I understand why you'd (almost) fall for this. I think it is wrong to assume you never will. So put safeguards in place, it may be good to start thinking about how those could look like. I have no idea... I'm very afraid my parents will someday waste a lot of money on a scam like this. Or, you know, me.
I've got to admit, although I'm not a security expert at all, all of these scams sound way too unlikely for to me fall for. But then again, it's easy to think that when you're behind your desk reading an article called "how I got scammed". It's very different when they reach you when you're already stressed and confused. Who knows what I'd fall for. I hope I'll never find out.
Also, banks are smart. If a single CC is being simultaneously used in multiple physical locations, that’s an immediate red flag for fraud. My bank also asks for OTPs when I make online payments at novel/obscure websites.
A scammer who got my full CC number couldn’t make a fake physical card since it’s chip-and-pin; or at least not use it at any mainstream retailer which would require a chip transaction. So they’d be limited to online ones. I suspect the bank might even be passed the IP or other fingerprint details when authenticating the transaction, resulting in OTP requirements when risk is detected (online transaction from foreign country when I live in my country).
As long as you have a couple of CCs (so you can still pay for stuff if one gets deactivated due to fraud), CC fraud will typically be detected by the bank and refunded, along with new card issuance.
My main CC company will also text me randomly asking if any of the last three charges was unauthorized, with their details. Sometimes the card is paused until I respond. This most typically happens when I’m traveling. If I text back that they’re all legitimate then the card works again immediately; if one is fraudulent then they get me on the phone to confirm the details and issue a new card.
The CC companies seem to be pretty good about not having false alarms when you travel any more (though if you’re traveling internationally, giving them a heads up helps avoid issues) - I believe it’s simultaneous use from multiple geos that trips fraud alarms.
0) the scammer somehow acquires Person A's credit card info
1) the scammer sets up an online store on Amazon or similar and sells some popular item at a 20% discount (eg Nespresso pods)
2) the scammer doesn't actually have that item in stock, but when they get an order from Person B, they use the stolen card to place another order with a legitimate seller and set the destination address to Person B's address (basically drop-shipping but where the victim is paying for the cost of the goods being sold)
3) Now the scammer has received already-laundered clean money from an online transaction, and Person B got the product they wanted on-time and at a steep discount. They're happy, and certainly won't be complaining to their credit card company.
4) when Person A reports their card stolen and tries to perform a chargeback, the legitimate seller who acted as an unwitting drop-shipper ends up eating the cost.
DEF CON 27 - Confessions of an Nespresso Money Mule Free Stuff and Triangulation Fraud: https://www.youtube.com/watch?v=4fYZpRBuh-s
This relies on churn and hoping that a percentage of the fraudulent charges go unnoticed. But if it’s oversight then it’s not really that party “seeing” anything.
But yeah, CC are safer, it's one of the things you pay for (typically by mean of higher prices, as merchants pass on their CC fees to customers).
While this is true, it's also much harder to do a fraudulent payment. The card number itself is not enough; you actually have to go through the bank's payment system with its 2FA, and that's not something a thief can easily fake.