Corpay

Single-Use Cards & Fraud Prevention: How Virtual Cards Reduce Payment Risk

Category:Virtual Card, Risk management, Payments Automation
Updated:2026-07-27
Author:David Luther

A single-use virtual card is a card number issued for exactly one payment, usually locked to a specific amount, that stops working the moment that payment clears. Steal the number afterward and you've stolen nothing.

Consumer coverage of these cards frames them as a privacy tool for online shopping, and that framing has stuck hard enough that most finance teams never evaluate them as an AP control. The B2B case is stronger and more measurable. A one-time number bounded by an exact amount doesn't only shut down a fraudster; it also blocks the overcharge, the transposed invoice figure, and the duplicate payment that your three-way match was supposed to catch and sometimes doesn't.

The tradeoff is real, and this piece takes it seriously. Single-use cards add issuance overhead, and there are categories of spend where a multi-use or lodged card is the better instrument.

Key Takeaways

  • A single-use number is dead after one authorization, so the window during which a stolen credential is worth anything closes at settlement rather than staying open for years.

  • Exact-amount matching does double duty, blocking both fraudulent charges and honest billing errors like overcharges and duplicate submissions.

  • The strongest fits are new or unvetted vendors, one-off purchases, and any high-value payment you won't repeat.

  • Recurring vendors, travel programs, and consumable purchasing are usually better served by a multi-use or lodged card.

  • Single-use cards are one layer in a fraud-prevention stack, not a replacement for vendor verification, approval workflows, or reconciliation.

  • Fraud prevention has become core AP work rather than a treasury side project, which changes who owns the decision about payment instruments.

What is a single-use virtual card, and how does it work?

A single-use virtual card is a card number generated on demand for one specific payment, carrying its own limit, expiry, and often a lock to a single merchant, that deactivates automatically after the transaction authorizes. It draws on your company's existing card line rather than creating a new one.

The mechanics are straightforward. Your platform mints a 16-digit number, attaches the invoice amount as a hard ceiling, and hands it to the vendor or applies it to the purchase. The vendor runs it, the authorization matches the expected amount, the payment settles, and the number retires. If someone later pulls that number out of the vendor's billing system, they have a string of digits that no longer maps to an active credential.

If the underlying concept is new to you, the broader mechanics of what a virtual card is cover the category, and single-use is the tightest configuration inside it. The category is not a niche experiment anymore. B2B virtual card payments are projected to reach $14.6 trillion by 2029, roughly 83% of the total virtual-card market, according to Juniper Research's 2024 Virtual Cards Market Research Report 2025-29.

How is a single-use number different from a reusable card?

A reusable number stays valid and stays stored, which means it accumulates exposure with every place it's been used. A single-use number carries almost none of that history because it has no future.

Think about where a reusable corporate card number actually lives after a year of normal use. It's in a dozen vendor billing databases, several booking platforms, an email thread or two, and probably a shared spreadsheet somebody built in 2023. Each one of those is an independent chance for the number to leak, and every leak stays exploitable for as long as the card is active. When one of them does leak, canceling the card breaks every legitimate payment attached to it, which is why teams hesitate and why compromised numbers stay live longer than they should.

Single-use card

Multi-use virtual card

One authorization, then deactivates

Valid until its limit, expiry, or cancellation

Amount typically matched to a specific invoice

Recurring or cumulative limit

Issued per payment

Issued per vendor, project, or cardholder

Best for one-off and unvetted vendors

Best for recurring and trusted relationships

Higher issuance overhead per transaction

Lower overhead, broader standing exposure

What happens to the number after the payment clears?

It stops authorizing. The issuer marks the credential closed once the single permitted authorization completes, so any subsequent attempt to charge it declines regardless of who's attempting it or how much they ask for.

