retail, counterfeit fraud at the point of sale fell sharply, and fraudsters did what fraudsters do: they moved. Card-not-present fraud, on websites, in apps and over the phone, became the dominant form of card fraud in many markets. The reason is structural. Online, a card number, expiry date and security code are often enough to pay, and all three can be stolen, bought or phished.
Two technologies are now attacking the problem from opposite sides. Network tokenization reduces the value of stolen card data. Passkeys reduce the value of stolen credentials. Neither is new, but their adoption has reached the point where they are reshaping fraud economics.
Side one: network tokenization
A network token is a substitute for the card number, issued by the card scheme's token service. It is bound to a domain, such as a specific merchant, device or wallet, and each transaction carries a one-time cryptogram. A token stolen from one merchant's database cannot be used at another merchant, and without the cryptogram it cannot be replayed.
Tokens have a second benefit that often matters more to merchants: lifecycle management. When a card is reissued because it expired or was reported lost, the issuer updates the token behind the scenes. Stored credentials keep working, which reduces false declines on subscriptions and saved cards.
- For issuers, a token in its proper domain with a valid cryptogram is a strong signal of legitimacy, which can support higher approval rates.
- For merchants, tokens can reduce the impact of a data breach and, depending on architecture, the scope of their PCI DSS obligations.
- For fraudsters, a database of tokens is far less valuable than a database of card numbers.
Tokenization is not universal. Coverage depends on issuer participation, and many transactions still fall back to the card number. But the direction is clear, and networks have publicly signaled goals of tokenizing much more of e-commerce over the coming years.
Side two: passkeys
Card numbers are not the only thing fraudsters steal. Account takeover, logging into a customer's existing account with stolen or guessed credentials, lets a fraudster use saved payment methods, change delivery addresses or drain stored value. Passwords and SMS one-time codes are both vulnerable to phishing, and SMS codes are further exposed to SIM-swap attacks.
Passkeys, built on the FIDO2 and WebAuthn standards, replace shared secrets with public-key cryptography. The user's device holds a private key and signs a challenge from the website; the site stores only the public key. The signature is bound to the site's domain, so a phishing site on a lookalike domain cannot obtain a valid one. There is no password to stuff and no code to intercept.
A passkey cannot be typed into the wrong website. That single property removes the most successful attack in online fraud.
Passkeys have moved from niche to mainstream as major operating systems and browsers support them and synchronize them across a user's devices. Banks and merchants report faster sign-in and lower support costs as well as reduced account takeover.
Where the two meet: authentication at payment
The real opportunity lies where tokenization and passkeys combine. Under strong customer authentication in Europe, many online card payments need two-factor authentication. EMV 3-D Secure has made much of that frictionless through risk-based assessment, but challenges still often rely on one-time codes.
Passkeys offer a phishing-resistant alternative. Schemes and issuers have been developing ways for a passkey assertion, performed on the merchant's page or within a wallet, to count as authentication for a card payment, and for that authentication result to travel with a tokenized transaction. Done well, a returning customer could buy with a single biometric gesture that satisfies the issuer, the merchant and the regulator at once.
The compliance backdrop
PCI DSS v4.0 raised the bar for anyone who handles card data. Among the requirements that became mandatory on 31 March 2025 were stronger controls over payment-page scripts, intended to counter the injection of skimming code into checkout pages, and broader multi-factor authentication for access to cardholder data environments. Tokenization and hosted payment fields reduce how much of an environment falls within scope, which makes these requirements easier to meet.
What to do
- Merchants: request network tokens for stored credentials, measure approval rates by token versus card number, and offer passkeys to returning customers.
- Issuers: expand token participation, and treat valid in-domain token cryptograms as a positive risk signal.
- Everyone: plan account recovery for passkeys carefully. The recovery path is now the weakest link, and fraudsters will target it.
Card-not-present fraud will not vanish; fraudsters will shift again, most likely toward social engineering that persuades genuine customers to act. But a world in which stolen card numbers and stolen passwords are both close to worthless is a meaningfully safer one.
Found this useful? Pass it on.
Companies working on this
Cobalt Canopy
Compliance-as-a-service for sponsor banks and their fintech partners.
Ferrous Pay
Full-stack acquiring with network tokens and 3DS2 on by default.
Lodestar Signals
Real-time scam and mule detection for instant payments.
Read next
From Open Banking to Open Finance: PSD3, the PSR, FDX and the Section 1033 Saga