Chapter 1. The fraud landscape: an arms race.
Payment fraud is a never-ending arms race. Every new protection (EMV chip, 3-D Secure, tokenization) pushes fraud toward the weakest link without ever eliminating it. In France, chip and PIN crushed card-present fraud from the 1990s onward, and fraud migrated to remote payments. PSD2’s strong customer authentication (SCA) squeezed it in turn, so fraudsters shifted to social engineering (fake bank advisers, credit transfer fraud) and to card testing on an industrial scale. Nothing disappears; it just moves.
French card fraud is very unevenly distributed. Remote payments account for only about a quarter of card payment value, but they concentrate two-thirds of fraud by value (OSMP). Card-present fraud is marginal thanks to EMV, and contactless fraud is kept in check by transaction limits. The joint ECB/EBA report on payment fraud (2024) confirms that SCA-authenticated transactions show markedly lower fraud rates, with the widest gap on cross-border transactions.
The economics: fraud is not the only cost
- Cost of a successful fraud: lost goods + refunded amount (chargeback) + dispute fees (€15 to €50, depending on the acquirer) + deteriorating scheme ratios + handling time.
- Cost of a false positive: lost margin on the declined sale + lifetime value of the “insulted” customer who defects to a competitor + reputational damage. Industry studies (Javelin, Sift) estimate that false declines cost merchants more than fraud itself.
- Cost of friction: every point of drop-off at the 3DS challenge is lost revenue, and it never shows up in fraud dashboards.
| Scenario | Who bears the loss? |
|---|---|
| Card-present, chip + PIN | The issuer (unless the cardholder was grossly negligent) |
| Remote, not authenticated (exemption, MIT…) | The merchant, through the chargeback |
| Remote, 3DS-authenticated | The issuer (liability shift) |
| Credit transfer authorized under manipulation | Historically the payer; refunds case by case, now changing under the PSD3/PSR package |
Chapter 2. Fraud typology: knowing your adversary.
You can only detect well what you can name. Six types cover most of the fraud a merchant or PSP faces, each with its own statistical signature, modus operandi, and preferred countermeasure.
Inside a BIN enumeration attack
A card number has little entropy: 6 to 8 known BIN digits, a Luhn check digit, and guessable issuing ranges. With a botnet, testing tens of thousands of combinations costs a few euros. The signature is unmistakable. Very small amounts (€0.10 to €2), a massive decline rate (often > 80%), the same BIN or a contiguous range, machine-like cadence, and disposable email addresses. Countermeasures: rate limiting by IP, ASN, or device; systematic CVV and AVS checks; bot detection; velocity thresholds by BIN; and temporary blocking of the ranges under attack. Even when declined, these authorizations incur scheme fees and hurt the merchant’s reputation with issuers.
Friendly fraud and the battle over evidence
First-party misuse has soared with e-commerce, and Visa estimates that up to three in four “fraud” disputes in card-not-present sales may actually come from the cardholder. The networks have responded. Visa Compelling Evidence 3.0 (April 2023) lets the merchant overturn a reason code 10.4 dispute by providing two prior undisputed transactions made 120 to 365 days earlier. Those transactions must share two matching data elements among IP address, device fingerprint, account ID, and shipping address. Mastercard follows the same logic with its First-Party Trust program. Properly archiving IP addresses, device IDs, and login logs therefore determines whether you can fight these disputes.
| Fraud type | Signature | Primary countermeasure |
|---|---|---|
| Stolen card | Unknown customer, resalable goods, express shipping | Scoring + targeted 3DS |
| BIN attack | Bursts of micro-amounts, mass declines, same BIN | Rate limiting, velocity by BIN, bot detection |
| Friendly fraud | Known customer, late “fraud” dispute | Evidence pack, CE 3.0, clear billing descriptor |
| ATO | Unusual login, then account changes | Login anomaly detection, re-authentication |
| Triangulation | Stolen card + “clean” shipping address | Card/account/address cross-checks, graph analysis |
| Refund abuse | Repeated “not received” claims, suspicious returns | Customer history, tiered policy |
Chapter 3. Signals and features: the raw material of scoring.
Whether it relies on rules or machine learning, every fraud prevention system runs on the same raw material: features, variables computed from the transaction, its context, and its history. The quality of the feature engineering matters more than the choice of algorithm.
Identity and order
- Email age and reputation: an address created 3 years ago and seen at other merchants is reassuring; a disposable domain (
mailinator, a timestamped alias) is a red flag. - Billing/shipping consistency: distance between billing address, shipping address, and IP geolocation; delivery to a pickup point or PO box for a high-end order.
- Order contents: digital goods, gift cards, and resalable electronics are favorite targets; so is an unusual quantity of the same item.
- Customer tenure: a first order carries structurally higher risk; recent changes (address, phone, card) on a long-standing account are an ATO signal.