There's an operational wrinkle worth knowing about. Some merchants authorize and capture at different times, and a few authorize an estimated amount before finalizing. Hotels and freight carriers are the usual culprits. A strict single-use configuration can decline the second attempt on a legitimate transaction, which is a good argument for using tightly scoped multi-use cards in those categories rather than fighting the settlement pattern.

How do single-use cards reduce payment fraud?

They reduce fraud by shrinking two things at once: the lifespan of a credential and the amount any single misuse can extract. Most payment fraud depends on a credential or an instruction remaining valid long enough to be exploited, and a single-use card removes that runway.

The problem is broad enough to justify structural fixes rather than more training. Among organizations hit by attempted or actual payments fraud in 2024, 63% reported check fraud and the same share reported business email compromise, according to AFP's 2025 Payments Fraud and Control Survey Report. Those aren't edge-case numbers. They describe the normal operating environment for a finance team, and both of those attack types aim at a payment instrument you get to choose.

Why does a one-time number limit a stolen card's value?

Because value in stolen card data comes from being able to use it, and a retired number can't be used. The economics of card fraud run on volume and reusability, so credentials that die at first use are close to worthless in the resale market where most stolen card data ends up.

The scale of what's being defended against is substantial. Global card fraud losses reached $33.41 billion in 2024, with the U.S. accounting for 41.87% of worldwide losses on 26.31% of card volume, and the Nilson Report's January 2026 study projects losses reaching $41.06 billion by 2030. Credit card fraud also remained the most prevalent form of identity theft in 2024, with more than 458,000 reports filed, per the FTC's 2025 Consumer Sentinel Network Data Book.

Underneath the number, network tokenization narrows exposure further by replacing the credential a merchant stores with a value bound to that merchant. Visa, which has issued 10 billion payment tokens since 2014, estimates tokenization can reduce fraud by up to 60%. Layering a one-time number on top of a token means a merchant breach yields a merchant-bound token pointing at a card that no longer exists.

How does exact-amount matching stop overcharges and duplicates?

Exact-amount matching sets the card's authorization ceiling to the approved invoice total, so anything above that figure declines at the terminal instead of arriving as a variance for someone to catch later. The control fires before the money moves rather than after.

That catches a broader class of problems than fraud alone:

  • A vendor bills $47,800 against an approved $47,080 and the authorization fails on the spot.

  • A duplicate invoice submitted through a second channel finds no live card to charge.

  • A recurring charge that shouldn't have recurred simply declines.

  • A padded change order gets stopped at the authorization rather than during a quarterly review.

Duplicate payments are the quiet cost center here. They rarely get reported as fraud, they're painful to recover, and they scale with invoice volume. Automation helps at the invoice layer, and four ways automated invoice processing reduces payment fraud covers that side, but the card-level ceiling is the last stop before funds leave.

Best practices for a virtual card program

Learn the internal strategies that make a virtual card program succeed — from program design to driving the vendor acceptance that determines how much of your AP spend earns rebates.

Download the guide
gated.jpg

How do you decide where single-use cards are worth the overhead?

Use them when a payment is a one-time event, when the vendor relationship is new or unverified, or when the dollar amount is large enough that a mistake would hurt. Those three conditions overlap often, and the overlap is where single-use cards earn their overhead.

The honest counterpoint is that issuance overhead is real. Generating a card per payment is more work than running everything through one number, and if your AP volume is high and your vendor base is stable, that work may not pay for itself everywhere. Deciding where to apply it is the actual skill.

Which payments are the best fit: new vendors, one-off buys, high-risk spend?

New and unvetted vendors are the clearest case, because you have no payment history to reason from and no basis for trusting their security posture. A single-use card lets you transact without extending standing exposure to an organization you've known for eleven days.

One-off purchases follow closely. A trade-show booth, a legal settlement, an equipment purchase from a vendor you'll never use again, and emergency spend during an outage all share the same profile. There's no reason for the credential to survive the transaction, and no downstream process depends on it staying live.

