Fraud reporting under PSD2
Fraud reporting under PSD2 is the statistical report on payment fraud that every payment service provider in the EU sends to its supervisor. It covers credit transfers, direct debits, card payments, cash withdrawals and e-money, split by fraud type and by whether strong customer authentication was applied. The EBA and the ECB publish the aggregate: EUR 4.2 billion of payment fraud in the EEA in 2024. Dated events on fraud and payments regulation are in the calendar below.
Who reports what to whom
Article 96(6) of PSD2 requires payment service providers to report statistical data on fraud to their national authorities, which pass it on to the EBA and the ECB in aggregated form. The EBA Guidelines on fraud reporting under PSD2 (EBA/GL/2018/05), applied as amended since July 1, 2020, define the data. Euro-area providers report fraud data to their national central bank under the ECB Regulation on payments statistics as well, and a memorandum of understanding lets one report via the central banks and the ECB count for both.
Data is reported every six months. In Germany, section 54(5) of the Payment Services Supervision Act obliges providers to send BaFin statistical data on fraud at least once a year. Card data is reported from the issuing side: payments with cards issued in the EU and EEA, accepted anywhere.
What the report breaks down
Each fraudulent payment is assigned a type. For an unauthorized payment, the fraudster either issued the payment order or modified a genuine one. Manipulation of the payer covers payments the customer made after being deceived, the case covered on the APP fraud page. Card fraud has further types such as lost or stolen cards. The report also says whether the payment was authenticated with strong customer authentication and, if not, which exemption applied, and who bore the loss.
Direct debits have a rule of their own. A refund within the eight-week window is not reported as fraud by default, only when the provider knows it was fraud, and providers do not have to ask. The 2025 report by the EBA and the ECB names this as one reason why many countries report no direct debit losses at all.
What the 2024 data shows about new payment methods
Fraudulent credit transfers reached EUR 2.5 billion in 2024, 24 percent more than in 2023, and manipulation of the payer was more than half of their value. SCA-authenticated card payments showed lower fraud rates than those without. A box in the report on SEPA instant credit transfers shows instant transaction volumes up 98 percent from 2022 to 2024 and instant fraud volumes up 175 percent.
The report adds that the data only partly reflects verification of payee, which became mandatory with instant payments on October 9, 2025, and that the check may help contain fraud in later periods. The EBA and the ECB check the submissions with validation rules published with the guidelines and in the EBA reporting framework.
Upcoming events on fraud and payments regulation in Germany
Who has to report payment fraud under PSD2?
Every payment service provider under PSD2: banks, payment institutions and e-money institutions. They report to their national authority, in Germany BaFin, and the data reaches the EBA and the ECB in aggregated form.
Where can the results be read?
In the joint report of the EBA and the ECB on payment fraud. The 2025 edition covers six half-years from the first half of 2022 to the second half of 2024 and builds on the report published in August 2024.
Fraud reporting under PSD2 and Finance Loop
Finance Loop is the meeting place for fraud, compliance and regulatory reporting teams at banks and payment firms in Germany, Austria and Switzerland. Finance Loop highlighted fAInance by Sopra Steria and Fraunhofer IAIS, which had a station on AI against financial crime.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.