Also, banks are smart. If a single CC is being simultaneously used in multiple physical locations, that’s an immediate red flag for fraud. My bank also asks for OTPs when I make online payments at novel/obscure websites.
A scammer who got my full CC number couldn’t make a fake physical card since it’s chip-and-pin; or at least not use it at any mainstream retailer which would require a chip transaction. So they’d be limited to online ones. I suspect the bank might even be passed the IP or other fingerprint details when authenticating the transaction, resulting in OTP requirements when risk is detected (online transaction from foreign country when I live in my country).
As long as you have a couple of CCs (so you can still pay for stuff if one gets deactivated due to fraud), CC fraud will typically be detected by the bank and refunded, along with new card issuance.
My main CC company will also text me randomly asking if any of the last three charges was unauthorized, with their details. Sometimes the card is paused until I respond. This most typically happens when I’m traveling. If I text back that they’re all legitimate then the card works again immediately; if one is fraudulent then they get me on the phone to confirm the details and issue a new card.
The CC companies seem to be pretty good about not having false alarms when you travel any more (though if you’re traveling internationally, giving them a heads up helps avoid issues) - I believe it’s simultaneous use from multiple geos that trips fraud alarms.