High-value spend is the third category, and the reasoning there is proportional rather than categorical. A $180,000 payment doesn't carry a higher probability of going wrong than an $1,800 one, but the consequence is a hundred times larger, and matching the card to the exact amount costs the same either way. The framework for deciding this systematically belongs in policy, which is where card controls and spend policies does more work than any single card setting.

When is a multi-use or lodged card the better choice?

When the payment repeats, when the settlement pattern is unpredictable, or when the vendor's systems expect a stable credential on file. Forcing single-use into those situations creates declines, support tickets, and vendor friction that outweigh the risk reduction.

The categories where multi-use usually wins:

  • Recurring software and subscription vendors, where the number needs to stay on file

  • Travel booked through an agency, where a lodged account is the established pattern

  • Categories with authorization-then-capture gaps, including hotels and freight

  • High-frequency, low-value purchasing where per-payment issuance would swamp the team

Lodged accounts have their own long history in corporate travel, and what a ghost card is explains where that model still holds up. The full single-versus-multi decision, framed around usage rather than risk, is worked through in single-use virtual cards and when to use them instead of multi-use, which is the companion piece to this one.

How do single-use cards fit into an AP fraud-prevention stack?

They're the last layer, sitting after vendor verification and approvals and before reconciliation, which means they catch what the earlier layers miss rather than replacing them. Treating a single-use card as a complete fraud program is the most common mistake I see teams make when they first adopt them.

A working stack has four layers doing different jobs:

  1. Vendor verification confirms the payee is who they claim and that the banking details belong to them.

  2. Approval workflow confirms someone with authority agreed to this amount for this purpose.

  3. The payment instrument enforces that agreement at authorization, which is where a single-use card sits.

  4. Automated reconciliation catches anything the first three let through, fast enough to act on.

Ownership of this has shifted meaningfully. Ardent Partners' 2025 State of ePayables report found that 79% of AP teams now play an active role in fraud prevention, making it the most common strategic responsibility in the function. Payment-instrument decisions used to live in treasury; increasingly the AP director is the one who has to defend them.

How do they pair with vendor verification and approval controls?

They pair well because each layer fails in a different way, and single-use cards cover the specific gap where a legitimate-looking instruction reaches a legitimate-looking vendor. Verification confirms who the vendor is and where their money should go. Approvals confirm somebody with authority agreed to the amount. The card enforces that agreement at the moment of payment.

Business email compromise is the attack that most often defeats the first two layers, since it works by impersonating a party everyone already trusts. The FBI Internet Crime Complaint Center's 2024 Internet Crime Report recorded $2.77 billion in reported losses across 21,442 complaints in 2024, and nearly $8.5 billion across 2022 through 2024. A card scoped to a verified merchant identity and a fixed amount narrows what a successful impersonation can actually collect. The patterns behind these schemes are worth understanding before designing controls around them, and accounts payable fraud walks through how they typically unfold.

One practical note from sitting in on these program reviews: the layer that fails most often is the exception path, not the technology. Ask your team what happens when a single-use card declines at 6 p.m. on the last day of a vendor's payment terms, and whether the answer involves someone emailing a reusable card number as a workaround. That workaround, if it exists, is your real control environment.

How does automated reconciliation close the loop?

It closes the loop by matching each card transaction back to the invoice it was issued for automatically, so an unmatched or mismatched payment surfaces within days instead of at month-end close. A control that catches problems at settlement is worth several that catch them in review.

Because a single-use card is created for one invoice, the match is nearly deterministic. There's no allocation guesswork, no shared-statement untangling, and no analyst reconstructing what a $6,400 charge at an unfamiliar merchant was for. The tighter the card scope, the cheaper the reconciliation. Programs that combine both effects are described in more depth in how virtual cards and automation mitigate fraud.

