My credit card was used fraudulently. What should I do next, and do I really need a replacement card if I already got a refund?

A push notification lands after midnight, and it’s not a wrong-number text or a login alert. It’s your bank, telling you about a charge you didn’t make. Maybe it’s small, a gift card or a subscription, something you’d never actually buy. You didn’t lose your wallet. You haven’t handed your card to a stranger. Now you’re lying awake trying to figure out how someone got a 16-digit number you’ve never told anyone.
If you’ve never dealt with card fraud before, your first instinct is usually to figure out who did this. That’s a natural reaction, but it’s the wrong place to spend your energy first. Most people spend more time trying to solve the mystery than actually protecting the card, when the reverse should be true.
So, In SHORT
Yes, in almost every case, you should still get your card replaced, even after the merchant refunds you. A refund closes out one transaction. It doesn’t change the fact that your card number is sitting somewhere it shouldn’t be, and it doesn’t stop whoever has it from trying again next week. Locking your card buys you time, but it isn’t a substitute for a new number. And no, you almost certainly won’t find out who did it. That’s not a failure on your part or your bank’s. It’s just how this type of fraud works, and we’ll explain why below.
Why This Happens More Often Than Most People Realize
If it feels like unauthorized charges have gotten more common, that’s not just a feeling. A 2026 survey from Security.org found that 61% of U.S. credit cardholders have experienced fraud on their account at some point, and 51% have been hit more than once. Over the past year, roughly 61.3 million Americans had a fraudulent charge hit their account, adding up to about $6.1 billion in unauthorized purchases. FTC complaint data tells a similar story: credit card fraud reports through the first three quarters of 2025 were already running about 180,000 higher than the same stretch a year earlier.
The statistic that matters most for your situation is this: in that same Security.org survey, only 5% of fraud cases involved a physically stolen card. The other 95% happened without a thief ever touching your plastic, through a breach at some company you bought something from, a skimmer, a phishing page, or your number simply getting resold after showing up in a data leak you never heard about. So “how did this even happen if I still have my card?” is exactly the right question to ask. You just usually won’t get a satisfying answer to it. That’s one reason banks focus their energy on stopping future fraud rather than tracing a single unauthorized purchase back to a specific person.
Why a Refund Doesn’t Mean You’re in the Clear
This is where a lot of people get tripped up, and it’s understandable. Getting your money back feels like the problem is solved. Unfortunately, that’s where things get misleading. The merchant refunding you and your card number being safe again are two separate events that happen to look similar from your side.
Fraudsters rarely use a stolen number for a single purchase and stop. Fraud researchers call a small, quick purchase a “card testing” transaction, a low-value charge run specifically to confirm a stolen number is still live before it’s used for something bigger, or sold to whoever will use it next. An unfamiliar gift card purchase is a common example of this. It’s an amount unlikely to trip a fraud alert, and gift card balances convert to cash almost instantly, which is why fraud-prevention researchers flag gift cards as one of the most common ways stolen card data gets cashed out. If that’s what happened here, the charge you noticed might not have been the attack. It might have been the test run for one.
One pattern fraud investigators see repeatedly is that unauthorized purchases often start small. If a $5, $20, or $50 charge shows up from a merchant you don’t recognize, don’t dismiss it just because the amount seems insignificant. Small charges are commonly used to test whether a stolen card is still active before larger transactions follow, sometimes within hours of that first test.
Security.org’s data backs this up: 22% of fraud victims experienced repeat, recurring charges from the same merchant in the past year, nearly double the 12% who reported that in 2024. Once a number is confirmed live, it doesn’t usually get used just once.
None of this is guaranteed to be what happened in your case. But it’s common enough that locking the card and hoping for the best leaves the door open for round two.
If you only remember one thing from this article, remember this: a refund fixes the transaction. A new card number fixes the exposure. They are not the same fix.
“Won’t the Same Thing Just Happen With My Replacement Card?”
Readers almost always ask the same follow-up question. If you don’t know exactly how your number leaked, it’s reasonable to wonder whether a new card will just get compromised the same way.
In most cases, no. Card fraud almost always traces back to a specific, isolated exposure: a breach at one merchant, a compromised checkout page, a skimmer at one gas pump, a leaked database your old number happened to be in. When you get a new number, you break that specific chain, since the new number was never part of that leak. The exception is when the exposure is on your end, such as malware on your phone, a compromised email account you use to manage cards, or a family member with access to your statements. That’s rare, but it’s the one scenario where a fresh card number alone won’t fully solve the problem.
“My Bank Told Me to Just Lock the Card. Was That Wrong?”
Not wrong exactly, but incomplete, and this is a common source of confusion. Customer service reps sometimes lead with “lock it” because the fraudulent transaction has already been refunded and there’s no active bleeding to stop. From their side, the immediate fire is out.
Most fraud specialists still recommend going a step further and replacing the card once the unauthorized charge is confirmed. Locking stops the number from being used again while it’s locked, but it doesn’t remove the number from circulation. The moment you unlock it, or if the lock has any gap, the same exposed number is live again.
