Latest News

What a fuel card exception report actually catches, and what it misses

Two numbers get quoted in almost every article about fuel card fraud. One is $16.6 billion, the other is $12.5 billion, and neither one measures fuel cards. Before you set a single threshold, it is worth knowing which figures describe your problem and which describe something else entirely. The answer changes what you build, because an exception report can only test what your own transaction data already contains. Look into the Shell fuel cards for enhanced security features.

The number in every fuel card fraud article is the wrong number

The $16.6 billion figure comes from the 2024 annual report of the FBI’s Internet Crime Complaint Center. It covers all cyber-enabled crime reported to that center in 2024, across 859,532 complaints, a 33 percent rise over 2023. Read one layer down and the shape changes: only 256,256 of those complaints reported an actual loss, and the average reported loss was $19,372. Investment fraud, most of it involving cryptocurrency, accounts for the largest single share.

The $12.5 billion comes from the Federal Trade Commission, whose Consumer Sentinel Network logged 6.5 million consumer reports in 2024 and a 25 percent rise in reported fraud losses. Different collector, different population, different definition of a loss.

Neither number tells you anything about your fleet.

That matters more than it sounds. A figure you cannot decompose is a figure you cannot build a rule from. If you want a threshold, you need a number with a denominator, and the national fraud totals do not have one that applies to a fuel program.

What the Secret Service data actually says about skimmers

There is a public dataset with a denominator, and almost nobody quotes it. In 2025 the United States Secret Service ran 22 skimming outreach operations across 17 cities, visited more than 9,000 businesses, and inspected close to 60,000 devices: point-of-sale terminal hardware, gas pumps, and ATMs. It removed 411 illegal skimming devices and estimated the prevented loss at $428.1 million.

Divide it out. That is roughly one device for every 146 terminals inspected, in cities selected because they were suspected hot spots.

Two honest caveats. Those sweeps were aimed primarily at Electronic Benefit Transfer fraud, not fleet cards, so the base rate is indicative rather than exact. And an inspection finds only the hardware present on the day. Neither caveat changes the useful conclusion: skimming at the automated fuel dispenser is real, it is not ambient, and it is not the thing your own reporting is well positioned to catch.

What an exception report can prove from transaction data alone

Fuel card exception reports catch three things reliably: fills that exceed a vehicle’s tank capacity, the same card transacting in two places it could not have traveled between, and product codes the vehicle cannot take. Everything else, including most skimming, gets caught by the issuer or the bank, not by your report.

Those three work because each one is a contradiction inside data you already hold, not an inference about intent.

Rule What it compares Starting threshold Data you must trust first
Over-capacity fill Gallons dispensed against assigned tank size Flag above 105 percent Vehicle roster tank sizes
Impossible pair Two fills, distance apart, time apart Flag under 45 mph implied Site coordinates
Wrong product Product code against vehicle fuel type Any mismatch Vehicle fuel type field

 

Every one of those thresholds is a starting point, not a recommendation. The third column is where programs fail, and it is worth being blunt about the order of operations: a rule built on a vehicle roster nobody has audited since the trucks were bought will generate noise, and noise is how reports get abandoned.

Worked example for the second rule. A card fills at 06:12 in Amarillo and again at 09:40 in Oklahoma City, about 260 highway miles apart. That is 3 hours and 28 minutes, an implied 75 mph average with no stops, no scale time, and no fueling minutes. The pair proves nothing on its own. It is a question worth one phone call, and it costs nothing to generate because both timestamps and both site locations are already on the statement.

An Electronic Logging Device or telematics feed makes the second rule sharper by replacing implied speed with actual position. It is not a prerequisite. The impossible-pair test runs on transaction timestamps and site locations alone, which every fuel card program already returns.

The vector Texas added that your exception report will misread

On September 1, 2025, Texas House Bill 201 took effect, expanding the mandate of the state’s Financial Crimes Intelligence Center. The bill directs the center to help detect skimmers and, in its own phrasing, motor fuel manipulation devices, and to coordinate the response when one is found.

That second category is the interesting one. A manipulated meter dispenses less fuel than it records, so the customer pays for gallons that never reached the tank.

Here is why it matters to a detection program. Meter manipulation is not card theft, and in your data it does not look like theft. It looks like a vehicle that suddenly needs more gallons per mile, or a fill that runs slightly over tank capacity at one particular site. Those are the same signatures as a driver filling a personal vehicle. A report that treats every volume anomaly as driver misconduct will produce an accusation where the correct output was a site to avoid.

The tell is clustering. Driver misuse follows a driver across sites. Meter problems follow a site across drivers. Group your exceptions by location before you group them by person, and the two separate cleanly.

Where tighter thresholds start costing more than the fraud

Every rule above has a false-positive rate, and false positives are what kill exception reporting. Not fraud. Abandonment.

Set the over-capacity rule at 100 percent of tank size and you will flag the driver who tops off after a long idle, the truck with an auxiliary tank nobody recorded, and every unit whose capacity was typed in wrong three years ago. Two weeks of that and nobody opens the report, which is worse than never building it, because now the exposure is invisible and everyone believes it is covered.

The sequence that survives contact: fix the vehicle roster, run the rules in reporting-only mode for a month, tune each threshold against the exceptions you actually get, and attach consequences last. Programs that skip to enforcement tend to be back at no controls within a quarter.

There is a real limit worth stating plainly. None of this catches a driver who fills the right vehicle with the right product in the right place and siphons it later. That is a custody problem, and no transaction rule will reach it.

Start with the rule you can build from data you already trust. One over-capacity check on a clean roster is worth more than five rules running on a vehicle list nobody has opened since it was imported.

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This