Where teams sometimes overreach is in expecting the card program to substitute for security standards on the platform side. PCI DSS v4.0.1 has been the only supported version of the standard since January 1, 2025, with 51 new requirements taking effect on March 31 that year, according to the PCI Security Standards Council. Ask any provider which entity holds the attestation and what scope it covers, and treat card-level controls as a complement to that, not a replacement.

How Corpay's single-use virtual cards cut payment risk

The scenario that ends most of these evaluations is a specific one. A vendor's email is compromised, an invoice arrives with a changed amount or changed banking details, the payment clears, and by the time reconciliation catches it the funds are unrecoverable. Corpay's virtual cards are built so that scenario has a ceiling.

Cards can be issued single-use and matched to the approved invoice amount, scoped to a merchant, and dated to expire on the terms you set. Vendor banking details are validated as part of the managed program rather than trusted from an inbound email. Each card produces its own transaction record that flows back into your accounting system, which is what makes the reconciliation match near-automatic rather than a monthly reconstruction project. Corpay's payments automation handles the surrounding workflow, including supplier enrollment and payment delivery, so the card program complements your ERP instead of asking it to do work it wasn't designed for.

If you're starting, pick your riskiest category rather than your largest. New-vendor first payments and one-off purchases over some threshold you set are the two places where single-use pays back fastest, and both are small enough to run for a quarter without reorganizing anything.

Frequently Asked Questions

How do single-use credit card numbers work?

Your platform generates a card number tied to your existing account, applies a limit matched to the payment, and permits one authorization. Once the vendor charges it and the transaction settles, the number deactivates. Everything after that declines, including a second attempt by the same vendor.

Can a single-use card be charged twice?

No, which is the point. After the permitted authorization completes, further charge attempts decline. That's why merchants with authorize-then-capture patterns, like hotels and some freight carriers, are better served by a tightly scoped multi-use card than by a strict single-use one.

What's the difference between single-use and multi-use virtual cards?

A single-use card permits one authorization and then retires. A multi-use card stays valid until it hits its limit, reaches its expiry date, or gets canceled. Single-use is scoped per payment; multi-use is scoped per vendor, project, or cardholder.

Which payments should use a single-use card?

One-off purchases, first payments to new or unverified vendors, and any transaction large enough that an error or fraud would be materially painful. Recurring vendors and travel programs are usually better served by a card that stays on file.

Are single-use cards safer than reusable cards?

Yes, in the specific and important sense that a stolen credential has almost no residual value. A reusable number sits in vendor databases indefinitely and stays exploitable for as long as it's active. A single-use number is exposed only during the short gap between issuance and settlement.

Do single-use cards help stop duplicate payments?

They do, and it's an underrated benefit. Because the card carries a hard amount ceiling and permits one authorization, a duplicate invoice pushed through a second channel has no live credential to charge. The duplicate fails at authorization rather than surfacing weeks later in a recovery effort.

Do single-use cards stop business email compromise?

They limit the damage rather than preventing the attack. A card issued against a verified merchant and a fixed amount won't authorize for an impostor's merchant account or pay more than the approved figure. Vendor verification and callback controls still do the primary work, which is why how to defend your company from payment fraud treats them as a set rather than as alternatives.

Do vendors need to do anything special to accept a single-use card?

Not usually. It processes as an ordinary card payment on the vendor's existing terminal or gateway, so no integration work is required on their side. The friction that does come up is acceptance, since some vendors resist card payments over interchange cost, and that negotiation is separate from the security question.

Headshot.JPG

David Luther

Product Marketing Program Manager
David Luther, MBA is a product marketing program manager with years of experience in commercial banking, finance, and technology sectors, with research and writing appearing in financial publications.
Virtual Card
Risk management
Payments Automation

Smarter payments. Stronger growth. Keep business moving.

Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.

Please select your communication type
Please enter your first name
Please enter your last name
Email address is required
Please enter your company
Please enter your region

By submitting your information through this form, you agree to receive a telephone call or email from a Corpay representative. Your information will be used in accordance with our Privacy Policy.