- Phone number: line type (mobile, disposable VoIP), and whether the phone, card, and IP countries match.
Device and network
A device fingerprint combines dozens of technical attributes (browser, OS, screen resolution, fonts, canvas/WebGL, time zone, languages) into a near-unique identifier. It links orders that appear unrelated and exposes device farms. On the network side, teams examine the IP address, ASN, VPN/proxy/Tor use, and mismatches between the declared time zone and the IP location. Behavioral biometrics (typing rhythm, mouse movements, pasting the card number) distinguish a human from a bot and a genuine cardholder from an impostor. Two limitations are worth knowing. Browser privacy protections (ITP, anti-fingerprinting) erode fingerprint stability, and well-equipped fraudsters rotate devices and residential IP addresses.
Velocity: the king of signals
A velocity counter measures how many events share the same key over a sliding time window: the number of cards seen on a device in 24 hours, attempts on a BIN in 10 minutes, or email addresses linked to a shipping address in 7 days. Industrial-scale fraud almost always betrays itself through abnormal velocity somewhere. But you still have to count on the right key.
RULE card_testing_burst
WHEN count(auth_attempts, key = card_bin, window = 10 min) > 25
AND avg(amount, window = 10 min) < 2.00 EUR
AND ratio(declines, window = 10 min) > 0.80
THEN block_source(ip, asn) FOR 24 h
AND force_3ds_challenge(bin) FOR 6 h
AND alert(severity = P1, channel = fraud-on-call)Graph features
Linking cards, email addresses, devices, postal addresses, and IBANs in an entity graph brings fraud rings to the surface. Ten “independent” accounts share two devices and one shipping address; one card shows up on five accounts in a week. Graph features (node degree, size of the connected component, proximity to a node already labeled as fraud) are among the most predictive against organized fraud. They are also the most expensive to compute in real time.
Chapter 4. Rules vs. machine learning, and the tools on the market.
The “rules or ML” debate is the wrong question: high-performing systems combine a rules engine (speed of response, control, regulatory cases) with machine learning models (generalization, nuance). The real question is what to assign to each.
| Criterion | Rules engine | Machine learning |
|---|---|---|
| Deployment | Immediate (a few minutes) | Training, validation, deployment cycle |
| Explainability | Full: every decision is readable | Partial (feature importance, SHAP) |
| Full rollout | None: sees only what was written | Detects new combinations of signals |
| False positives | High if rules pile up | Better precision/recall trade-off at equal volume |
| Maintenance | Rule debt, side effects between rules | Model drift, retraining, monitoring |
| Best use | Immediate response, lists, regulatory thresholds | Baseline scoring on all traffic |
Fraud ML in practice
The industry relies heavily on gradient boosting (XGBoost, LightGBM), which performs well on tabular data, runs fast at inference, and is relatively interpretable. The hard problems lie elsewhere. Extreme class imbalance: fraud often makes up less than 0.1% of rows, so teams rely on weighting and undersampling, and evaluate on precision and recall, never accuracy. Label delay: the chargeback that labels a transaction as fraud arrives 30 to 90 days later, so the model is always learning yesterday’s fraud. Feedback loop: declined transactions never produce a label, so you never learn whether they were fraudulent. A thin control sample has to be let through to keep an unbiased view. Deployment follows a champion/challenger setup, with the new model scoring in parallel before it takes over. The score threshold works like an economic dial: every point of recall gained is paid for in false positives.
The tools market
The market falls into three groups. PSP modules (Stripe Radar, Adyen RevenueProtect, Checkout.com) integrate with no effort and pool signals across the network, though their configuration options can be limited. Guaranteed-decision specialists (Riskified, Signifyd, Forter) approve or decline orders and reimburse fraud chargebacks on the transactions they approve, turning risk into a contractual cost (0.4% to 1% of revenue) that appeals to high-risk verticals. Platforms and data enrichment providers (Feedzai for banks and acquirers, Sift, SEON for identity enrichment, plus scheme solutions such as Visa/Cybersource Decision Manager or Mastercard Brighterion/NuData). Build vs. buy depends on volume: below a few million transactions a year, a merchant’s own data rarely beats a pooled model.
Chapter 5. Targeted 3DS: calibrating friction, allocating liability.
Since PSD2, strong customer authentication (SCA) has been the rule in Europe for payer-initiated electronic payments. But challenging every transaction with 3DS hurts conversion: drop-off runs to several percentage points, depending on the checkout flow and the bank. The skill lies in choosing who faces the friction and who bears the fraud liability.