A cleaner way to think about the sequence: lock the card immediately, and replace it as soon as the unauthorized charge is confirmed. Don’t treat locking as the finish line.
Lock, Freeze, or Replace: What Each One Actually Does

Card issuers throw around a few different terms here, and they’re not interchangeable, even though reps sometimes use them like they are.
| Action | What it does | What it doesn’t do | Best for |
|---|---|---|---|
| Lock / temporary freeze | Blocks new purchases on your existing card number instantly, usually from the app | Doesn’t change your card number; anyone who already has it still has a valid number waiting for the lock to lift | Buying yourself time while you decide next steps, or if you’re not sure a charge is fraudulent |
| Replace (new card number) | Cancels the compromised number entirely and issues a new one tied to your account | Takes a few business days to arrive; you’ll need to update autopay and subscriptions | Confirmed unauthorized charges. This is the step that actually closes the exposure |
| Full credit freeze (at the bureaus) | Stops new credit accounts from being opened in your name at Equifax, Experian, and TransUnion | Has nothing to do with your existing card being misused | Protecting against new-account identity theft, not existing-card fraud |
A locked-but-not-replaced card is still a valid number sitting wherever it came from, whether that’s a dark web listing, a bot’s database, or a breach dump. Unlocking it later doesn’t erase that. For a deeper breakdown of how bureau-level freezes differ from card-level locks, our credit freeze guide covers that side in more detail.
Signs Your Card Number May Still Be Compromised
Sometimes the first charge isn’t the last warning sign. Watch for:
- Another unfamiliar charge appears, even a small one.
- Small “test” transactions show up from merchants you don’t recognize.
- You start getting repeated fraud alerts within a short window.
- Your bank or a merchant notifies you of a failed purchase attempt you didn’t make.
If any of that happens after your first fraud alert, don’t wait around for a pattern to fully develop. At that point, replacing the card isn’t optional. It’s overdue.
Some People See Fraud on a Card They Haven’t Even Used Yet
It sounds unlikely, but it does happen: a replacement card gets compromised before the cardholder has really used it. Banks rarely disclose the exact cause when this happens. Possible explanations include a broader data breach that swept up the new number anyway, an account updater service that automatically pushed the new card details to a merchant on file, or an unrelated compromise that occurred shortly after the replacement was issued. Frustrating, but uncommon, and not something you could have prevented by “being more careful” with a card you hadn’t even used.
Can You Find Out Who Did It?
Almost never, and it helps to understand why so it stops feeling like an unsolved case you’re supposed to crack yourself.
Card-not-present fraud, meaning the physical card was never swiped or tapped, leaves no security-camera footage, no signature, and usually no IP address that traces back to a specific person rather than a VPN or a compromised device three states away. Banks do investigate, using tools like transaction timestamps, device fingerprinting, and geolocation, but that effort is aimed at deciding whether to reverse the charge, not at naming a suspect for you. Law enforcement involvement is rare at this dollar amount. A small charge isn’t the kind of case that gets an assigned detective, and only a small share of fraud victims ever report to police, mostly because there’s rarely a lead worth chasing.
Can the merchant just tell me who bought it? No, and this trips people up too. Even when a digital gift card is delivered instantly, merchants generally can’t hand over another customer’s information to you directly. Any real investigation happens between the merchant, the payment processor, your bank, and, if it ever escalates that far, law enforcement. That’s simply how fraud investigations are handled.
None of this means your case is being brushed off. It’s the tradeoff built into a payment system that clears card-not-present purchases in a fraction of a second. The same speed that makes online shopping convenient is what makes tracing a single bad transaction back to a person nearly impossible.
Where to Actually Report This
Your bank’s fraud department is step one, but it isn’t the only place this belongs.
- IdentityTheft.gov: the FTC’s dedicated recovery site. Even for a single unauthorized charge, it’s worth filing a report here. It generates a personalized recovery checklist, pre-filled dispute letters, and an official Identity Theft Report that some companies will ask for if things escalate.
- ReportFraud.ftc.gov: the FTC’s general fraud-reporting portal. Reports feed into the Consumer Sentinel Network, the database law enforcement agencies use to spot patterns across victims. More useful at the macro level than for your individual case, but part of how these operations eventually get shut down.
- IC3.gov: the FBI’s Internet Crime Complaint Center, worth filing with if the fraud is tied to a phishing email or a fake website.
- Fraud alerts at the credit bureaus: a free fraud alert with any one of Equifax, Experian, or TransUnion makes it harder for someone to open new credit in your name using the same stolen information. It’s a different protection than replacing your card, but a reasonable extra step given that the same breach that exposed your card number may have exposed more than that.
- Consumer Financial Protection Bureau (CFPB): worth filing a complaint here too if your bank is dragging its feet on a dispute or replacement request.
What the Law Actually Says About Your Liability
You’re not on the hook here, and this isn’t up for interpretation. It’s federal law.
Under the Fair Credit Billing Act (FCBA), your maximum liability for unauthorized credit card charges is $50, and that only applies if you don’t report it within 60 days of your statement. If you catch it before it’s even fully posted, which is what happened here, your liability is $0.
