🎓 CoursesRisk & complianceAdvanced⏱ 60 min

Fraud prevention: detecting, scoring, and fighting back. 7 chapters and a final quiz.

A complete typology of payment fraud: stolen cards, card testing and BIN attacks, friendly fraud, ATO, triangulation, and refund abuse. Scoring signals and features, rules vs. machine learning, and the tools on the market. Targeted 3DS and exemptions, fraud team KPIs, and a crisis management playbook.

Chapter 1. The fraud landscape: an arms race.

Payment fraud is a never-ending arms race. Every new protection (EMV chip, 3-D Secure, tokenization) pushes fraud toward the weakest link without ever eliminating it. In France, chip and PIN crushed card-present fraud from the 1990s onward, and fraud migrated to remote payments. PSD2’s strong customer authentication (SCA) squeezed it in turn, so fraudsters shifted to social engineering (fake bank advisers, credit transfer fraud) and to card testing on an industrial scale. Nothing disappears; it just moves.

€1.195B
fraud on non-cash payment instruments in France (2023)
Banque de France / OSMP
0,053 %
fraud rate on card payments in France (2023)
OSMP, annual report
≈ $34B
global card fraud (2023)
Nilson Report
3 in 4
share of remote “fraud” disputes that may actually be first-party misuse
Visa

French card fraud is very unevenly distributed. Remote payments account for only about a quarter of card payment value, but they concentrate two-thirds of fraud by value (OSMP). Card-present fraud is marginal thanks to EMV, and contactless fraud is kept in check by transaction limits. The joint ECB/EBA report on payment fraud (2024) confirms that SCA-authenticated transactions show markedly lower fraud rates, with the widest gap on cross-border transactions.

The economics: fraud is not the only cost

  • Cost of a successful fraud: lost goods + refunded amount (chargeback) + dispute fees (€15 to €50, depending on the acquirer) + deteriorating scheme ratios + handling time.
  • Cost of a false positive: lost margin on the declined sale + lifetime value of the “insulted” customer who defects to a competitor + reputational damage. Industry studies (Javelin, Sift) estimate that false declines cost merchants more than fraud itself.
  • Cost of friction: every point of drop-off at the 3DS challenge is lost revenue, and it never shows up in fraud dashboards.
🔑
The goal is not zero fraud
A mature fraud team does not minimize the fraud rate; it maximizes net margin by constantly balancing accepted fraud, false declines, and added friction. A 0% fraud rate almost always means you are declining too many good customers.
ScenarioWho bears the loss?
Card-present, chip + PINThe issuer (unless the cardholder was grossly negligent)
Remote, not authenticated (exemption, MIT…)The merchant, through the chargeback
Remote, 3DS-authenticatedThe issuer (liability shift)
Credit transfer authorized under manipulationHistorically the payer; refunds case by case, now changing under the PSD3/PSR package
Who bears the fraud loss? (simplified liability rules)
🎯 Quick question
What is the economic objective of a mature fraud team?