Card not present fraud in Europe
Card not present fraud hits card payments where neither the card nor the cardholder is at the merchant: online, in an app or by phone. In the latest EBA and ECB report, these remote payments were around 28 percent of the value of card transactions and around 83 percent of the value of card fraud. Dated events on payments and fraud are in the calendar below.
What the European figures show
The 2025 report on payment fraud by the EBA and the ECB puts fraud on cards issued in the EU and EEA at EUR 1.3 billion in 2024, a fraud rate of 0.033 percent of the value. Remote card payments had a fraud rate of 0.091 percent by value, against 0.007 percent for card payments at the point of sale, 13 times higher. In most card fraud the fraudster issued the payment order, often with stolen card credentials.
Card fraud rates were about 17 times higher when the counterpart sat outside the EEA, where strong customer authentication may not be required, and 30 percent of the value of fraudulent card payments in 2024 came from cross-border transactions outside the EEA.
Where the card data comes from
The BSI names phishing, malware and stolen databases as the routes by which access data reaches criminals. Card numbers that may or may not still work get checked in bulk by card testing, which the Visa Core Rules call an enumeration attack: the systematic submission of card-absent transactions to obtain or validate payment information. Scripts on payment pages are another route, covered by the requirements on payment page scripts in PCI DSS 4.0.
A fraudulent card-absent payment surfaces as a dispute: Visa issuers use dispute condition 10.4, "Other Fraud: Card-Absent Environment", within 120 days of processing. Disputes filed by the real cardholder who did buy the goods are friendly fraud.
What strong customer authentication changed
PSD2 made strong customer authentication the default for electronic payments, and the report finds that SCA-authenticated card payments showed lower fraud rates than those without SCA. Dynamic linking ties the authentication code to the amount and the payee of a remote transaction. Only 40 percent of electronically initiated card payments were SCA-authenticated in 2024, because contactless payments at the point of sale often run without it.
The report also notes that new fraud types target transactions under an SCA exemption or manipulate the cardholder into authenticating the fraudster's payment. Banks answer with risk scoring on each payment, described on the AI fraud detection page, and with authentication elements such as behavioral biometrics.
Upcoming events on payments and fraud in Germany
What is a card not present transaction?
A card not present transaction is a card payment in which the card is not physically presented to the merchant: an online purchase, an in-app payment, or an order by mail or phone. The EBA and the ECB call these remote card payments. Card scheme rules call the setting a card-absent environment.
Who pays for card not present fraud?
Across the EEA, payment service users bore 38 percent of card fraud losses in 2024, with shares between 12 and more than 87 percent from country to country. In Germany, under section 675v of the Civil Code, a payer carries at most EUR 50 of an unauthorized payment with a misused card unless the payer acted with intent or gross negligence, and nothing if the bank did not require strong customer authentication. Between merchant and issuer, the card scheme rules decide.
Card not present fraud and Finance Loop
Finance Loop is the meeting place for card, ecommerce and fraud teams at banks, acquirers and payment service providers in Germany, Austria and Switzerland. Finance Loop highlighted fAInance by Sopra Steria and Fraunhofer IAIS, which had a station on AI against financial crime.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.