Every major U.S. card network layers its own zero-liability policy on top of that legal floor, and in practice these go further:
- Visa and Mastercard both guarantee $0 liability for unauthorized transactions on consumer cards, provided you’ve used reasonable care with the card and reported promptly.
- American Express offers the same protection under its Fraud Protection Guarantee.
- Discover guarantees $0 fraud liability and typically closes the account and issues a new card as part of resolving a claim.
- Issuer-level guarantees track the same standard. Bank of America’s $0 Liability Guarantee, Chase’s Zero Liability Protection, Citi’s $0 liability on unauthorized charges, and Capital One’s $0 Fraud Liability all work the same way in practice.
None of these protections require you to identify the thief. They’re triggered by you reporting the charge as unauthorized, which you’ve already done.
Is a Debit Card Protected the Same Way?
No, and this is worth knowing before it happens to you on the debit side. Debit cards fall under the Electronic Fund Transfer Act (EFTA), not the FCBA. Your liability is capped at $50 only if you report within two business days. Wait longer than that and it can rise to $500, and after 60 days you could be on the hook for the full amount, since the money has already left your checking account rather than being a disputed charge on a bill you haven’t paid yet. It’s a meaningful gap, and part of why credit cards are the safer default for online purchases.
What Happens After You Report It
Roughly, here’s the timeline once you flag a charge as fraudulent:
- Day 1: Card gets locked, fraud is reported, replacement is ordered.
- Days 3–7: New card arrives, old number is fully deactivated.
- Within 60–90 days: Issuer wraps up its formal investigation and finalizes the dispute, though your $0 liability protection kicks in well before that’s resolved.
Your money and your protection aren’t waiting on that full investigation to close. They’re already in effect from the moment you report.
How to Protect Your New Card From Future Fraud

The annoying part of replacing a card usually isn’t waiting for the physical card to arrive. It’s updating every subscription and autopay tied to the old number. If you’ve had the same card for years, that list is longer than you’d expect: streaming services, utilities, a gym membership, whatever recurring charge you forgot you even had. It’s tedious, but it’s a lot less painful than dealing with repeat fraud alerts over the next few months because the old number is still floating around out there.
A few things cut down how often you end up back in this spot:
- Turn on real-time purchase alerts. Most issuers will text or push-notify you the moment a charge posts. It’s how you caught this one in the first place.
- Use a virtual card number for online purchases where your issuer offers it. Capital One’s Eno tool, Citi’s Virtual Account Numbers, and American Express’s virtual card option all generate a separate number tied to your real account, so a breach at a merchant’s checkout exposes a disposable number instead of your actual card. Our guide to virtual card numbers walks through which issuers support this and how to set it up.
- Don’t assume a new number is doomed to repeat the cycle. Most fraud traces back to one isolated exposure, not a permanent flaw in your phone, your bank, or your habits. A fresh number genuinely closes off the specific hole that let this happen, even if it can’t promise you’ll never see fraud again.
- If you’re shopping for a new card anyway, some cards build in stronger fraud monitoring than others. Our roundup of the best cards for fraud protection compares issuer tools side by side.
After going through issuer guidance, FTC resources, payment-network policies, and the patterns that show up again and again in real cardholder reports, the advice lands in the same place every time: treat a compromised number as permanently compromised, not as something you can quietly reactivate later.
FAQ
Do I need a new card if the merchant already refunded me? Usually, yes. The refund resolves that one transaction; it doesn’t revoke the card number itself, which may still be circulating or being tested by whoever obtained it.
Will locking my card without replacing it keep me safe? Only temporarily. A lock blocks new charges on the existing number, but the number itself is still compromised. Unlocking it later brings the same exposure right back.
Can my bank or the FTC tell me who used my card? Almost never for card-not-present fraud. There’s no physical trail to follow, and the dollar amounts involved rarely justify a law enforcement investigation into a specific suspect.
Am I liable for the charge? No. Federal law caps your liability at $50, and $0 if you report before further unauthorized use, and every major card network’s zero-liability policy goes further than that floor in practice.
How did my card number leak if I never gave it to anyone and don’t use the merchant it was charged at? Most likely candidates: a data breach at a company you do use that stored your card on file, a card-testing bot that guessed a valid combination, or your number resurfacing from an older breach that’s now circulating. It’s genuinely common not to be able to pin down the exact source.
Should I also freeze my credit report, not just my card? It’s a reasonable extra step, but it protects against something different, namely new accounts being opened in your name, rather than misuse of the card you already have.
Is a debit card as protected as a credit card in this situation? No. Debit cards fall under the EFTA, which caps liability at $50 only if you report within two business days, rising to $500 after that, and potentially the full amount after 60 days.
This article is for general informational purposes and isn’t legal or financial advice. Liability protections and reporting timelines can vary by issuer and card agreement. Check your cardholder agreement or contact your issuer directly for details specific to your account.
Reviewed against guidance from the FTC, the Fair Credit Billing Act, and published fraud policies from Visa, Mastercard, American Express, and Discover.