With 3-D Secure 2, there are two possible outcomes. Frictionless: the issuer authenticates silently based on the data received (device, history, address). Challenge: in-app biometrics or a one-time code. The merchant can influence the outcome by requesting an exemption, forcing a challenge, or sending more data (up to Mastercard’s “data only” flow) to maximize frictionless approvals.
| Case | Conditions | Who bears the fraud loss? |
|---|---|---|
| TRA exemption (transaction risk analysis) | Exempting party’s fraud rate ≤ 0.13% → up to €100; ≤ 0.06% → €250; ≤ 0.01% → €500 | The party requesting the exemption (acquirer/merchant or issuer) |
| Low-value payment (LVP) | ≤ €30, max. 5 consecutive transactions or €100 cumulative without SCA | The party requesting the exemption |
| Trusted beneficiaries | The cardholder has added the merchant to an allowlist with their issuer | The issuer |
| Recurring subscriptions | SCA on the first transaction, exemption on later fixed-amount payments | The party requesting the exemption |
| MIT (merchant-initiated transaction) | Out of scope for SCA: transaction without the payer present, based on an authenticated initial agreement | The merchant (no liability shift) |
| MOTO, one-leg-out | Out of scope: mail or telephone order, or one of the two banks is outside the EEA | Generally the merchant |
The 3DS routing strategy
- Very low score (safe traffic): request the TRA exemption → zero friction, maximum conversion, and a risk you accept but that is statistically negligible.
- Medium score: send to 3DS aiming for frictionless (low friction, liability shift secured).
- High score: force the challenge, or even decline upstream without using up an authorization.
- Soft declines: a decline with code
1A(Visa) or65(Mastercard) means “authentication required,” not “hard decline.” You must automatically retry the transaction with 3DS, or you will lose perfectly legitimate sales. - Feedback loop: track the frictionless rate, challenge drop-off rate, and post-authentication decline rate by issuer, and adjust routing bank by bank.
This fine-tuning requires staying below your acquirer’s TRA thresholds: if the fraud rate slips above 0.13%, you lose the right to exempt transactions above €100. A snowball effect follows, with more friction and more drop-off but no immediate drop in fraud, and it can cost points of conversion for months. Your fraud rate is therefore a commercial asset to protect.
Chapter 6. KPIs: managing fraud like a P&L.
A fraud team without a dashboard is flying blind. The metrics must be read together: a fraud rate that falls while the approval rate collapses is not a win but a transfer of cost to the business.
- Fraud rate (in basis points): fraud amount / processed volume. Measured in bps (0.05% = 5 bps), by channel, country, and payment method. It is also the variable that determines TRA exemption eligibility.
- Dispute ratio (chargeback ratio): number of disputes / number of transactions. This is the metric scheme monitoring programs watch.
- Approval rate: the commercial counterweight, to be tracked at the same management level as the fraud rate.
- False positives / insult rate: the share of good customers wrongly declined. Hard to measure directly; estimated through control samples, complaints, and the “return” rate of declined customers.
- Manual review rate and SLA: the share of orders sent to an analyst (typical target < 5% of orders) and the time to decision. Every hour of waiting degrades the customer experience and the delivery promise.
- Rule hit rate: the share of each rule’s triggers that turn out to be real fraud; a rule below 20–30% precision is a candidate for retirement.
- Total cost of fraud: losses + dispute fees + tooling costs + team costs + revenue lost to false positives. This is the number to optimize.
Scheme monitoring programs
Crossing these thresholds triggers remediation plans, escalating fines and, as a last resort, termination of the acquiring agreement, an existential threat for an online merchant. VAMP has a built-in trap: fraud reports (TC40) count even if the transaction was refunded. Refunding after the fact does not erase the record, which is why attacks must be stopped before capture.
Chapter 7. Building a fraud team and managing a crisis.
Fraud prevention is a cross-functional team effort that spans risk, data, and operations. Depending on company size, it reports to the risk, payments, or operations function. Two things matter above all. The first is a clear mandate that sets decision thresholds and the budget for acceptable losses; the second is direct access to the product teams and the PSP.
- Fraud analysts: manual order review, dispute and representment handling, and monitoring of fraud tactics.
- Rule writers / fraud engineers: rule design, testing, and life cycle; block list and allowlist management; rapid response to attacks.
- Data scientists: scoring models, features, false positive measurement, control samples, drift monitoring.
- Fraud ops manager: review SLAs, capacity, training, decision quality (second reviews, calibration across analysts).
- Routines: a daily alert check-in, a weekly review of rules and their hit rates, a monthly fraud/payments/finance committee, and a post-mortem after every incident.
Crisis playbook: an attack is under way
Crisis readiness is built in calm times. Tested runbooks settle in advance the questions that come up mid-attack. They name who is authorized to turn on 3DS for 100% of traffic, and who calls the acquirer at 3 a.m. Add a documented kill switch on sensitive flows (account creation, donation page, adding a card), a properly equipped on-call rotation, and regular tabletop exercises. On the day, the only thing you improvise is what you have not rehearsed.