Yes — you can shop online with minimal fraud risk by holding five habits: use virtual card numbers or one dedicated card for online purchases, buy from stores you can verify exist, hover before you tap buy, keep the transaction inside the platform (never wire or pay by gift card), and treat every urgency or off-site request — "confirm your order," "pay the courier directly" — as hostile until verified. U.S. law caps cardholder liability at $50 and networks run zero-liability policies, which is why card fraud is recoverable while gift-card, wire, and crypto payments are not — the entire game is keeping payments on instruments that protect you.
Set up your payment layer first
- Use virtual card numbers where offered — browser- and bank-generated single-use or merchant-locked numbers (Apple Pay, Google Pay, and most large issuers offer variants). A leaked virtual number is closed with a click; your real number never travels.
- Or dedicate one card to online shopping with alerts on, so compromise is a nuisance rather than a life event — and never shop with a debit card, whose dispute protections are weaker and whose money is yours-on-loan during the fight.
- Turn on transaction alerts for the card: instant notification is the fastest fraud detection that exists.
- Consider a payment wallet (Apple Pay, Google Pay, PayPal) at checkout: the merchant never sees the card number at all.
How do you spot a fake shop?
Fake storefronts are the e-commerce era's phishing page — polished sites with prices engineered to overcome skepticism. The tells:
- Prices too far below market on current-model goods. A 70%-off power tool or camera is the lure itself.
- New domain age: shops that appeared weeks ago selling established brands. A whois lookup or simply searching the store's name plus "scam" costs seconds.
- Contact reality: no physical address, no phone, a support email at a free provider — or contacts that exist only through a form.
- Checkout anomalies: a card-entry page that is not on the shop's own domain, redirects to a differently-named payment site, or pressure countdown timers.
- Reviews that travel: identical review text across "different" stores, or a wall of five-stars weeks after the domain registered.
For marketplaces, the variant is the hijacked or spoofed seller: prices off-market, seller accounts with no history, and requests to move the conversation to email or WhatsApp — which is where the actual theft is proposed. Stay in the platform's checkout and messaging, always.
What about the checkout itself?
Confirm the padlock and the correct domain on the payment page — the lock is table stakes (every site has HTTPS), the domain spelling is the real check. Do not save cards on sites you will never revisit; the convenience is a standing credential at a merchant you cannot vouch for. And on any site that stores your card for recurring use, prefer those that support network tokenization (the wallet flows above) — a tokenized card number that a breach exposes is worthless outside that merchant.
What are the post-purchase scams?
Two dominate. The fake order confirmation: an email or text about an order you didn't make, with a link or number to "dispute" — the goal is your card details or remote access; check orders in your account on the real site or app, never from the message. The delivery scam: a text about a package problem with a fee or address confirmation, timed to holiday shipping seasons; carriers do not conduct business through random links. Both are phishing with a shopping costume, and both lose their power the moment you navigate to the app yourself instead of trusting the message.
What if fraud happens anyway?
Card charge path: report to the issuer in the app immediately — provisional credit and a replacement card are routine under network rules; document the order, the confirmation, and the merchant's non-response. Non-card payments to a fake shop: report to the FTC at reportfraud.ftc.gov, the FBI's IC3, and your bank for any possible recall — recovery odds fall with each hour. And for identity exposure beyond a card — an account created in your name, or a shop that stored more than payment — the breach-notification playbook applies, including credit freezes if the data warrants it.
For more context, read How to spot a phishing email: the six checks that catch most fakes.
For more context, read personal security checklist.
For more context, read How to read a data breach notification without panicking.

