How can I protect myself against credit card theft?

Most card fraud does not involve someone pocketing your physical card. It happens when your card number is captured - on a compromised device, at a tampered terminal, through a convincing scam, or in a breach at a company you bought from. The reassuring part: a handful of everyday habits make a stolen number far less useful, and acting fast when something looks wrong usually means you lose nothing.

How card details get stolen

Knowing the common routes is what makes the protections below make sense.

On your computer or phone

  • Malware and infostealers. Programs like RedLine, Raccoon, and Lumma quietly harvest saved passwords, browser autofill, and stored card numbers. They usually arrive through pirated software, dodgy email attachments, or fake "update" downloads.
  • Cards saved in the browser. Numbers stored in Chrome, Edge, or Safari are a prime target on any shared or compromised machine.
  • Phishing and fake checkout pages. A spoofed shop or bank page captures the number the moment you type it.
  • Skimming scripts on real sites (formjacking). Malicious code injected into a legitimate shop skims your card at the genuine checkout, with nothing visibly wrong.
  • Session theft. Malware can lift a logged-in session to a shop or bank, skipping the password entirely.
  • Unsecured Wi-Fi. Less common now that most sites use HTTPS, but still a risk on poorly configured sites and public captive-portal networks.

Away from your device

  • Skimmers and shimmers fitted to ATMs, fuel pumps, and shop terminals.
  • Merchant data breaches - often the single biggest source of stolen cards, and completely outside your control.
  • Physical theft of the card, or a photo of its front and back.
  • Scam calls and texts impersonating your bank to coax out the number, expiry, and security code.

What you can do

Secure your devices

  • Keep your operating system, browser, and security software up to date, and run reputable protection.
  • Do not save card numbers in your browser. Remove any already stored, and use your bank's own app or a dedicated password manager instead.
  • Only install software from official sources - never pirated apps.
  • Use a standard (non-admin) account for everyday work, and keep the disk encrypted (FileVault on Mac, BitLocker on Windows) in case the device is lost or stolen.

Pay in ways that limit exposure

  • Use virtual or single-use card numbers where your bank or card offers them. A number that leaks is then worthless.
  • Prefer mobile wallets like Apple Pay or Google Pay. They swap in a tokenised code for your real number, so the merchant never sees it.
  • Check for HTTPS, and type website addresses yourself rather than following links in email.
  • Use credit rather than debit online where you can - the fraud protection is stronger, and the money is not drawn straight from your account.

Watch for trouble

  • Turn on real-time transaction alerts from your bank, so every payment pings your phone.
  • Enable two-factor authentication on banking and shopping accounts, and never read a one-time code to someone who calls you.
  • Review your statements regularly, and freeze the card instantly (most apps allow this) at the first sign of anything odd - even a tiny "test" charge.
  • Treat any unexpected call, text, or email asking for card details as suspicious. Your bank will never ask for your full number or security code this way.

Where should I keep my card details?

A dedicated password manager (such as 1Password or Bitwarden) is generally safer than your browser. Cards sit in a vault that locks automatically and only fills on the exact site you saved, so a look-alike checkout page will not trigger it. Modern browsers have improved - Safari protects cards behind Face ID or Touch ID - so the browser is not automatically weak, but a locked vault is a harder target for the infostealers written specifically to grab browser autofill. Either way, a saved number is still a number that can be stolen.

If you only do one thing

Combine a virtual or single-use card number with a tokenised mobile wallet. Together they make your card data worthless even if your device, or a shop you bought from, is compromised - which is why they beat every method that simply stores the real number more carefully.

Related: How can I tell if a message is a scam?

← All guides

General information, correct when last reviewed. Platforms and threats change - always confirm critical steps on the official source. Product names are used only to describe their features; Monkleton Labs is not affiliated with, or endorsed by, them. No ads, no affiliate links.